Horizon Screen Protection: Pilot Acceptance Tests and Exceptions
- Get link
- X
- Other Apps
Test the security requirement, not just whether a watermark is visible. This acceptance worksheet is for a Horizon screen-protection pilot after settings have been selected. It is not a completed test report or a second configuration tutorial.
Correction, September 12, 2026: The previous article asserted that every client and capture application would be blocked, and supplied unverified policy paths and variables. The replacement defines separate test surfaces and records exceptions rather than claiming universal enforcement.
Define the pilot boundary
Record exact Client and Agent versions, endpoint OS, desktop or published-app session, display protocol, effective user/machine policies, and the allowed business workflows. Use a small approved group and non-sensitive test documents. The scope should reflect the real devices users will use, not only the administrator's laptop.
| Test surface | Record separately | Acceptance question |
|---|---|---|
| Endpoint screenshot | Tool/version, captured surface, watermark visibility | Does the supported endpoint enforce the intended restriction? |
| Capture inside the remote desktop | Remote application and resulting output | Does the policy requirement include this distinct path? |
| Meeting/screen-sharing workflow | Where the meeting application runs and optimization mode | Is permitted collaboration usable without exposing restricted content? |
| Redirected content | Browser/media redirection configuration | Does the documented exception conflict with the requirement? |
| Reconnect and another supported endpoint | Fresh session, versions, effective policy | Is behavior consistent within the stated support boundary? |
Set expected results from documentation
Use the matching release's official feature guidance. The 2406 Agent policy reference documents platform-specific screen-capture behavior and exceptions. The 2309 watermark guide illustrates why a visible overlay is not a guarantee for every recording path. These are version-scoped references, not evidence that an unlisted platform passes.
Write the expected outcome before each test, then record the actual outcome, timestamp, configuration and evidence file. Mark unsupported or untested combinations explicitly. Do not convert an empty result cell into “passed.” Avoid repeatedly capturing real sensitive records just to demonstrate that a control does not cover them.
Decide whether to expand
- If effective policy is missing, correct delivery and rerun the same test.
- If behavior matches a documented exception but violates the business requirement, stop expansion and ask the security owner for an alternative supported control or approved access restriction.
- If a supported combination behaves unexpectedly, preserve logs and a sanitized reproduction for vendor support.
- If essential support, accessibility, or collaboration breaks, roll back the pilot and review the requirement with the affected owner.
Close the pilot
Keep a record of supported combinations, accepted exceptions, rollout group, policy version, rollback settings, and responsible owner. Recheck after Client/Agent upgrades rather than treating the first pilot as permanent certification. This process can expose a mismatch between a control and a requirement; it cannot guarantee that all screen content is impossible to copy or photograph.
Related troubleshooting guides
- Get link
- X
- Other Apps
Comments
Post a Comment