EzDRM protects your content with Widevine, FairPlay and PlayReady across Live Events, Live Scheduler and Video on Demand. This article explains how to enable it for each content type, how the DRM Strictness tiers work, and which devices and browsers can play each tier.
In this article
- Overview and prerequisites
- Supported DRM systems
- Enabling EzDRM on content
- DRM Strictness tiers
- Device and browser compatibility
- What viewers see on an unsupported device
- AirPlay and Chromecast
- Troubleshooting
1. Overview and prerequisites
StreamShark offers two DRM options for protected content. Both appear under DRM in the Access Control settings of your content.
| Option | What it does | Available on |
|---|---|---|
| StreamShark DRM | AES-128 encryption of the stream, with keys served by StreamShark only to viewers who pass your access control (password, SSO, viewer group or privacy profile). Plays in any browser. | All plans with access control. |
| EzDRM | Studio-grade multi-DRM. Content is encrypted once and licensed per viewing session through Widevine, FairPlay or PlayReady. Keys never leave the device's content decryption module, and hardware tiers enforce a protected video path and HDCP on displays. | Enterprise and Broadcaster plans, as an add-on. |
Before you start
- The EzDRM add-on must be enabled on your account. Contact your account manager or StreamShark Support. Once enabled, the EzDRM option appears in Access Control for your Events, Live Scheduler and VOD.
- An EzDRM account is linked to your StreamShark account by our team. We configure Widevine and PlayReady for you. Tell us at setup time which DRM systems you need.
- FairPlay needs a certificate that only you can obtain from Apple. Apple issues FairPlay Streaming certificates directly to the content owner through your Apple Developer account. StreamShark cannot request one on your behalf. Once Apple approves your request, send us the certificate, private key, passphrase and Application Secret Key through a secure channel, and we load them into your account and enable FairPlay. Until then Safari, iPhone, iPad and Apple TV cannot play your EzDRM content. See Generating a FairPlay Streaming Certificate for the step-by-step process. Apple review is not instant, so start early.
- Content must use an access control method. DRM options only appear when the access control method is something other than No Restrictions. DRM controls who receives a license; access control identifies the viewer.
- Playback uses the StreamShark player. EzDRM content plays through StreamShark embeds and viewer pages. The legacy video.js player does not support EzDRM VOD.
2. Supported DRM systems
Each asset is encrypted once and served to all three DRM systems from the same files. Viewers automatically receive the system their device supports.
| DRM system | Used by | Hardware-backed on |
|---|---|---|
| Google Widevine | Chrome, Firefox, Edge and other Chromium browsers on desktop; Android phones, tablets and TVs; Chromecast. | Android devices with Widevine L1 (most current phones and tablets), Android TV, Chromecast. Desktop browsers use software Widevine (L3) only. |
| Apple FairPlay Streaming | Safari on macOS; all browsers on iPhone and iPad; Apple TV; Apple Vision Pro. Requires your own Apple-issued FairPlay Streaming certificate (see prerequisites). | All Apple devices. FairPlay is hardware-backed by design. |
| Microsoft PlayReady | Microsoft Edge on Windows. | Edge on Windows 10 and 11 with a supported GPU (PlayReady SL3000). Not available over Remote Desktop or in most virtual desktops. |
Chrome on Windows. Chrome supports PlayReady in the browser, but its hardware PlayReady decode path is still experimental and produces corrupted video for this content. StreamShark therefore directs Chrome on Windows viewers of hardware-tier content to open the page in Microsoft Edge. Standard-tier content plays normally in Chrome through Widevine.
3. Enabling EzDRM on content
The DRM controls are the same on every content type. Choose an access control method first, then set DRM to EzDRM, then choose a DRM Strictness.
The DRM method cannot be changed after the content is created. DRM Strictness can be changed at any time and takes effect the next time a viewer starts playback.
Live Events
- Open the event and go to Settings > Access Control.
- Choose an access control method other than None. The DRM Mode section appears.
- Under DRM Mode select EzDRM. The DRM Strictness section appears.
- Choose a tier, or leave Account default.
Video on Demand
- In the StreamShark portal go to Videos and click Add Video.
- In the Access Control section choose a method: Password Protection, Single Sign On (SSO), Viewer Group or Privacy Profile.
- Under DRM select EzDRM.
- Under DRM Strictness leave Account default or choose a tier. See section 4.
- Choose an encoding profile that includes a CMAF format and finish adding the video.
To change the strictness of an existing video, open the video, go to the Settings tab and change DRM Strictness. The DRM method is shown read-only.
Output formats for EzDRM video. EzDRM video is encoded to CMAF (fragmented MP4 served over HLS). Formats that cannot carry DRM are not produced: progressive MP4 downloads, legacy HLS and VP9 are dropped from the profile automatically. Spatial MV-HEVC formats are supported. If a profile contains no DRM-capable format the video is rejected at creation.
Live Scheduler
- Create or open a schedule and go to Settings > Privacy.
- Choose an Access Control method other than No Restrictions.
- Under DRM select EzDRM, then choose a DRM Strictness.
On an existing schedule the DRM method is locked and shows "DRM method cannot be changed after creation". DRM Strictness stays editable.
EzDRM-protected videos from your library can be added as sources to a Live Scheduler schedule directly, with no re-encode. The schedule carries its own DRM setting for the license it issues.
4. Account Default DRM Strictness
Every account has a default strictness tier. New content uses it unless you pick a tier on the asset. The dropdown shows the current default, for example Account default - Standard (plays on all devices). New accounts default to Standard. To change your account default, contact StreamShark Support.
DRM Strictness tiers
A strictness tier defines the minimum device security a viewer needs to receive a license. StreamShark applies the tier consistently across all three DRM systems, so one setting gives the same policy on every device. Tiers are enforced when each license is issued, and again on the device for the whole playback session.
| Tier (portal label) | Requirement | Widevine | FairPlay | PlayReady | Recommended for |
|---|---|---|---|---|---|
Standard (plays on all devices)SOFTWARE
|
Any certified DRM module, software or hardware. No HDCP requirement. | Security Level 1 (software crypto, L3 permitted). Output protection HDCP_NONE. | HDCP not required. Non-HDMI adapters allowed. | Output protection level 0. Any PlayReady security level. | Internal communications, training, general catalog content where reach matters most. |
Hardware DRM + HDCP requiredHARDWARE
|
Hardware-backed decryption and a protected video path. HDCP (any version) on external displays. | Security Level 3 (HW_SECURE_CRYPTO). Output protection HDCP_V1. Player requests a hardware key session up front. | HDCP Type 0. Non-HDMI adapters allowed. | Output protection level 270 (HDCP required). Requires SL3000 on Edge. | Licensed premium content, paid catalogs, most content-license contracts. |
Hardware DRM + HDCP 2.2 (maximum strictness)HARDWARE_STRICT
|
Full hardware pipeline. HDCP 2.2 or later on any external display. No analog or non-HDMI output. | Security Level 5 (HW_SECURE_ALL, Widevine L1). Output protection HDCP_V2_2. | HDCP Type 1. Non-HDMI adapters blocked. | Output protection level 300 (HDCP Type 1). | Pre-release screeners, embargoed material, content under the strictest license terms. |
How enforcement works
- Before playback: on hardware tiers the player checks whether the browser can provide hardware DRM. If it cannot, the viewer sees guidance instead of a failed stream (see section 6). No license request is made.
- At license time: StreamShark tells the DRM license server the tier's requirements for that viewer's session. A device that cannot meet them is refused a license.
- During playback: the device's DRM module enforces the license continuously. On HDCP tiers, moving the window to a non-compliant external display blacks out the video until it is moved back.
Changing the tier applies to the next license request. Existing viewers are affected when they next start playback or reload. The content is never re-encoded.
Screen recording. Standard tier uses software DRM on desktop browsers, which protects keys and content but does not defeat every screen capture tool. Hardware tiers keep video on a protected path that operating-system screen capture cannot read. Choose a hardware tier when screen recording is a concern.
5. Device and browser compatibility
Legend: Plays · Conditions (see note) · Blocked (guidance shown)
| Device / browser | DRM used | Standard | Hardware DRM + HDCP | Hardware DRM + HDCP 2.2 |
|---|---|---|---|---|
| Safari on macOS | FairPlay | Plays | Plays | Conditions: external display must be HDCP 2.2. Built-in display always plays. |
| Chrome, Firefox, Edge on macOS | Widevine (software) | Plays | Blocked: "Open in Safari" | Blocked: "Open in Safari" |
| Microsoft Edge on Windows | PlayReady | Plays | Plays | Conditions: external display must be HDCP 2.2. Not over Remote Desktop. |
| Chrome, Firefox on Windows | Widevine (software) | Plays | Blocked: "Open in Microsoft Edge" | Blocked: "Open in Microsoft Edge" |
| Linux desktop browsers | Widevine (software) | Plays | Blocked | Blocked |
| Virtual desktops, Remote Desktop, Citrix | Varies | Conditions: plays where the virtual browser has a DRM module. | Blocked: no hardware path in a remote session. | Blocked |
| iPhone, iPad (Safari and all browsers) | FairPlay | Plays | Plays | Plays. HDCP 2.2 on external displays. |
| Android phone or tablet, Widevine L1 | Widevine (hardware) | Plays | Plays | Plays. HDCP 2.2 on external displays. |
| Android phone or tablet, Widevine L3 only | Widevine (software) | Plays | Blocked | Blocked |
| Apple TV, Apple Vision Pro | FairPlay | Plays | Plays | Conditions: connected TV must be HDCP 2.2. |
| Android TV, Chromecast | Widevine (hardware) | Conditions: casting to these devices is disabled by default for EzDRM content. See section 7. | ||
Most current Android phones and tablets from major manufacturers ship with Widevine L1. Budget devices, some tablets and devices with unlocked bootloaders may be L3 only. A viewer can check their level with a DRM info app from the Play Store.
6. What viewers see on an unsupported device
When a hardware tier is set and the viewer's browser cannot provide hardware DRM, the player shows a message in place of the video:
This video needs a more secure browser
This video is protected and can only play in a browser with hardware content protection.
The message includes a platform-specific action:
- Mac: "On this Mac, open this page in Safari to watch it." with a Copy this page's link for Safari button.
- Windows: "On Windows, open this page in Microsoft Edge to watch it." with an Open in Microsoft Edge link that opens Edge directly.
- iPhone or iPad in a third-party browser: an Open in Safari link.
- Other platforms: "This browser cannot play it. iPhones, iPads and most Android devices can."
On Standard tier this message never appears.
7. AirPlay and Chromecast
AirPlay and Chromecast send video to a second device that the license policy cannot fully control, and any viewer watermark does not follow the cast. For EzDRM content StreamShark therefore disables AirPlay in the license and hides the Chromecast button by default, on every tier.
This is a policy setting, not a technical limit. If your license terms and audience allow it, StreamShark Support can enable AirPlay and casting for your account. Cast receivers still have to meet the asset's strictness tier; Chromecast and Android TV devices are Widevine L1 and satisfy hardware tiers on an HDCP-compliant TV.
8. Troubleshooting
The EzDRM option is missing from Access Control. Either the EzDRM add-on is not enabled on your account, or the access control method is set to No Restrictions. Choose an access control method first. If EzDRM still does not appear, contact Support.
Viewers see "This video needs a more secure browser". The asset is on a hardware tier and the viewer's browser only has software DRM. They should follow the on-screen guidance (Safari on Mac, Edge on Windows, or a phone or tablet). If broad desktop reach is required, set the asset to Standard.
Video goes black when moved to an external monitor. The tier requires HDCP and the monitor, cable, adapter or dock does not support it. On the HDCP 2.2 tier the whole chain must be HDCP 2.2. Play on the built-in display or use a compliant HDMI or DisplayPort connection.
Chrome on Windows shows garbled or corrupted video. Known Chrome limitation with hardware PlayReady. Use Microsoft Edge. StreamShark shows Edge guidance automatically on hardware tiers; on Standard tier Chrome uses Widevine and plays normally.
Safari, iPhone or iPad cannot play but Chrome can. FairPlay is not configured on your account. FairPlay requires an Apple-issued FairPlay Streaming certificate that you obtain through your Apple Developer account and provide to StreamShark. See Generating a FairPlay Streaming Certificate. Assets created before FairPlay was enabled need to be re-created to include FairPlay signaling.
Edge on Windows does not play a hardware tier. Check that the viewer is not in a Remote Desktop or virtual desktop session, that the GPU driver is current, and that Windows is not running in a battery-saver mode that disables hardware media. These all disable the PlayReady SL3000 path.
The video has no MP4 download or the profile changed after creation. Expected. EzDRM video is produced only in DRM-capable CMAF formats. Downloadable files would bypass DRM.
I cannot change DRM from StreamShark DRM to EzDRM on an existing asset. The DRM method is fixed at creation because it determines how the content is encrypted. Create the asset again with EzDRM selected.
Does changing the tier require re-encoding? No. Tiers are enforced at license time. The change applies the next time a viewer starts playback.