Configure a macOS PPPC Screen Capture entry for the current Teams bundle ID com.microsoft.teams2 with Authorization = Allow Standard User To Set System Service; macOS does not permit MDM to silently grant this permission, so each user must still enable Teams in System Settings.
Create the Intune PPPC policy
Prerequisites:
- The Macs must be enrolled in Intune, with the Apple MDM push certificate configured.
- The administrator needs at least the Intune Policy and Profile Manager role.^1^
In the Microsoft Intune admin center:
- Go to Devices → Manage devices → Configuration.
- Select Create → New policy.
- Choose:
- Platform: macOS
- Profile type: Settings catalog
- Select Add settings.
- Open Privacy → Privacy Preferences Policy Control → Services.
- Under Screen Capture, add:
- Authorization
- Code Requirement
- Identifier
- Identifier type
- Static Code
- Select Edit instance and configure:
| Setting | Value |
|---|---|
| Authorization | Allow Standard User To Set System Service |
| Identifier | com.microsoft.teams2 |
| Identifier type | Bundle ID |
| Code Requirement | Use the designated requirement extracted from the installed, Microsoft-signed Teams app |
| Static Code | Not configured or False |
The Settings Catalog path and authorization behavior follow Microsoft's documented PPPC Screen Capture deployment pattern.^2^ The current Teams client uses com.microsoft.teams2.^3^
Do not set Block screen recording to Yes. That setting denies capture; Intune cannot use it to allow capture.^4^
Obtain and verify the code requirement
Run this against the Teams installation being deployed:
codesign --display -r - "/Applications/Microsoft Teams.app" 2>&1
mdls -name kMDItemCFBundleIdentifier \
"/Applications/Microsoft Teams.app"
For the PPPC Code Requirement, copy everything shown after designated =>. Intune documents this codesign method for obtaining the app's signing designation.^4^
Verify the returned bundle identifier is com.microsoft.teams2 before assignment. This avoids applying a current-client profile to a legacy Teams installation. Leave static-code validation unconfigured unless the process invalidates its dynamic signature; Microsoft recommends enabling it only in that circumstance.^4^
Assign the profile to a pilot device group, synchronize a Mac, and check its configuration-profile status before broad deployment.
Required user action
The profile only lets a standard user approve Screen Capture without administrator credentials; it does not turn permission on automatically.
After the profile arrives, instruct users to:
- Open Apple menu → System Settings → Privacy & Security → Screen & System Audio Recording.
- Enable Microsoft Teams.
- Quit and reopen Teams.
- Rejoin the meeting and select Share again.
Microsoft documents that Teams must have Screen Recording permission and must be restarted after the permission is enabled.^5^
If macOS 15.x still reports missing permission
A matching macOS 15.x case identifies a known post-upgrade issue. Try its workaround before changing or removing the PPPC profile:
- Open System Settings → Privacy & Security → Screen & System Audio Recording.
- Select Microsoft Teams and click – to remove it.
- Click + and add Microsoft Teams from
/Applications. - Select Quit & Reopen.
- Confirm Teams is enabled, then relaunch it.^6^
Only if the entry cannot be changed, or this workaround fails specifically while the PPPC profile is installed, temporarily unassign the profile from one test Mac and repeat the test. Treat that as diagnosis—not the production solution.
If it still fails, open a Microsoft Support case through the Microsoft 365 admin center. Include:
- macOS and Teams versions
- installed bundle ID
- Intune assignment and device-status results
- exported PPPC payload and code requirement
- relevant device/Teams logs
- results with and without the pilot PPPC assignment
Conditional: Windows 365 or Azure Virtual Desktop content
This applies only when users are sharing content from a protected Cloud PC or Azure Virtual Desktop session. Screen-capture protection on macOS can make shared windows blank.^7^
Disabling that control weakens data protection and may violate compliance requirements. Have the security administrator assess the narrowest supported exception or scope; do not disable it broadly.
References
- Enrollment guide: Microsoft Intune enrollment
- Deploying Remote Help with Microsoft Intune
- Teams for Mac screen sharing permission loop on macOS Tahoe 26.4 — TCC ...
- Apple device restriction settings in Microsoft Intune (macos)
- Deploy the Microsoft Teams client for Mac - Microsoft Teams
- Microsoft Teams MacOS Screensharing Permission .mobileconfig - Microsoft Q&A
- Enable screen capture protection in Azure Virtual Desktop and Windows 365