OneDrive Known Folder Move is meant to be a silent policy: set the tenant ID, and Desktop, Documents and Pictures quietly move into OneDrive. When it fails, it fails per folder and per device, often without the user seeing anything. And one documented failure leaves the files in OneDrive while the original folders sit empty. Almost every failure traces back to something already on the PC before the policy arrived.
The failures sort into three groups: an older folder redirection, a Group Policy that forbids redirection, and content the sync app cannot move. Where each folder should end up once it lands is the question in OneDrive vs SharePoint. This post is about getting it there. Every Microsoft fact below was checked against Microsoft Learn and Microsoft Support on 26 September 2026.
What the Known Folder Move policies actually write
Microsoft’s OneDrive policies reference documents the silent move as a string value holding the tenant ID, with three optional DWORD values that choose individual folders. If none of the per folder values are set, the default moves all three: Desktop, Documents and Pictures.
# Values to read back on a device after the silent move policy is deployed.
# The blocking policy is named BlockKnownFolderMove in the admin template,
# but its registry value is KFMBlockOptIn. Look for that name, not the policy name.
HKLM\SOFTWARE\Policies\Microsoft\OneDrive
KFMSilentOptIn (String) = TENANT-ID
KFMSilentOptInDesktop (DWORD) = 1
KFMSilentOptInDocuments (DWORD) = 1
KFMSilentOptInPictures (DWORD) = 1
Two lines in the same reference change how you should think about the policy. First, once a folder has moved, the policy won’t affect that folder again, even if you clear its checkbox. Known Folder Move is a one-way door, not a setting you can toggle back. Second, the blocking policy’s registry value name, KFMBlockOptIn, differs from the policy name, BlockKnownFolderMove. Anyone verifying the block by searching the registry for the policy name will conclude it is missing.
In Intune, Microsoft’s education configuration reference lists the equivalent settings catalog entry as Silently move Windows known folders to OneDrive, with the tenant ID as a device setting. The trade between that and an imported template is covered in settings catalog vs administrative templates.
Why OneDrive Known Folder Move fails on a device that already had a plan
The redirect known folders article is direct about the most common blocker. The Known Folder Move Group Policy objects don’t work if Windows Folder Redirection previously sent Documents, Pictures or Desktop to a location other than OneDrive. The same article says that extending the scope of folders synced by OneDrive using Windows Folder Redirection isn’t supported. Two redirection mechanisms cannot share a folder.
The second blocker is a Group Policy most estates set years ago and forgot. The OneDrive reference states that User Configuration > Administrative Templates > Desktop > Prohibit User from manually redirecting Profile Folders must be Disabled or Not configured, and that folders will not move if it is Enabled. That policy has nothing to do with OneDrive by name, which is why nobody thinks to look at it.
The third catches migrations between organisations. If a user’s folders are already redirected to OneDrive in a different organisation, redirecting them to yours creates new folders, and the article says the user then sees an empty desktop. The files are not lost. They are in the other tenant’s OneDrive, which the user may no longer be able to reach.
The failure modes
These are the documented ways OneDrive Known Folder Move stops, and what each one means.
| What you see | What is happening | What to do |
|---|---|---|
| Error 0x80070005 | The Prohibit User from manually redirecting Profile Folders policy is enabled | Set it to Disabled or Not configured before retrying |
| Files appear in OneDrive, original folders are empty | Microsoft Support describes this alongside 0x80070005: files moved to identically named folders in OneDrive and the original locations left empty | Fix the policy first, then check where the files actually are before telling the user anything |
| Nothing moves on a device with an existing redirection | Windows Folder Redirection already points the folder elsewhere | Remove the old redirection before deploying the move |
| Folder contains another important folder | A known folder is nested inside another, for example Documents inside Desktop | Move the nested folder out first |
| Path too long | The full path including file name must be under 260 characters | Shorten the path or move the file |
| Pictures will not move | Pictures, Screenshots and Camera Roll must all be selected or not exist | Include all three |
| Folder contains a reparse point | A junction or symbolic link inside the folder cannot be protected | Remove the link |
| A file will not move | Open files cannot be moved | Close the application holding it |
| Outlook errors after the move | When the move is set by Group Policy, .pst files are migrated, and Outlook keeps looking in the original location | Relocate .pst files before the move, or repoint Outlook afterwards |
The first two rows are the same event seen from two sides. The Microsoft Support article Back up your folders with OneDrive puts them together. Error 0x80070005 means the Prohibit User policy is enabled, and the files from the selected folders may have been moved to identically named folders in OneDrive with the originals left empty. From the user’s side that looks like data loss, and it is the one to prepare the service desk for.
The .pst row comes from the Microsoft Support restrictions and limitations page. That page also recommends syncing no more than 300,000 items in total across cloud storage for best performance, which is worth checking before you move a Documents folder that has quietly become a file share.
Rollout limits Microsoft recommends
The redirect known folders article carries deployment ceilings that most guides leave out. For the prompt policy, Microsoft recommends existing devices only, limited to 5,000 devices a day and not exceeding 20,000 a week across macOS and Windows. For the silent policy, it recommends limiting existing devices to 1,000 a day and not more than 4,000 a week.
These are recommendations, not enforced limits. The silent figure is the one to plan around, because it turns an estate of 20,000 existing devices into a five week rollout at minimum. The limit applies to existing devices. New devices can take the silent policy from day one, and that is where it does the most good.
One scope limit is absolute rather than advisory: Known Folder Move doesn’t work for users syncing OneDrive files in SharePoint Server. If any users still sync from an on-premises farm, they are out of scope. How the sync app treats space on the device after the move is covered in Files On-Demand.
What I would do differently
I have not run a OneDrive Known Folder Move rollout on a production estate. My tenant is a lab, so the following is judgement built on the documentation above.
Audit before deploying. Query the fleet for the Prohibit User policy and for any Windows Folder Redirection target, and fix both first. Those two account for the failures that confuse users, and neither shows up in the OneDrive admin experience.
Treat the move as permanent. The policy will not touch a folder again once it has moved, so a pilot group is not a rehearsal you can undo by unassigning. Pick pilot users whose folders you would be comfortable moving for good.
Deal with .pst files before the policy lands, not after Outlook starts complaining. And keep to the silent policy’s daily ceiling for existing devices even though nothing enforces it. The limit exists because the first sync of a full Documents folder is not free, for the device or for the network. For how this fits the wider SharePoint picture, SharePoint Online basics covers the sharing model the moved files will then inherit.
Last verified: 26 September 2026



