IntuneHow-to

OneDrive Known Folder Move with Intune: silent sign-in, silent move and stuck folders

Deploy OneDrive Known Folder Move through the Intune settings catalog, roll it out at a safe pace, read the sync health dashboard, and fix the documented reasons a folder refuses to move.

Known Folder Move (KFM) quietly redirects Desktop, Documents and Pictures into OneDrive, so a lost laptop or a failed disk stops being a data-loss event. The policies are simple, but the rollout has a few sharp edges: a missing tenant ID, a user who isn't silently signed in, or a folder that OneDrive refuses to move. In this post I'll walk through the Intune settings, a safe rollout pace, the reports that show progress, and the documented blockers.

How this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (3 steps: Create the settings catalog profile; Assign in waves; Turn on the sync health dashboard). 3. Verify. 4. Tips & gotchas. Toolbox: 0x80070005, …\Microsoft\OneDrive, Create › New policy, Health › OneDrive Sync, SilentAccountConfig.1Prerequisites2Step-by-step3Verify4Tips & gotchas1Create the settingscatalog profile2Assign in waves3Turn on the sync healthdashboardTOOLBOX0x80070005…\Microsoft\OneDriveCreate › New policyHealth › OneDrive SyncSilentAccountConfigHow this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (3 steps: Create the settings catalog profile; Assign in waves; Turn on the sync health dashboard). 3. Verify. 4. Tips & gotchas. Toolbox: 0x80070005, …\Microsoft\OneDrive, Create › New policy, Health › OneDrive Sync, SilentAccountConfig.1Prerequisites2Step-by-step1Create the settings catalog profile2Assign in waves3Turn on the sync health dashboard3Verify4Tips & gotchasTOOLBOX0x80070005…\Microsoft\OneDriveCreate › New policyHealth › OneDrive SyncSilentAccountConfig
At a glance: how this guide is organised · 3 steps · 5 key settings and tools

Prerequisites#

  • Device identity: silent account configuration works on PCs that are joined to Microsoft Entra ID, because the sync app picks up the signed-in user's Windows credentials. Users still see OneDrive Setup once to confirm folders and location.
  • Sync app: Microsoft recommends the latest available OneDrive build before deploying KFM. The sync health reports additionally require version 22.232 or later.
  • Tenant ID: the silent-move and prompt policies won't do anything without it. Copy it from the Microsoft Entra admin center overview page before you start.
  • No conflicting Group Policy: the Windows Folder Redirection policies must not redirect Documents, Pictures or Desktop elsewhere, and Prohibit User from manually redirecting Profile Folders must be Disabled or Not configured. If it's Enabled, the move fails with error 0x80070005.
  • Not SharePoint Server: KFM doesn't work for users syncing OneDrive from SharePoint Server.

Step-by-step#

Step 1: Create the settings catalog profile#

In the Microsoft Intune admin center go to Devices › Manage devices › Configuration › Create › New policy, choose Windows 10 and later and Settings catalog. Select Add settings, search for OneDrive, and pick the device-scoped versions of these settings (they map to HKLM\SOFTWARE\Policies\Microsoft\OneDrive):

SettingValueRegistry value written
Silently sign in users to the OneDrive sync app with their Windows credentialsEnabledSilentAccountConfig = 1
Silently move Windows known folders to OneDriveEnabled, your tenant ID, optionally show a notification after folders are redirectedKFMSilentOptIn = tenant ID, KFMSilentOptInWithNotification = 1
Prompt users to move Windows known folders to OneDriveEnabled, your tenant ID (recommended alongside the silent policy)KFMOptInWithWizard = tenant ID
Prevent users from redirecting their Windows known folders to their PCEnabledKFMBlockOptOut = 1
Use OneDrive Files On-DemandEnabledFilesOnDemandEnabled = 1
Enable sync health reporting for OneDriveEnabledEnableSyncAdminReports = 1
Limit the sync app upload rate to a percentage of throughputEnabled, 50% or higher, temporarily during the rolloutAutomaticUploadBandwidthPercentage

The silent move policy can move all three folders or a selection; once a folder has been moved, the policy never touches it again, even if you later clear its checkbox. If the silent move fails, the prompt policy gives users a dialog to correct the error and continue, which is why Microsoft suggests deploying both.

Watch out: There is also a setting called Prevent users from moving their Windows known folders to OneDrive (KFMBlockOptIn). It does the opposite of what you want here and is ignored while either KFM policy is enabled. Don't confuse it with Prevent users from redirecting their Windows known folders to their PC.

Step 2: Assign in waves#

Uploading everyone's Documents folder on the same morning will saturate your internet links. Microsoft's guidance is to limit the silent policy to about 1,000 existing devices a day and no more than 4,000 a week, and the prompt policy to 5,000 a day and 20,000 a week. Start with a pilot group of IT staff, then expand by department, keeping the upload-rate limit on until the bulk of the content is in the cloud.

Step 3: Turn on the sync health dashboard#

The dashboard lives in the Microsoft 365 Apps admin center at config.office.com › Health › OneDrive Sync, not in the Microsoft Intune admin center. An Office Apps Administrator or Microsoft 365 Administrator enables it under Setup by generating a Tenant Association Key; afterwards Global Reader, Security Administrator, Office Apps Administrator or Reports Reader can view it. Devices must be able to reach https://clients.config.office.net, must have EnableSyncAdminReports applied, and can take up to three days to appear. Devices also need roughly five hours of uptime with the user signed in to OneDrive before they report.

Verify#

On a pilot device, confirm the policy arrived and OneDrive acted on it:

Command Prompt
reg.exe query HKLM\SOFTWARE\Policies\Microsoft\OneDrive

You should see SilentAccountConfig, KFMSilentOptIn with your tenant ID and the other values from the table. Then open the OneDrive sync app settings, go to Sync and backup › Manage backup (older builds show a Backup tab) and check that Desktop, Documents and Pictures are backed up and that the stop option is greyed out. In File Explorer, right-click Documents and open Properties › Location: the path should sit under the OneDrive folder. In Intune, the profile's Per setting status shows which devices received each setting. In the sync health dashboard, the Known folders card on the Overview tab tracks the percentage of devices with folders moved, and the Devices tab lists each device with its known folders, app version and any errors.

Tips & gotchas#

Folders that won't move#

When the silent move fails, the user sees the KFM dialog with a reason. Microsoft's Fix problems with folder backup page documents the causes:

MessageCause and fix
File exceeds the maximum path length in WindowsFull path including the file name must stay under 260 characters; shorten folder or file names
File exceeds the maximum file sizeOneDrive can't sync files over 250 GB; move them out of the folder
The file name isn't allowed in OneDriveNames can't start with a space or contain \ : / * ? < > " |
The folder isn't selected for syncingIn OneDrive settings, Choose folders, make sure the folder (for Pictures also Screenshots and Camera Roll) is selected
Important folders aren't in the default locationsThe folder contains another known folder or the OneDrive folder itself; move the nested folder out first
Error code 0x80070005The Prohibit User from manually redirecting Profile Folders Group Policy is enabled; content may already have been copied into OneDrive, so move it back and fix the policy
Folder contains a reparse pointJunctions or symlinks can't be protected; remove the link

Other things worth knowing#

  • Silent sign-in didn't happen. Check that the device is joined to Microsoft Entra ID, that the user is actually signed in to Windows with that account, and that Prevent the sync app from automatically signing in users with existing credentials (DisableAutoConfig) isn't also deployed.
  • Path length. The local root is C:\Users\<user>\OneDrive - <organization name>, which eats into the 260-character limit. The Set a custom name for the OneDrive folder policy (now in the Windows settings catalog) shortens it for new users; the full root path can't exceed 120 characters.
  • Coming from Folder Redirection. Disable the Windows Folder Redirection policy first and leave the files in place, then enable KFM; for folders on a file share, use Migration Manager to copy content into the users' OneDrive before switching.
  • Folders redirected to another tenant aren't migrated; the user gets empty folders in your tenant and must move files manually. Disable the other redirection first where possible.
  • Setting a policy back to Not configured doesn't undo it. OneDrive policies leave the registry value in place; to reverse a decision, deploy the setting as Disabled.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)