Emergency server help: get in touch

Group Policy Desktop Wallpaper and Lock Screen: Complete Guide for Windows 11

Set a company desktop wallpaper and lock screen image on Windows 11 and Windows Server 2025 with Group Policy: copy the image locally, apply the Desktop Wallpaper and lock screen policies, work around Pro edition limits and use Intune for cloud devices.

Published Updated 13 min read

A Group Policy desktop wallpaper setup has two parts: copy the image to every PC, then point the “Desktop Wallpaper” policy at that local copy so users see the same background at every sign-in. The lock screen needs a separate computer policy that only works on Enterprise, Education and Server editions. This guide covers both, plus a default wallpaper users can change, Windows 11 Pro workarounds, Intune and troubleshooting.

Short answer: Use a Group Policy Preferences Files item to copy wallpaper.jpg to C:\ProgramData\Contoso\Branding, then enable User Configuration » Policies » Administrative Templates » Desktop » Desktop » "Desktop Wallpaper" with that local path and the style Fill. For the lock screen on Enterprise or Education, enable Computer Configuration » Policies » Administrative Templates » Control Panel » Personalization » "Force a specific default lock screen and logon image". Users see the change at their next sign-in.

Which method to use

MethodWhat it setsEditionsUser can change it?
“Desktop Wallpaper” policy (User Configuration)Desktop background and stylePro, Enterprise, Education, ServerNo
GPP Registry item in HKCU\Control Panel\DesktopDefault desktop backgroundAll domain-joined editionsYes, if applied once
“Force a specific default lock screen and logon image” (Computer Configuration)Lock screen and sign-in imageEnterprise, Education, Server onlyNo, with “Prevent changing lock screen and logon image”
Intune Personalization CSPDesktop and lock screen image from a URLEnterprise and Education; Pro with conditionsNo
GPP Registry for the PersonalizationCSP keyLock screen on ProPro (undocumented)No

For most domains, the Group Policy desktop wallpaper setting plus the lock screen policy covers everything. Pro devices need one of the alternatives for the lock screen only; the desktop policy works on Pro.

Prerequisites

  • Windows 11 Pro, Enterprise or Education joined to the domain, or Windows Server 2016 to 2025.
  • Rights to create and link GPOs, and GPMC.
  • An image in JPEG (.jpg) or bitmap (.bmp) format for the policy. Microsoft recommends a 16:9 image (for example 1600 x 900 or 1920 x 1080) and keeping logos and text inside the centre 4:3 area, because other screen shapes crop the edges.
  • A share that computer accounts can read, such as \\contoso.com\NETLOGON\Branding or a dedicated file share with Domain Computers read access.

Step 1: Stage the image on each PC

The Desktop Wallpaper policy only stores a path. If the file is not available when the user signs in, Windows shows no wallpaper at all. A UNC path works on the office network but fails on laptops that sign in before the VPN connects, so copy the image locally first.

  1. Copy wallpaper.jpg (and lockscreen.jpg if needed) to \\contoso.com\NETLOGON\Branding.
  2. Create a GPO named, for example, CFG – Branding and link it to the OU that holds the computer objects.
  3. Edit it and go to Computer Configuration » Preferences » Windows Settings » Files, then choose New » File.
  4. Set Action to Replace, Source file(s) to \\contoso.com\NETLOGON\Branding\wallpaper.jpg and Destination File to C:\ProgramData\Contoso\Branding\wallpaper.jpg. Parent folders are created as needed.
  5. Add a second item for lockscreen.jpg, then run gpupdate /force on a test PC and check that both files exist.

We use Replace because Update only copies the file when it is missing and otherwise just adjusts attributes, so a new image with the same name would never arrive. Computer-side file items run as SYSTEM and read the share with the computer account, which is why Domain Computers need read access.

Method 1: The Desktop Wallpaper policy

This is the core Group Policy desktop wallpaper setting. It is a user setting, so link it to the OU that holds the user accounts, or to the computer OU with loopback processing.

  1. Create or edit a GPO linked to the user OU, for example USR – Desktop Wallpaper.
  2. Go to User Configuration » Policies » Administrative Templates » Desktop » Desktop and open “Desktop Wallpaper”.
  3. Select Enabled. In Wallpaper Name type C:\ProgramData\Contoso\Branding\wallpaper.jpg.
  4. In Wallpaper Style choose Fill for photos or Fit for logos on a plain background, then click OK.
  5. Sign out and back in on a test PC.

The policy writes the values Wallpaper and WallpaperStyle under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System. While it applies, the Background page in Settings is locked. Microsoft notes that the setting does not apply to remote desktop server sessions, so do not expect it on RDS hosts.

Lock the background picker completely

For shared or kiosk PCs, also enable User Configuration » Policies » Administrative Templates » Control Panel » Personalization » "Prevent changing desktop background". It writes NoChangingWallPaper = 1 under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop and greys out every background option. Microsoft states that you must also enable “Desktop Wallpaper” to stop users changing the image itself, so use the two together.

Apply it per computer with loopback

To give meeting-room PCs a different image from office desks, put the Group Policy desktop wallpaper setting in a GPO linked to the meeting-room computer OU and enable Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Configure user Group Policy loopback processing mode" in Merge mode on that OU. The user setting from the computer OU then wins on those PCs only.

Method 2: A default wallpaper users can change

If you only want to set a starting image, skip the policy and use a Group Policy Preferences registry item, which writes the normal user value instead of a policy value.

  1. In a GPO linked to the user OU, go to User Configuration » Preferences » Windows Settings » Registry and choose New » Registry Item.
  2. Action Update, hive HKEY_CURRENT_USER, key path Control Panel\Desktop, value name Wallpaper, type REG_SZ, data C:\ProgramData\Contoso\Branding\wallpaper.jpg.
  3. Add WallpaperStyle (REG_SZ) with 10 for Fill or 6 for Fit, and TileWallpaper (REG_SZ) with 0.
  4. On the Common tab of each item, tick “Apply once and do not reapply” so users can pick their own picture later.

Windows reads these values at sign-in, so the image appears at the next sign-in, not immediately. Do not combine this with the Group Policy desktop wallpaper policy for the same users: the policy value always wins, and the registry item then has no visible effect.

Method 3: Lock screen policy (Enterprise and Education)

  1. In a GPO linked to the computer OU, go to Computer Configuration » Policies » Administrative Templates » Control Panel » Personalization.
  2. Open “Force a specific default lock screen and logon image”, select Enabled and enter C:\ProgramData\Contoso\Branding\lockscreen.jpg. The same image is used for the lock screen and the sign-in screen.
  3. Enable “Prevent changing lock screen and logon image” in the same node so users cannot pick another picture.
  4. Run gpupdate /force and lock the PC with Win+L.

The settings write LockScreenImage and NoChangingLockScreen = 1 under HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization. Microsoft states that the lock screen policy applies only to Enterprise, Education and Server editions. On Windows 11 Pro the registry value appears, but the lock screen does not change.

Method 4: Intune (Personalization CSP)

For Entra-joined or co-managed devices:

  1. In the Intune admin center, create Devices » Configuration » Create » New policy, platform Windows 10 and later, profile type Settings catalog.
  2. Add the Personalization category and select Desktop Image Url and Lock Screen Image Url.
  3. Enter an https:// URL to a .jpg, .jpeg or .png file, for example on a public storage account or your intranet. The CSP also accepts file:// URLs to a local image.
  4. Assign to a device group and sync.

These map to ./Vendor/MSFT/Personalization/DesktopImageUrl and ./Vendor/MSFT/Personalization/LockScreenImageUrl. The read-only DesktopImageStatus and LockScreenImageStatus nodes report 1 when the download succeeded, and 3, 4, 5 or 6 for failures such as a bad file type or URL scheme. Microsoft’s configuration page lists Pro as supported, but the CSP reference adds conditions for Pro devices (shared PC settings), so test on a Pro device before you rely on it. If you prefer the classic policy, the settings catalog also contains Administrative Templates » Desktop » Desktop » Desktop Wallpaper (User).

Windows 11 Pro lock screen workaround

Many admins set the lock screen on Pro by writing the values that the Personalization CSP uses locally, with Group Policy Preferences registry items under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PersonalizationCSP:

LockScreenImagePath    REG_SZ     C:\ProgramData\Contoso\Branding\lockscreen.jpg
LockScreenImageUrl     REG_SZ     C:\ProgramData\Contoso\Branding\lockscreen.jpg
LockScreenImageStatus  REG_DWORD  1

This location is not documented by Microsoft and is not a supported policy, so a feature update can change the behaviour. Test it on your Windows 11 builds, keep it in a separate GPO targeted with item-level targeting on the Operating System edition, and move to Enterprise or Intune where you can.

Multiple monitors, RDS and VDI

A few environments need extra thought before you roll out a Group Policy desktop wallpaper setting to everyone:

  • Multiple monitors: Fill repeats the image on each screen. Span stretches one image across all screens, which only looks right when every desk has the same layout. For mixed desks, stay with Fill and a plain background with the logo in the centre.
  • RDS session hosts: the Desktop Wallpaper policy does not apply to remote desktop server sessions, and a wallpaper adds bandwidth to every session. Most farms leave the session desktop plain and brand the RemoteApp or web client instead.
  • Non-persistent VDI: bake the image into the master image under C:\ProgramData so it exists before the first sign-in, and keep the policy for the path.
  • Laptops off the network: once the Files item has copied the image, the local copy keeps working offline. Only the first copy needs access to the share, so run it while the device is still in the office.

If you manage several brands or regions, keep one image per region on the share and one Files item per region with item-level targeting, so each GPO stays small and easy to read.

Targeting and exceptions

  • Different images per site or department: use one GPO with several Files and Registry items and item-level targeting on Site or Security Group, or separate GPOs with security filtering.
  • Exempt IT staff: add a group such as SEC-Wallpaper-Exempt to the user-side GPO’s Delegation » Advanced list with Deny on Apply group policy. Keep Authenticated Users with Read so computers can still read the GPO.
  • Servers: link the lock screen GPO to server OUs only if you want the branding there; servers support the lock screen policy.
  • System information on the desktop: tools such as Sysinternals BGInfo render a bitmap with host details and set it as wallpaper at sign-in. They conflict with the Group Policy desktop wallpaper policy, which always wins, so use one or the other on a machine.

Verify it works

  1. Check the GPOs apply:
    gpupdate /force
    gpresult /scope user /r
    gpresult /scope computer /r

  2. Check the files and values:
    Test-Path C:\ProgramData\Contoso\Branding\wallpaper.jpg
    reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v Wallpaper
    reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization"

  3. Sign out and in, then open Settings » Personalization » Background. A message that some settings are managed by your organisation confirms the Group Policy desktop wallpaper policy is active.
  4. Press Win+L to check the lock screen, and sign out to see the sign-in screen.
  5. For Intune, check the status nodes in Devices » device » Device configuration, or on the device read HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PersonalizationCSP.

Troubleshooting

SymptomLikely causeFix
Black or empty desktopFile missing at sign-in, or UNC path unreachableStage the image locally and point the policy at the local path
Old image still shownFiles item uses Update, so the new file never copiedUse Replace, or change the file name for each new version
Wallpaper appears only after a second sign-inFiles item copied the image after the user profile loadedEnable “Always wait for the network at computer startup and logon”, or restart once after linking
Lock screen unchanged on ProPolicy only applies to Enterprise, Education and ServerUse Intune, the PersonalizationCSP workaround, or upgrade the edition
Files item fails with access deniedComputer account cannot read the shareGrant Domain Computers read on the share and NTFS
Image stretched or croppedWrong style for the screen shapeUse a 16:9 image and Fill, or Fit for logos
Setting missing in gpresultUser GPO linked to computer OU without loopbackLink to the user OU or enable loopback on the computer OU

If the GPO is not applied at all, check security filtering, WMI filters and events 1058 and 1030 in the System log.

Roll back or undo

  1. Set “Desktop Wallpaper”, “Prevent changing desktop background”, “Force a specific default lock screen and logon image” and “Prevent changing lock screen and logon image” to Not Configured, or unlink the GPOs. Policy values are removed at the next refresh and users can pick their own image after signing in again.
  2. Registry items set with “Apply once” stay as normal user settings; users change them in Settings.
  3. Delete the PersonalizationCSP values if you used the Pro workaround, or tick “Remove this item when it is no longer applied” before unlinking.
  4. In Intune, unassign the profile and sync.

Keep the image share and the Files items in place until every Group Policy desktop wallpaper and lock screen setting is gone, so no PC points at a missing file.

Group Policy desktop wallpaper at a glance

Group Policy Desktop Wallpaper and Lock Screen summary card: Use a Group Policy Preferences Files item to copy wallpaper.jpg to C:\ProgramData\Contoso\Branding, then enable User…
In short: Use a Group Policy Preferences Files item to copy wallpaper.jpg to C:\ProgramData\Contoso\Branding, then enable User Configuration » Policies » Administrative Templates » Desktop » Desktop » “Desktop Wallpaper” with that local path and the style Fill.

Official documentation: Configure the desktop and lock screen background, ADMX_ControlPanelDisplay Policy CSP, Personalization CSP.

Related guides: Deploy registry settings with Group Policy Preferences · Screen Lock Group Policy: Lock Windows After Inactivity the Right Way · Group Policy loopback processing: merge vs replace for RDS hosts and kiosks.

Frequently asked questions

Why does the lock screen Group Policy not work on Windows 11 Pro?

Microsoft limits “Force a specific default lock screen and logon image” to Enterprise, Education and Server editions. On Pro, use Intune’s Personalization settings or the undocumented PersonalizationCSP registry workaround, and test it on your builds.

Should the Desktop Wallpaper policy point to a UNC path or a local file?

Use a local file. If the image is not available when the user signs in, Windows shows no wallpaper, which often happens on laptops before the VPN connects. Copy the image with a Group Policy Preferences Files item first.

Can I set a default wallpaper that users can still change?

Yes. Use a Group Policy Preferences registry item for Wallpaper under HKCU\Control Panel\Desktop with “Apply once and do not reapply” instead of the Desktop Wallpaper policy, which locks the setting.

What image format and size should I use?

Use JPEG for the Group Policy setting and JPEG or PNG for Intune. A 16:9 image such as 1920 x 1080 works well, with text and logos kept inside the centre 4:3 area.

How do I update the wallpaper image later?

Replace the file on the share and make sure the Files item uses the Replace action, or use a new file name and update the policy path. Users see the new image at their next sign-in.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.