How to Prevent Users from Moving Known Folders to OneDrive with Intune
By default, Windows prompts users to back up their Desktop, Documents, and Pictures folders to OneDrive. In some organizations, you may want to keep those files on local drives for security, compliance, or storage management reasons. Microsoft Intune lets you block folder redirection so users can’t move their known folders into OneDrive. Here’s how to set it up.
Why Block Known Folder Moves?
When users redirect folders to OneDrive, they store files in the cloud automatically. That’s great for backup, but in certain environments you may need to:
-
Keep data on-premises
-
Prevent accidental sharing of sensitive files
-
Control storage costs
-
Enforce a consistent backup strategy
Blocking the move doesn’t undo any folders already synced. It simply prevents new migrations once the policy is in place.
Step-by-Step: Create the Policy in Intune
-
Sign in to the Microsoft Intune admin center.
-
Go to Devices → Configuration profiles.
-
Click + Create profile.
-
Choose Platform: Windows 10 and later.
-
Choose Profile type: Settings catalog.
-
Click Create.
Define Basic Details
-
On the Basics tab, enter a clear name, such as “Block Known Folder Move to OneDrive.”
-
Add an optional description explaining the policy purpose.
-
Click Next.
Select the OneDrive Setting
-
On the Configuration settings tab, click + Add settings.
-
In the picker, expand OneDrive.
-
Find Prevent users from moving their Windows known folders to OneDrive.
-
Toggle it to Enabled.
-
Click Next.
Assign the Policy
-
(Optional) Add Scope tags if you use them to filter policies.
-
On the Assignments tab, click + Add groups under Included groups.
-
Select the Azure AD group that contains the target devices (for example, “All Corporate PCs”).
-
Click Next.
Review and Create
-
On the Review + create tab, verify your settings.
-
If everything looks right, click Create.
-
You’ll see a success message when the policy is created.
Verify Deployment
-
It can take up to eight hours to apply.
-
In Intune, go to Devices → Configuration profiles and check the policy’s Device check-in status.
-
On a client PC, open Event Viewer and navigate to Applications and Services Logs → Microsoft → Windows → DeviceManagement-Enterprise-Diagnostics-Provider → Admin. Look for Event ID 814 to confirm the setting applied.
Removing or Deleting the Policy
-
To remove a group assignment, edit the policy’s Assignments tab and click Remove under the included groups.
-
To delete the policy entirely, find it in Configuration profiles, click the three-dot menu, and choose Delete.
Blocking known folder moves ensures your critical data stays where you need it. With this policy in place, users won’t see the OneDrive folder protection prompt or be able to start protection manually. Intelligent use of Intune policies like this gives you tighter control over where your files live.

