Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
AVD

Azure Virtual Desktop Advanced Clipboard Controls: Restrict Text, Images, RTF and HTML

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Azure Virtual Desktop (AVD) clipboard control has two layers. The host-pool RDP property turns the clipboard channel on or off; Intune or Group Policy then limits the transfer direction and permitted formats. Microsoft’s documented levels range from no clipboard transfers (0) to plain text, images, Rich Text Format (RTF) and HTML (4). The most restrictive applicable setting wins, so an enabled host-pool property cannot override a blocking session-host or endpoint policy.

Microsoft documents this capability as clipboard transfer direction and data types, not “AVD Advanced Clipboard Controls.”

What AVD clipboard controls actually govern

Clipboard redirection connects the local client and the remote session host. You can disable that channel completely, allow only one direction, or permit selected clipboard data classes in each direction.

  • Client to session host: content copied on the local device and pasted in the remote session.
  • Session host to client: content copied in the remote session and pasted on the local device.
  • Data types: plain text, images, RTF and HTML. RTF and HTML are separate formats; allowing RTF does not automatically allow HTML.

These policies govern clipboard formats, not every possible transfer route. Files copied in File Explorer use clipboard-based file transfer and are also affected by drive-redirection policy. Uploads through a browser, USB devices, printer redirection and application-specific sharing require separate controls.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s clipboard data-type levels

Level Permitted clipboard content Typical use
0 Clipboard transfers disabled Maximum isolation
1 Plain text only Commands, ticket numbers and account IDs
2 Plain text and images Support screenshots and diagrams
3 Plain text, images and RTF Formatted Office-style text
4 Plain text, images, RTF and HTML Broad compatibility with browser-originated rich content

RTF commonly preserves fonts, colors, emphasis and paragraph structure. HTML can contain web-style markup and additional formatting. The level permits a data class; it does not guarantee that every source and destination application will preserve formatting identically.

Enable the basic clipboard channel in the Azure portal

Newly created host pools may have clipboard redirection disabled under Microsoft’s newer redirection-security defaults. Check the effective setting rather than assuming an older host pool’s behavior applies.

  1. Sign in to the Azure portal.
  2. Open Azure Virtual Desktop, then select Host pools.
  3. Open the required host pool and select RDP Properties.
  4. Open Device redirection.
  5. For Clipboard redirection, choose Clipboard on local computer is available in remote session to enable it, Clipboard on local computer isn’t available in remote session to disable it, or Not configured.
  6. Select Save, end existing test sessions and reconnect.

The corresponding RDP property is redirectclipboard:i:1 when enabled and redirectclipboard:i:0 when disabled. This is only the coarse channel setting. A restrictive Intune, Group Policy or local-client setting can still block the effective connection. See Microsoft’s configuration guidance at Configure clipboard redirection in Azure Virtual Desktop.

Configure direction and formats with Intune

  1. In the Microsoft Intune admin center, create or edit a configuration profile for Windows 10 and later.
  2. Choose the Settings catalog profile type.
  3. Browse to Administrative templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection.
  4. Configure Restrict clipboard transfer from server to client and/or Restrict clipboard transfer from client to server.
  5. Enable each policy and select level 0, 1, 2, 3 or 4.
  6. Assign the profile to the session-host device group, allow policy delivery, and restart or renew sessions as required.

Do not confuse these directional policies with Do not allow Clipboard redirection. The latter is an all-or-nothing block and can prevent the granular settings from having any effect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure the same controls with Group Policy

For domain-joined or hybrid session hosts, use:

Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection

  1. Open Restrict clipboard transfer from server to client, choose Enabled, select the required level and apply.
  2. Open Restrict clipboard transfer from client to server, choose Enabled, select the required level and apply.

The equivalent policies are also available under User Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection. Configure only the direction your workflow requires.

Registry values and direction mapping

Microsoft documents these values for implementation and troubleshooting. Centralized Intune or Group Policy deployment is preferable for a managed fleet.

Direction Registry location Value
Session host to client HKEY_CURRENT_USERSoftwarePoliciesMicrosoftWindows NTTerminal Services SCClipLevel (REG_DWORD)
Client to session host, machine-wide HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindows NTTerminal Services CSClipLevel (REG_DWORD)
Client to session host, per user HKEY_CURRENT_USERSoftwarePoliciesMicrosoftWindows NTTerminal Services CSClipLevel (REG_DWORD)

Use the same values: 0 disables transfers, 1 permits plain text, 2 adds images, 3 adds RTF and 4 adds HTML. Restart the session host after applying registry configuration, then create a new user session.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Practical security profiles

Profile Client to session host Session host to client When it fits
Maximum isolation 0 0 Clipboard exfiltration and data injection are unacceptable.
Text only 1 1 Users need short identifiers, commands or ticket data.
Text plus screenshots 2 2 Images are operationally necessary but rich formatting is not.
Formatted documents 3 3 RTF formatting is required; HTML is not.
Broad compatibility 4 4 HTML clipboard content is necessary and the larger transfer surface is accepted.

These are risk-versus-usability patterns, not Microsoft security classifications. One-way configurations can be safer: for example, allow client-to-host input while setting host-to-client to 0 to reduce copying sensitive remote data to an endpoint.

Drive redirection and clipboard file transfers

Microsoft states that disabling drive redirection prevents files from being transferred between the local device and remote session through the clipboard. Plain text and images are not affected by that particular restriction. Therefore, “clipboard works” may mean text succeeds while file transfer is intentionally blocked. Clipboard settings alone do not replace controls for browser uploads, USB, drives or other exfiltration paths.

How to test a deployment

  1. Record the client application, endpoint operating system, session-host operating system and policy source.
  2. Test plain text from client to host and host to client.
  3. Test bold or otherwise formatted text to determine whether RTF survives.
  4. Copy a screenshot or image from an editor in both directions.
  5. Copy browser content that exposes HTML formatting.
  6. Copy a file in File Explorer and verify the expected drive-redirection result.
  7. Paste each item into more than one destination application; applications may prefer different clipboard formats.
  8. Sign out, close the client and reconnect after policy changes. Restart the session host where Microsoft’s registry guidance requires it.

Troubleshooting by symptom

Nothing transfers

Check the host-pool redirectclipboard property, the Do not allow Clipboard redirection policy, endpoint DisableClipboardRedirection, and whether the client supports clipboard redirection.

Text works but images do not

The effective level may be 1, the directional policy may be set for the opposite direction, or another management channel may be more restrictive. Test with a simple screenshot.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Text works but formatting is lost

Levels 1 and 2 do not allow RTF. At level 3, the source or destination may expose only plain text or may convert the content during paste. HTML requires level 4.

One direction fails

Compare CSClipLevel (client to session host) with SCClipLevel (session host to client). Different values intentionally produce different results.

Images work but files fail

Check drive redirection. Microsoft’s documented behavior allows text and images to remain available while file transfer through the clipboard is blocked.

Browser copy and paste behaves differently

Web clients also depend on browser clipboard permissions and client implementation. A correct AVD policy does not guarantee identical behavior across Windows App, Remote Desktop, web, mobile and other clients. Review supported-client guidance in Microsoft’s clipboard redirection documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Block clipboard on a specific local Windows device

To block clipboard redirection from a particular Windows client, Microsoft documents:

HKEY_LOCAL_MACHINESoftwareMicrosoftTerminal Server Client
DisableClipboardRedirection (REG_DWORD) = 1

This endpoint setting is distinct from the AVD host-pool property and session-host policies. It is useful for selected unmanaged or high-risk devices, but it does not configure the remote session’s format levels.

Governance and scope

Align clipboard decisions with drive, USB, printer and other redirection controls. Clipboard restrictions reduce one transfer path; they are not complete data-loss prevention. Windows 365 uses the same general RDP concepts, but Cloud PC provisioning and management are not host-pool operations. Traditional Remote Desktop Services has related policy terminology with different infrastructure and licensing. Citrix and Omnissa Horizon use their own clipboard policy models.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For AVD planning, use the Azure Virtual Desktop product page. Intune is the cloud-management option described at Microsoft Intune pricing; estimate the broader environment, not a separate clipboard feature, with the Azure pricing calculator.

Operational checklist

  • Check the host-pool clipboard RDP property.
  • Check for an all-clipboard block in Intune or Group Policy.
  • Set client-to-host and host-to-client levels independently.
  • Choose the minimum data-type level that meets the workflow.
  • Confirm how drive redirection affects file tests.
  • Check endpoint exceptions, including DisableClipboardRedirection.
  • Restart or renew sessions after policy changes.
  • Test text, RTF, images, HTML and files in both directions.
  • Document the client, operating system, policy source and observed result.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.