Known Folder Move (KFM) quietly redirects Desktop, Documents and Pictures into OneDrive, so a lost laptop or a failed disk stops being a data-loss event. The policies are simple, but the rollout has a few sharp edges: a missing tenant ID, a user who isn't silently signed in, or a folder that OneDrive refuses to move. In this post I'll walk through the Intune settings, a safe rollout pace, the reports that show progress, and the documented blockers.
Prerequisites#
- Device identity: silent account configuration works on PCs that are joined to Microsoft Entra ID, because the sync app picks up the signed-in user's Windows credentials. Users still see OneDrive Setup once to confirm folders and location.
- Sync app: Microsoft recommends the latest available OneDrive build before deploying KFM. The sync health reports additionally require version 22.232 or later.
- Tenant ID: the silent-move and prompt policies won't do anything without it. Copy it from the Microsoft Entra admin center overview page before you start.
- No conflicting Group Policy: the Windows Folder Redirection policies must not redirect Documents, Pictures or Desktop elsewhere, and Prohibit User from manually redirecting Profile Folders must be Disabled or Not configured. If it's Enabled, the move fails with error
0x80070005. - Not SharePoint Server: KFM doesn't work for users syncing OneDrive from SharePoint Server.
Step-by-step#
Step 1: Create the settings catalog profile#
In the Microsoft Intune admin center go to Devices › Manage devices › Configuration › Create › New policy, choose Windows 10 and later and Settings catalog. Select Add settings, search for OneDrive, and pick the device-scoped versions of these settings (they map to HKLM\SOFTWARE\Policies\Microsoft\OneDrive):
| Setting | Value | Registry value written |
|---|---|---|
| Silently sign in users to the OneDrive sync app with their Windows credentials | Enabled | SilentAccountConfig = 1 |
| Silently move Windows known folders to OneDrive | Enabled, your tenant ID, optionally show a notification after folders are redirected | KFMSilentOptIn = tenant ID, KFMSilentOptInWithNotification = 1 |
| Prompt users to move Windows known folders to OneDrive | Enabled, your tenant ID (recommended alongside the silent policy) | KFMOptInWithWizard = tenant ID |
| Prevent users from redirecting their Windows known folders to their PC | Enabled | KFMBlockOptOut = 1 |
| Use OneDrive Files On-Demand | Enabled | FilesOnDemandEnabled = 1 |
| Enable sync health reporting for OneDrive | Enabled | EnableSyncAdminReports = 1 |
| Limit the sync app upload rate to a percentage of throughput | Enabled, 50% or higher, temporarily during the rollout | AutomaticUploadBandwidthPercentage |
The silent move policy can move all three folders or a selection; once a folder has been moved, the policy never touches it again, even if you later clear its checkbox. If the silent move fails, the prompt policy gives users a dialog to correct the error and continue, which is why Microsoft suggests deploying both.
Watch out: There is also a setting called Prevent users from moving their Windows known folders to OneDrive (KFMBlockOptIn). It does the opposite of what you want here and is ignored while either KFM policy is enabled. Don't confuse it with Prevent users from redirecting their Windows known folders to their PC.
Step 2: Assign in waves#
Uploading everyone's Documents folder on the same morning will saturate your internet links. Microsoft's guidance is to limit the silent policy to about 1,000 existing devices a day and no more than 4,000 a week, and the prompt policy to 5,000 a day and 20,000 a week. Start with a pilot group of IT staff, then expand by department, keeping the upload-rate limit on until the bulk of the content is in the cloud.
Step 3: Turn on the sync health dashboard#
The dashboard lives in the Microsoft 365 Apps admin center at config.office.com › Health › OneDrive Sync, not in the Microsoft Intune admin center. An Office Apps Administrator or Microsoft 365 Administrator enables it under Setup by generating a Tenant Association Key; afterwards Global Reader, Security Administrator, Office Apps Administrator or Reports Reader can view it. Devices must be able to reach https://clients.config.office.net, must have EnableSyncAdminReports applied, and can take up to three days to appear. Devices also need roughly five hours of uptime with the user signed in to OneDrive before they report.
Verify#
On a pilot device, confirm the policy arrived and OneDrive acted on it:
reg.exe query HKLM\SOFTWARE\Policies\Microsoft\OneDriveYou should see SilentAccountConfig, KFMSilentOptIn with your tenant ID and the other values from the table. Then open the OneDrive sync app settings, go to Sync and backup › Manage backup (older builds show a Backup tab) and check that Desktop, Documents and Pictures are backed up and that the stop option is greyed out. In File Explorer, right-click Documents and open Properties › Location: the path should sit under the OneDrive folder. In Intune, the profile's Per setting status shows which devices received each setting. In the sync health dashboard, the Known folders card on the Overview tab tracks the percentage of devices with folders moved, and the Devices tab lists each device with its known folders, app version and any errors.
Tips & gotchas#
Folders that won't move#
When the silent move fails, the user sees the KFM dialog with a reason. Microsoft's Fix problems with folder backup page documents the causes:
| Message | Cause and fix |
|---|---|
| File exceeds the maximum path length in Windows | Full path including the file name must stay under 260 characters; shorten folder or file names |
| File exceeds the maximum file size | OneDrive can't sync files over 250 GB; move them out of the folder |
| The file name isn't allowed in OneDrive | Names can't start with a space or contain \ : / * ? < > " | |
| The folder isn't selected for syncing | In OneDrive settings, Choose folders, make sure the folder (for Pictures also Screenshots and Camera Roll) is selected |
| Important folders aren't in the default locations | The folder contains another known folder or the OneDrive folder itself; move the nested folder out first |
| Error code 0x80070005 | The Prohibit User from manually redirecting Profile Folders Group Policy is enabled; content may already have been copied into OneDrive, so move it back and fix the policy |
| Folder contains a reparse point | Junctions or symlinks can't be protected; remove the link |
Other things worth knowing#
- Silent sign-in didn't happen. Check that the device is joined to Microsoft Entra ID, that the user is actually signed in to Windows with that account, and that Prevent the sync app from automatically signing in users with existing credentials (
DisableAutoConfig) isn't also deployed. - Path length. The local root is
C:\Users\<user>\OneDrive - <organization name>, which eats into the 260-character limit. The Set a custom name for the OneDrive folder policy (now in the Windows settings catalog) shortens it for new users; the full root path can't exceed 120 characters. - Coming from Folder Redirection. Disable the Windows Folder Redirection policy first and leave the files in place, then enable KFM; for folders on a file share, use Migration Manager to copy content into the users' OneDrive before switching.
- Folders redirected to another tenant aren't migrated; the user gets empty folders in your tenant and must move files manually. Disable the other redirection first where possible.
- Setting a policy back to Not configured doesn't undo it. OneDrive policies leave the registry value in place; to reverse a decision, deploy the setting as Disabled.