Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Introduction
Watermarking Protection in Microsoft Edge helps organizations visibly reinforce data protection policies by overlaying a persistent watermark on sensitive content viewed in the browser. This feature is designed to deter unauthorized sharing, support compliance efforts, and increase user awareness when handling confidential information.
When enabled, watermarking appears automatically on content that meets sensitivity criteria such as pages labeled via Microsoft Purview or those subject to Data Loss Prevention (DLP) enforcement. The watermark is rendered by the browser and can't be removed or altered by the user.
Requirements
To use Watermarking Protection, your organization must meet the following prerequisites:
- Microsoft Edge version 142 or later
- Microsoft 365 E5 (preferred) or E3 licensing
- Admin access to the Edge Management Service portal
- Targeted Release enabled for your tenant
Admin Experience
Admins can enable watermarking through the Edge Management Service (EMX) by creating a test profile and configuring the watermarking toggle.
Steps to Enable:
- Go to the Edge Management Service portal.
- Create a test profile and assign it to a desired scope group. Note: It should be scoped to user identity, not device.
- In the Security Settings page, turn on the Watermarking toggle.
Where Watermarking Shows Up
| Surface Type | Supported |
|---|---|
| Regular browser tabs | ✔️ |
| Split screen tabs | ✔️ |
| Pop-up windows and app windows | ✔️ |
| Local PDFs with sensitivity labeling | ✔️ |
| MIP-labeled PDFs | ✔️ |
| Printing and screenshots | ✔️ |
| Sidebar and Shoreline surfaces | ❌ (planned for future) |
| Reading mode | ✔️ |
Watermark Overlay Details
When watermarking is triggered, users see a semi-transparent overlay across the content area. These strings are rendered consistently across supported surfaces and can't be modified by the user or admin today. Customizable, dynamic watermarks are planned for a future release. The default string is:
“Confidential – Don't share”
Username
Timestamp
Watermarking is tied to enforcement actions, not to labels or auditing. A watermark appears only when a policy applies an actual restriction action (for example, block copy, block upload, or block print) from a DLP provider such as a Purview label policy, a Purview session policy, eDLP Purview policy, or Intune.
A watermark is not rendered when:
- A sensitivity label is present but applies no restriction.
- The matching DLP policy is set to Audit only. An audit action logs the activity but does not display a watermark.
If you expect a site or file to be watermarked, confirm it is receiving a restriction (block) action, not just audit.
Troubleshooting: watermark isn't showing
If a watermark doesn't appear on content you expect to be protected:
- In
edge://policy, confirm the watermarking policy is applied and the user is in scope. - Verify the DLP/session/label policy carries a restriction (block) action, not just Audit. This is the most common cause.
- Confirm the profile is scoped to user identity, not device.
- Confirm Microsoft Edge is version 142 or later.

Feedback and support
This experience is supported by Microsoft Support. You can reach out to Microsoft Support to report issues or give feedback. You can also leave feedback in our TechCommunity forum.