Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
Input and Output Protection is in preview. For legal terms that apply to features that are in beta, preview, or otherwise not yet released into general availability, see the Supplemental Terms of Use for Microsoft Azure Previews. Visit this page to learn more about previews in Windows 365
Applies to:
- Windows 365 Cloud PCs
- Azure Virtual Desktop session hosts
Overview
Input and Output Protection is a set of security features that establish a secure channel for keyboard input and display output between the endpoint device and Windows 365 Cloud PCs or Azure Virtual Desktop session hosts. It helps session data pass securely between the endpoint and the cloud, reducing the risk from threats that may reside on the connect device, such as keyloggers and screen capture tools. Input and Output Protection isn't antivirus software—instead of detecting or removing malware, it secures the input and output channels so that session data stays protected as it moves between the endpoint and the remote session.
Input and Output Protection includes two independently configured components:
- Input Protection: Protects keyboard input by securely routing keystrokes directly to the Cloud PC or session host, bypassing OS layers on the endpoint that are vulnerable to keylogger malware.
- Display Protection (Output Protection): Protects the display output of the remote session against unauthorized screen capture and recording on the endpoint device.
Each component can be enabled separately based on your organization's security requirements. Input protection uses a kernel-level driver on the endpoint device and requires the Input Protection MSI to be installed. Display protection requires an updated version of Windows App on the endpoint.
Input and Output Protection value
Windows 365 Cloud PCs and Azure Virtual Desktop session hosts encrypt session traffic and enforce identity-based authentication methods like multifactor authentication (MFA). These measures protect against network interception and unauthorized access. However, they don't address threats that operate directly on the endpoint device, such as:
- Keylogger malware: Software that intercepts keystrokes on the endpoint before they're transmitted to the remote session.
- Screen capture malware: Software that records or captures the display output of the remote session as it's rendered on the endpoint.
These endpoint-resident threats can expose sensitive data even when network-level protections are in place. Input and Output Protection addresses this gap by securing the input and output paths at the kernel or hardware level.
Input and Output Protection capabilities
The following table summarizes the capabilities of each component:
| Capability | Input protection | Display protection |
|---|---|---|
| Risk mitigated | Keystroke interception (keyloggers) | Screen capture and recording |
| Protection scope | Keyboard input to the remote session | Display output of the remote session |
| Enforcement mechanism | Kernel-level | Hardware or Software protection, depending on configuration |
| Requires MSI on endpoint | Yes | No |
| Configuration method | Intune (Windows 365) or Azure portal (Azure Virtual Desktop) | Intune (Windows 365) or Azure portal (Azure Virtual Desktop) |
| Configured independently | Yes | Yes |
Input Protection
Input Protection secures keyboard input by routing keystrokes directly from the endpoint's kernel-level driver to the Cloud PC or session host. This bypasses OS layers on the endpoint that are vulnerable to interception by keylogger malware.
Only endpoints with the input protection MSI installed can connect to a protected Cloud PC or session host. If the MSI isn't installed, the connection is blocked.
For configuration steps and detailed information, see Input Protection.
Display Protection
Display protection is a component of Output Protection. When enabled on a Cloud PC or session host, it prevents unauthorized applications or malware from capturing or recording the remote session's display output.
Display protection requires an updated version of Windows App on the endpoint device. For configuration steps and detailed information, see Display Protection for Windows 365 and Azure Virtual Desktop.
Common use cases
Consider enabling Input and Output Protection in the following scenarios:
- Sensitive data access: Users access financial records, health data, or other confidential information through Windows 365 Cloud PCs or Azure Virtual Desktop session hosts.
- Compliance requirements: Organizational or regulatory policies require protection against keystroke interception and screen capture threats on endpoint devices.
- Bring your own device (BYOD): Users connect from personally owned or unmanaged devices, and the organization wants to help protect sensitive information from endpoint-based threats such as keyloggers and screen capture tools.
- Defense in depth: You want to complement existing protections such as session encryption, multifactor authentication (MFA), and Conditional Access with controls that help protect sensitive cloud session content from unauthorized screen capture or recording.
Configure Input and Output Protection
Input protection and display protection are configured independently. Each feature is enabled on the Cloud PC or session host. Input protection also requires the input protection MSI on the endpoint device. Display protection requires an updated version of Windows App.
Each component has its own endpoint requirements, protection options, and validation steps. To avoid duplication, those details are maintained in the component articles. For prerequisites and step-by-step configuration, see:
Monitor Input and Output Protection
You can monitor input protection and display protection activity across your tenant by using [Cloud PC monitoring](cloud-pc-monitoring-overview.md (preview) in the Microsoft Intune admin center. Protection status is reported as connection events that you can review on the Connection health page.
Note
Cloud PC monitoring is in preview. Protection events are surfaced through the connection Events data, and the available events and values might change before general availability.
To look up protection events:
- Sign in to the Microsoft Intune admin center and select Reports > Cloud PC monitoring (preview).
- Select the Connection health tab.
- Use the time range picker and filters to focus on the connections you want to investigate.
- Select View data to expand the fly-out, and then open the Events table.
- Add the event name column if it isn't already shown, or use Search to find protection events by name.
The following table lists the connection event for each component:
| Component | Connection event |
|---|---|
| Input protection | KeyboardInputProtectionState |
| Display protection | DisplayProtectionState |
Use these events to confirm whether protection was negotiated for a connection and to investigate connections where protection wasn't applied. For more information about the Connection health page, the Events table, and how to interpret event data, see Cloud PC monitoring overview, Connection health, and View data.
Related features
- Input Protection: Detailed configuration and validation steps for input protection.
- Display Protection for Windows 365 and Azure Virtual Desktop: Detailed configuration and validation steps for display protection.
- Enable screen capture protection: A separate screen capture protection feature for Azure Virtual Desktop and Windows 365.
- Watermarking: Adds visible watermarks to remote sessions to discourage photo-based screen capture.