# Desktop Shortcut Group Policy: 4 Ways to Deploy Shortcuts

Source: https://srvscripts.com/guides/desktop-shortcut-group-policy/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A desktop shortcut Group Policy setup uses the Shortcuts extension of Group Policy Preferences (GPP) to create, update or delete `.lnk` and `.url` files on domain-joined computers, without login scripts. You need it when every user must see the same intranet link, file share or line-of-business application, or when one department needs its own set of icons. This guide covers GPP Shortcuts, copying ready-made shortcut files, PowerShell, Intune for cloud-managed devices, OneDrive Known Folder Move, verification and clean removal.

**Short answer:** Edit a GPO linked to the user OU, go to `User Configuration » Preferences » Windows Settings » Shortcuts`, choose **New » Shortcut**, set **Action** to Replace, **Target type** to URL or File System Object, **Location** to Desktop, and fill in the target. On the **Common** tab tick “Remove this item when it is no longer applied”. Run `gpupdate /force` and the shortcut appears on the desktop.

In short: Edit a GPO linked to the user OU, go to User Configuration » Preferences » Windows Settings » Shortcuts, choose New » Shortcut, set Action to Replace, Target type to URL or File System Object, Location to Desktop, and fill in the target.

## Which method to use

Every desktop shortcut Group Policy option below ends with the same file on the desktop. They differ in who maintains it and how it is removed.

| Method | Scope | Needs | Pros | Cons |
| --- | --- | --- | --- | --- |
| GPP Shortcuts | User or computer | AD domain, GPMC | No files to host; item-level targeting; clean removal | Icon files must exist on the client |
| GPP Files (copy .lnk/.url) | User or computer | Readable share, e.g. NETLOGON | Keeps exact shortcut properties built on a reference PC | You maintain the source files |
| PowerShell (WScript.Shell) | Per machine or per user | Script delivery (GPO script, RMM) | Works anywhere PowerShell runs | No automatic removal |
| Intune platform script or Win32 app | Device or user | Intune licence, enrolled devices | Covers Entra-joined devices with no line of sight to a DC | Scripts run once; removal needs a second script or an uninstall command |

For domain-joined PCs, GPP Shortcuts is the method we recommend. Use the Files method only when a shortcut needs properties the Shortcuts dialog does not expose.

## Prerequisites

Before you create a desktop shortcut Group Policy item, check the following:

- Windows 11 Pro, Enterprise or Education (or Windows Server 2016 to 2025) joined to the domain. Windows 11 Home does not process domain Group Policy.

- Group Policy Management Console on a domain controller or through RSAT, and rights to create and link GPOs.

- The target of each shortcut reachable from the client: the URL, the UNC path such as `\\fs01\Departments`, or the installed program.

- Icon files stored locally or on a share that users and computers can read.

## Choose the location

The **Location** field decides where a desktop shortcut Group Policy item writes the file. Locations other than the All Users entries are relative to the signed-in user.

| Location | Folder on Windows 11 | Use it when |
| --- | --- | --- |
| Desktop | %USERPROFILE%\Desktop (or the OneDrive Desktop after Known Folder Move) | A user GPO should give each user their own copy; the user can delete it until the next refresh |
| All Users Desktop | C:\Users\Public\Desktop | Every user of the PC must see it, for example on shared or kiosk PCs; best from Computer Configuration |
| Start Menu / Programs | %APPDATA%\Microsoft\Windows\Start Menu\Programs | The link should appear in All apps without cluttering the desktop |
| All Users Start Menu / All Users Programs | C:\ProgramData\Microsoft\Windows\Start Menu\Programs | The same for every user of the PC |
|  | Any path, typed with the name, e.g. %CommonDesktopDir%\IT\Service Desk | Subfolders or non-standard locations |

To place a shortcut in a subfolder of a standard location, put the folder in the **Name** field, for example Contoso\Service Desk. On Windows 11 a Start Menu shortcut shows in All apps; pinning to Start or the taskbar is a separate setting.

## Method 1: Group Policy Preferences Shortcuts

This is the standard desktop shortcut Group Policy method. Create one GPO per purpose (for example USR – Desktop Shortcuts) so you can filter and remove it as a unit.

### Create the GPO

- Open **Group Policy Management** (`gpmc.msc`).

- Right-click the OU that holds the user accounts and choose **Create a GPO in this domain, and Link it here**. For All Users Desktop shortcuts, link a computer GPO to the workstation OU instead.

- Right-click the new GPO and choose **Edit**.

- Go to `User Configuration » Preferences » Windows Settings » Shortcuts` (or the same node under Computer Configuration), right-click and choose **New » Shortcut**.

### Actions

| Action | What it does |
| --- | --- |
| Create | Creates the shortcut only if it does not exist; later edits in the GPO are not pushed. |
| Replace | Deletes and recreates the shortcut on every refresh, so changes always reach clients. Required for “Remove this item when it is no longer applied”. |
| Update | Changes only the properties you filled in and creates the shortcut if missing. |
| Delete | Removes a shortcut; name, target type and location must match the existing one. |

### URL shortcut to the intranet

- **Action:** Replace. **Name:** Contoso Intranet.

- **Target type:** URL. **Location:** Desktop.

- **Target URL:** `https://intranet.contoso.com/`.

- Optional: **Icon file path** `%SystemRoot%\System32\shell32.dll` and an **Icon index**, or a `.ico` file on a readable share.

A URL shortcut is saved as a `.url` file and opens in the user’s default browser.

### Shortcut to a file share

- **Target type:** File System Object. **Name:** Department Files.

- **Target path:** `\\fs01\Departments\%LogonDomain%` or a fixed path such as `\\fs01\Departments\Sales`.

- Leave **Arguments** and **Start in** empty for folders.

Point shortcuts at UNC paths rather than mapped drive letters. If a path does use a mapped drive, the item must be under User Configuration, the drive must exist before the shortcut is processed, and “Run in logged-on user’s security context” must be ticked on the Common tab.

### Application shortcut

- **Target type:** File System Object. **Target path:** `%ProgramFiles%\Contoso\CRM\crm.exe`.

- **Arguments:** any switches, e.g. `/profile sales`. **Start in:** `%ProgramFiles%\Contoso\CRM` (no quotes, no trailing backslash).

- **Run:** Normal window or Maximized. **Comment:** the tooltip text.

GPP resolves variables in the target path before it writes the shortcut. To keep the variable inside the shortcut so that each PC resolves it, use the unresolved syntax `%<ProgramFiles>%`. Only environment variables work in that form.

### Shell object shortcuts

Choose **Target type** Shell Object to link to This PC, Network, Control Panel items or printers. Click the browse button next to **Target object** and pick the object. This is the cleanest way to put a This PC icon on every desktop.

### Common tab options

- **Remove this item when it is no longer applied:** deletes the shortcut when the GPO stops applying. Selecting it switches the action to Replace.

- **Run in logged-on user’s security context:** user preferences run as SYSTEM by default; tick this when the target is a mapped drive or a share only the user can read.

- **Apply once and do not reapply:** creates the shortcut once and lets the user delete it permanently.

- **Stop processing items in this extension if an error occurs on this item:** leave clear unless later items depend on this one.

## Method 2: Copy .lnk or .url files with GPP Files

Build the shortcut on a reference PC, then copy it with the Files extension. This keeps properties such as “Run as administrator” flags or compatibility settings stored in the file.

- Save the shortcut to a share readable by Domain Computers and Authenticated Users, e.g. `\\contoso.com\NETLOGON\Shortcuts\CRM.lnk`.

- In a computer GPO go to `Computer Configuration » Preferences » Windows Settings » Files` and choose **New » File**.

- **Action:** Replace. **Source file(s):** `\\contoso.com\NETLOGON\Shortcuts\CRM.lnk`. **Destination File:** `%CommonDesktopDir%\CRM.lnk`.

- For a per-user copy, create the item under User Configuration with the destination `%DesktopDir%\CRM.lnk`.

A `.url` file is plain text, so you can write it in Notepad:

```
[InternetShortcut]
URL=https://intranet.contoso.com/
IconFile=\\contoso.com\NETLOGON\Shortcuts\intranet.ico
IconIndex=0
```

## Method 3: PowerShell with WScript.Shell

Use a script where Group Policy is not available, for example from an RMM tool or a computer startup script. This creates a shortcut on the Public Desktop and needs administrator rights:

```
$wsh = New-Object -ComObject WScript.Shell
$lnk = $wsh.CreateShortcut("$env:PUBLIC\Desktop\Contoso CRM.lnk")
$lnk.TargetPath = "C:\Program Files\Contoso\CRM\crm.exe"
$lnk.Arguments = "/profile sales"
$lnk.WorkingDirectory = "C:\Program Files\Contoso\CRM"
$lnk.IconLocation = "C:\Program Files\Contoso\CRM\crm.exe,0"
$lnk.Description = "Contoso CRM"
$lnk.Save()
```

For a web link, write a `.url` file:

```
$url = "$env:PUBLIC\Desktop\Contoso Intranet.url"
Set-Content -Path $url -Encoding ASCII -Value @(
  "[InternetShortcut]",
  "URL=https://intranet.contoso.com/"
)
```

To remove it later, run `Remove-Item "$env:PUBLIC\Desktop\Contoso CRM.lnk" -ErrorAction SilentlyContinue`.

## Method 4: Intune for Entra-joined devices

Intune has no dedicated shortcut profile, so deliver the PowerShell above.

### Platform script

- In the Intune admin center go to **Devices » Scripts and remediations » Platform scripts » Add » Windows 10 and later**.

- Upload the script. Set **Run this script using the logged on credentials** to No so it runs as SYSTEM and can write to `C:\Users\Public\Desktop`.

- Set **Run script in 64 bit PowerShell Host** to Yes so `$env:ProgramFiles` points to the 64-bit folder.

- Assign it to a device group.

A platform script does not run again after it succeeds, so a deleted shortcut stays deleted until you change the script.

### Win32 app

For shortcuts that must come back and be removable, package an install script and an uninstall script with the Win32 Content Prep Tool. Use a **File** detection rule on `C:\Users\Public\Desktop` with the shortcut name. Intune reinstalls the app if the file disappears and runs the uninstall command when you assign it as Uninstall.

## OneDrive Known Folder Move

With Known Folder Move, the user’s Desktop is redirected into OneDrive, for example `%USERPROFILE%\OneDrive - Contoso\Desktop`. A per-user desktop shortcut Group Policy item that uses the Desktop location follows the redirected folder, and the file is synchronised to every PC the user signs in to. Three things follow from that:

- A shortcut to a local program appears on devices where the program is not installed.

- Replace recreates the file on every refresh, which OneDrive then uploads again.

- If two PCs write the same file at once, OneDrive may keep a copy with the computer name added.

To avoid this, deliver shortcuts to All Users Desktop from Computer Configuration. The Public Desktop is not redirected, is merged into every user’s desktop view and never syncs to OneDrive.

## Target shortcuts with item-level targeting

One desktop shortcut Group Policy object can hold shortcuts for many departments. Open a shortcut item, go to **Common**, tick **Item-level targeting** and click **Targeting**.

- **Security Group:** CONTOSO\GRP-Sales, so only members get the CRM shortcut. Under Computer Configuration, choose computer groups.

- **Organizational Unit:** limit an item to users in one OU.

- **Operating System:** restrict an item to Windows 11 or to Windows Server for admin tools.

- **File Match:** create the application shortcut only if `crm.exe` exists, so broken icons never appear on PCs without the program.

Combine conditions with **And**/**Or** and use **Item Options » Is Not** for exclusions. With “Remove this item when it is no longer applied” ticked, the shortcut disappears when a user leaves the group. For whole-GPO exclusions, use security filtering instead.

## Verify it works

- On a test PC run `gpupdate /force`. User preferences apply at the next sign-in or background refresh.

- Run `gpresult /r /scope user` (or `/scope computer`) and check that the GPO is listed under Applied Group Policy Objects.

- Check the file exists:

```
Get-ChildItem "$env:USERPROFILE\Desktop", "$env:PUBLIC\Desktop" -Filter *.lnkGet-ChildItem "$env:PUBLIC\Desktop" -Filter *.url
```

- Open **Event Viewer » Windows Logs » Application** and filter on the source Group Policy Shortcuts. A warning (event ID 4098) names the item and the error code when it fails.

- For detail, enable `Computer Configuration » Policies » Administrative Templates » System » Group Policy » Logging and tracing » "Configure Shortcuts preference logging and tracing"`; trace files are written to `%SystemDrive%\ProgramData\GroupPolicy\Preference\Trace`.

## Troubleshooting

When a desktop shortcut Group Policy item fails, the cause is usually scope, permissions or the action type:

| Symptom | Cause | Fix |
| --- | --- | --- |
| No shortcut, GPO not in gpresult | Wrong OU link, security filtering or a WMI filter | Link the user GPO to the user OU, or use loopback for computer OUs |
| Event 4098 with 0x80070005 | SYSTEM or the user cannot write the folder, often All Users Desktop from a user-context item | Create Public Desktop items under Computer Configuration |
| Blank or generic icon | Icon path unreachable or resolved on the admin PC | Store icons locally or on NETLOGON; use %% syntax |
| Changes not reaching users | Action set to Create | Change the action to Replace or Update |
| Duplicate “-PCNAME” shortcuts | OneDrive KFM syncing per-user copies | Move the item to All Users Desktop |
| Shortcut to mapped drive fails | Drive not mapped yet or item runs as SYSTEM | Use a UNC path, or tick “Run in logged-on user’s security context” |

If the GPO is missing entirely, work through the general Group Policy checks (`gpresult /h`, events 1058 and 1030) before looking at the preference item.

## Roll back or remove shortcuts

- **Items with “Remove this item when it is no longer applied”:** unlink the GPO, delete the item, or remove users from the targeting group. Shortcuts are deleted at the next refresh.

- **Items without that option:** change the action to Delete with the same name, target type and location, leave it in place for a few weeks, then remove the item.

- **GPP Files copies:** add a Files item with action Delete for the destination path.

- **Scripts and Intune:** run the `Remove-Item` line as a new script, or assign the Win32 app as Uninstall.

Test every desktop shortcut Group Policy change on a pilot OU first, and keep shortcut names stable: the Delete action and removal both match on the name.

## Desktop shortcut Group Policy at a glance

**Official documentation:** [Configure a Shortcut Item (Group Policy Preferences)](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/cc753580(v=ws.10)), [Configure Common Options for preference items](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/cc772371(v=ws.10)), [Use PowerShell scripts on Windows devices in Intune](https://learn.microsoft.com/en-us/intune/intune-service/apps/powershell-scripts).

**Related guides:** [Map Network Drives Group Policy: 2026 Item-Level Targeting Made Easy](/guides/map-network-drives-group-policy/) · [Deploy registry settings with Group Policy Preferences](/guides/registry-group-policy-preferences/) · [Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030](/guides/group-policy-not-applying/).

## Frequently asked questions

### Should I use Create, Replace or Update for GPP shortcuts?

Use Replace for most shortcuts. It rewrites the file on every refresh so edits reach clients, and it is required when you tick “Remove this item when it is no longer applied”. Create never pushes later changes.

### Why does the shortcut come back after users delete it?

Replace and Update recreate a missing shortcut at every Group Policy refresh. Tick “Apply once and do not reapply” on the Common tab if users may delete it permanently.

### How do I put a shortcut on the desktop for all users of a PC?

Create the item under Computer Configuration with the location set to All Users Desktop. It writes to C:\Users\Public\Desktop, which every profile shows and OneDrive does not sync.

### Can Intune deploy desktop shortcuts?

Yes, but there is no shortcut profile. Deploy a PowerShell platform script that runs as SYSTEM, or a Win32 app with a file detection rule if the shortcut must be restored and removable.

### Do GPP shortcuts work on Windows 11 24H2 and 25H2?

Yes. The Shortcuts preference extension is part of Windows and works on domain-joined Windows 11 Pro, Enterprise and Education and on Windows Server 2016 to 2025.
