macOS users can't share their screen in Microsoft Teams after an upgrade

Adin Mohhamed 40 Reputation points
2026-10-09T08:20:47.2533333+00:00

After upgrading macOS, our users can no longer share their desktop screen in Microsoft Teams meetings. How do we grant Screen Recording permissions to Teams through an MDM PPPC profile ?

Windows for business | Windows 365 Business
0 comments No comments

2 answers

Sort by: Most helpful
  1. Domic Vo 34,490 Reputation points Independent Advisor
    2026-10-09T09:07:10.6833333+00:00

    Hello,

    after the macOS upgrade, deploy an updated Privacy Preferences Policy Control (PPPC) configuration profile through your MDM solution (such as Jamf Pro or Intune). Configure the Screen Recording privacy service for Microsoft Teams using the correct application bundle identifier and code-signing requirements.

    For the classic Teams app, verify the bundle identifier and designated code requirement against the installed version; do not reuse a code requirement from an older build. Note that macOS may require users to approve screen recording access interactively, depending on the macOS version and MDM-supported privacy controls. A PPPC profile cannot silently grant every Screen Recording permission on every macOS release.

    After deployment, have users check System Settings → Privacy & Security → Screen & System Audio Recording and confirm Teams is permitted. Also verify the MDM profile installed successfully and test screen sharing in a new Teams meeting.

    Which macOS version and MDM platform are you using, and is this the new Microsoft Teams or classic Teams? I can provide the appropriate profile configuration once those details are confirmed.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    Domic Vo.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-10-09T08:22:32.92+00:00

    Configure a macOS PPPC Screen Capture entry for the current Teams bundle ID com.microsoft.teams2 with Authorization = Allow Standard User To Set System Service; macOS does not permit MDM to silently grant this permission, so each user must still enable Teams in System Settings.

    Create the Intune PPPC policy

    Prerequisites:

    • The Macs must be enrolled in Intune, with the Apple MDM push certificate configured.
    • The administrator needs at least the Intune Policy and Profile Manager role.^1^

    In the Microsoft Intune admin center:

    1. Go to Devices → Manage devices → Configuration.
    2. Select Create → New policy.
    3. Choose:
      • Platform: macOS
      • Profile type: Settings catalog
    4. Select Add settings.
    5. Open Privacy → Privacy Preferences Policy Control → Services.
    6. Under Screen Capture, add:
      • Authorization
      • Code Requirement
      • Identifier
      • Identifier type
      • Static Code
    7. Select Edit instance and configure:
    Setting Value
    Authorization Allow Standard User To Set System Service
    Identifier com.microsoft.teams2
    Identifier type Bundle ID
    Code Requirement Use the designated requirement extracted from the installed, Microsoft-signed Teams app
    Static Code Not configured or False

    The Settings Catalog path and authorization behavior follow Microsoft's documented PPPC Screen Capture deployment pattern.^2^ The current Teams client uses com.microsoft.teams2.^3^

    Do not set Block screen recording to Yes. That setting denies capture; Intune cannot use it to allow capture.^4^

    Obtain and verify the code requirement

    Run this against the Teams installation being deployed:

    codesign --display -r - "/Applications/Microsoft Teams.app" 2>&1
    mdls -name kMDItemCFBundleIdentifier \
      "/Applications/Microsoft Teams.app"
    

    For the PPPC Code Requirement, copy everything shown after designated =>. Intune documents this codesign method for obtaining the app's signing designation.^4^

    Verify the returned bundle identifier is com.microsoft.teams2 before assignment. This avoids applying a current-client profile to a legacy Teams installation. Leave static-code validation unconfigured unless the process invalidates its dynamic signature; Microsoft recommends enabling it only in that circumstance.^4^

    Assign the profile to a pilot device group, synchronize a Mac, and check its configuration-profile status before broad deployment.

    Required user action

    The profile only lets a standard user approve Screen Capture without administrator credentials; it does not turn permission on automatically.

    After the profile arrives, instruct users to:

    1. Open Apple menu → System Settings → Privacy & Security → Screen & System Audio Recording.
    2. Enable Microsoft Teams.
    3. Quit and reopen Teams.
    4. Rejoin the meeting and select Share again.

    Microsoft documents that Teams must have Screen Recording permission and must be restarted after the permission is enabled.^5^

    If macOS 15.x still reports missing permission

    A matching macOS 15.x case identifies a known post-upgrade issue. Try its workaround before changing or removing the PPPC profile:

    1. Open System Settings → Privacy & Security → Screen & System Audio Recording.
    2. Select Microsoft Teams and click – to remove it.
    3. Click + and add Microsoft Teams from /Applications.
    4. Select Quit & Reopen.
    5. Confirm Teams is enabled, then relaunch it.^6^

    Only if the entry cannot be changed, or this workaround fails specifically while the PPPC profile is installed, temporarily unassign the profile from one test Mac and repeat the test. Treat that as diagnosis—not the production solution.

    If it still fails, open a Microsoft Support case through the Microsoft 365 admin center. Include:

    • macOS and Teams versions
    • installed bundle ID
    • Intune assignment and device-status results
    • exported PPPC payload and code requirement
    • relevant device/Teams logs
    • results with and without the pilot PPPC assignment

    Conditional: Windows 365 or Azure Virtual Desktop content

    This applies only when users are sharing content from a protected Cloud PC or Azure Virtual Desktop session. Screen-capture protection on macOS can make shared windows blank.^7^

    Disabling that control weakens data protection and may violate compliance requirements. Have the security administrator assess the narrowest supported exception or scope; do not disable it broadly.


    References

    1. Enrollment guide: Microsoft Intune enrollment
    2. Deploying Remote Help with Microsoft Intune
    3. Teams for Mac screen sharing permission loop on macOS Tahoe 26.4 — TCC ...
    4. Apple device restriction settings in Microsoft Intune (macos)
    5. Deploy the Microsoft Teams client for Mac - Microsoft Teams
    6. Microsoft Teams MacOS Screensharing Permission .mobileconfig - Microsoft Q&A
    7. Enable screen capture protection in Azure Virtual Desktop and Windows 365
    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.