A desktop shortcut Group Policy setup uses the Shortcuts extension of Group Policy Preferences (GPP) to create, update or delete .lnk and .url files on domain-joined computers, without login scripts. You need it when every user must see the same intranet link, file share or line-of-business application, or when one department needs its own set of icons. This guide covers GPP Shortcuts, copying ready-made shortcut files, PowerShell, Intune for cloud-managed devices, OneDrive Known Folder Move, verification and clean removal.
Short answer: Edit a GPO linked to the user OU, go to User Configuration » Preferences » Windows Settings » Shortcuts, choose New » Shortcut, set Action to Replace, Target type to URL or File System Object, Location to Desktop, and fill in the target. On the Common tab tick “Remove this item when it is no longer applied”. Run gpupdate /force and the shortcut appears on the desktop.
Table of Contents
Which method to use
Every desktop shortcut Group Policy option below ends with the same file on the desktop. They differ in who maintains it and how it is removed.
| Method | Scope | Needs | Pros | Cons |
|---|---|---|---|---|
| GPP Shortcuts | User or computer | AD domain, GPMC | No files to host; item-level targeting; clean removal | Icon files must exist on the client |
| GPP Files (copy .lnk/.url) | User or computer | Readable share, e.g. NETLOGON | Keeps exact shortcut properties built on a reference PC | You maintain the source files |
| PowerShell (WScript.Shell) | Per machine or per user | Script delivery (GPO script, RMM) | Works anywhere PowerShell runs | No automatic removal |
| Intune platform script or Win32 app | Device or user | Intune licence, enrolled devices | Covers Entra-joined devices with no line of sight to a DC | Scripts run once; removal needs a second script or an uninstall command |
For domain-joined PCs, GPP Shortcuts is the method we recommend. Use the Files method only when a shortcut needs properties the Shortcuts dialog does not expose.
Prerequisites
Before you create a desktop shortcut Group Policy item, check the following:
- Windows 11 Pro, Enterprise or Education (or Windows Server 2016 to 2025) joined to the domain. Windows 11 Home does not process domain Group Policy.
- Group Policy Management Console on a domain controller or through RSAT, and rights to create and link GPOs.
- The target of each shortcut reachable from the client: the URL, the UNC path such as
\\fs01\Departments, or the installed program. - Icon files stored locally or on a share that users and computers can read.
Choose the location
The Location field decides where a desktop shortcut Group Policy item writes the file. Locations other than the All Users entries are relative to the signed-in user.
| Location | Folder on Windows 11 | Use it when |
|---|---|---|
| Desktop | %USERPROFILE%\Desktop (or the OneDrive Desktop after Known Folder Move) | A user GPO should give each user their own copy; the user can delete it until the next refresh |
| All Users Desktop | C:\Users\Public\Desktop | Every user of the PC must see it, for example on shared or kiosk PCs; best from Computer Configuration |
| Start Menu / Programs | %APPDATA%\Microsoft\Windows\Start Menu\Programs | The link should appear in All apps without cluttering the desktop |
| All Users Start Menu / All Users Programs | C:\ProgramData\Microsoft\Windows\Start Menu\Programs | The same for every user of the PC |
| <Specify full path> | Any path, typed with the name, e.g. %CommonDesktopDir%\IT\Service Desk | Subfolders or non-standard locations |
To place a shortcut in a subfolder of a standard location, put the folder in the Name field, for example Contoso\Service Desk. On Windows 11 a Start Menu shortcut shows in All apps; pinning to Start or the taskbar is a separate setting.
Method 1: Group Policy Preferences Shortcuts
This is the standard desktop shortcut Group Policy method. Create one GPO per purpose (for example USR – Desktop Shortcuts) so you can filter and remove it as a unit.
Create the GPO
- Open Group Policy Management (
gpmc.msc). - Right-click the OU that holds the user accounts and choose Create a GPO in this domain, and Link it here. For All Users Desktop shortcuts, link a computer GPO to the workstation OU instead.
- Right-click the new GPO and choose Edit.
- Go to
User Configuration » Preferences » Windows Settings » Shortcuts(or the same node under Computer Configuration), right-click and choose New » Shortcut.
Actions
| Action | What it does |
|---|---|
| Create | Creates the shortcut only if it does not exist; later edits in the GPO are not pushed. |
| Replace | Deletes and recreates the shortcut on every refresh, so changes always reach clients. Required for “Remove this item when it is no longer applied”. |
| Update | Changes only the properties you filled in and creates the shortcut if missing. |
| Delete | Removes a shortcut; name, target type and location must match the existing one. |
URL shortcut to the intranet
- Action: Replace. Name: Contoso Intranet.
- Target type: URL. Location: Desktop.
- Target URL:
https://intranet.contoso.com/. - Optional: Icon file path
%SystemRoot%\System32\shell32.dlland an Icon index, or a.icofile on a readable share.
A URL shortcut is saved as a .url file and opens in the user’s default browser.
Shortcut to a file share
- Target type: File System Object. Name: Department Files.
- Target path:
\\fs01\Departments\%LogonDomain%or a fixed path such as\\fs01\Departments\Sales. - Leave Arguments and Start in empty for folders.
Point shortcuts at UNC paths rather than mapped drive letters. If a path does use a mapped drive, the item must be under User Configuration, the drive must exist before the shortcut is processed, and “Run in logged-on user’s security context” must be ticked on the Common tab.
Application shortcut
- Target type: File System Object. Target path:
%ProgramFiles%\Contoso\CRM\crm.exe. - Arguments: any switches, e.g.
/profile sales. Start in:%ProgramFiles%\Contoso\CRM(no quotes, no trailing backslash). - Run: Normal window or Maximized. Comment: the tooltip text.
GPP resolves variables in the target path before it writes the shortcut. To keep the variable inside the shortcut so that each PC resolves it, use the unresolved syntax %<ProgramFiles>%. Only environment variables work in that form.
Shell object shortcuts
Choose Target type Shell Object to link to This PC, Network, Control Panel items or printers. Click the browse button next to Target object and pick the object. This is the cleanest way to put a This PC icon on every desktop.
Common tab options
- Remove this item when it is no longer applied: deletes the shortcut when the GPO stops applying. Selecting it switches the action to Replace.
- Run in logged-on user’s security context: user preferences run as SYSTEM by default; tick this when the target is a mapped drive or a share only the user can read.
- Apply once and do not reapply: creates the shortcut once and lets the user delete it permanently.
- Stop processing items in this extension if an error occurs on this item: leave clear unless later items depend on this one.
Method 2: Copy .lnk or .url files with GPP Files
Build the shortcut on a reference PC, then copy it with the Files extension. This keeps properties such as “Run as administrator” flags or compatibility settings stored in the file.
- Save the shortcut to a share readable by Domain Computers and Authenticated Users, e.g.
\\contoso.com\NETLOGON\Shortcuts\CRM.lnk. - In a computer GPO go to
Computer Configuration » Preferences » Windows Settings » Filesand choose New » File. - Action: Replace. Source file(s):
\\contoso.com\NETLOGON\Shortcuts\CRM.lnk. Destination File:%CommonDesktopDir%\CRM.lnk. - For a per-user copy, create the item under User Configuration with the destination
%DesktopDir%\CRM.lnk.
A .url file is plain text, so you can write it in Notepad:
[InternetShortcut]
URL=https://intranet.contoso.com/
IconFile=\\contoso.com\NETLOGON\Shortcuts\intranet.ico
IconIndex=0
Method 3: PowerShell with WScript.Shell
Use a script where Group Policy is not available, for example from an RMM tool or a computer startup script. This creates a shortcut on the Public Desktop and needs administrator rights:
$wsh = New-Object -ComObject WScript.Shell
$lnk = $wsh.CreateShortcut("$env:PUBLIC\Desktop\Contoso CRM.lnk")
$lnk.TargetPath = "C:\Program Files\Contoso\CRM\crm.exe"
$lnk.Arguments = "/profile sales"
$lnk.WorkingDirectory = "C:\Program Files\Contoso\CRM"
$lnk.IconLocation = "C:\Program Files\Contoso\CRM\crm.exe,0"
$lnk.Description = "Contoso CRM"
$lnk.Save()
For a web link, write a .url file:
$url = "$env:PUBLIC\Desktop\Contoso Intranet.url"
Set-Content -Path $url -Encoding ASCII -Value @(
"[InternetShortcut]",
"URL=https://intranet.contoso.com/"
)
To remove it later, run Remove-Item "$env:PUBLIC\Desktop\Contoso CRM.lnk" -ErrorAction SilentlyContinue.
Method 4: Intune for Entra-joined devices
Intune has no dedicated shortcut profile, so deliver the PowerShell above.
Platform script
- In the Intune admin center go to Devices » Scripts and remediations » Platform scripts » Add » Windows 10 and later.
- Upload the script. Set Run this script using the logged on credentials to No so it runs as SYSTEM and can write to
C:\Users\Public\Desktop. - Set Run script in 64 bit PowerShell Host to Yes so
$env:ProgramFilespoints to the 64-bit folder. - Assign it to a device group.
A platform script does not run again after it succeeds, so a deleted shortcut stays deleted until you change the script.
Win32 app
For shortcuts that must come back and be removable, package an install script and an uninstall script with the Win32 Content Prep Tool. Use a File detection rule on C:\Users\Public\Desktop with the shortcut name. Intune reinstalls the app if the file disappears and runs the uninstall command when you assign it as Uninstall.
OneDrive Known Folder Move
With Known Folder Move, the user’s Desktop is redirected into OneDrive, for example %USERPROFILE%\OneDrive - Contoso\Desktop. A per-user desktop shortcut Group Policy item that uses the Desktop location follows the redirected folder, and the file is synchronised to every PC the user signs in to. Three things follow from that:
- A shortcut to a local program appears on devices where the program is not installed.
- Replace recreates the file on every refresh, which OneDrive then uploads again.
- If two PCs write the same file at once, OneDrive may keep a copy with the computer name added.
To avoid this, deliver shortcuts to All Users Desktop from Computer Configuration. The Public Desktop is not redirected, is merged into every user’s desktop view and never syncs to OneDrive.
Target shortcuts with item-level targeting
One desktop shortcut Group Policy object can hold shortcuts for many departments. Open a shortcut item, go to Common, tick Item-level targeting and click Targeting.
- Security Group: CONTOSO\GRP-Sales, so only members get the CRM shortcut. Under Computer Configuration, choose computer groups.
- Organizational Unit: limit an item to users in one OU.
- Operating System: restrict an item to Windows 11 or to Windows Server for admin tools.
- File Match: create the application shortcut only if
crm.exeexists, so broken icons never appear on PCs without the program.
Combine conditions with And/Or and use Item Options » Is Not for exclusions. With “Remove this item when it is no longer applied” ticked, the shortcut disappears when a user leaves the group. For whole-GPO exclusions, use security filtering instead.
Verify it works
- On a test PC run
gpupdate /force. User preferences apply at the next sign-in or background refresh. - Run
gpresult /r /scope user(or/scope computer) and check that the GPO is listed under Applied Group Policy Objects. - Check the file exists:
Get-ChildItem "$env:USERPROFILE\Desktop", "$env:PUBLIC\Desktop" -Filter *.lnk
Get-ChildItem "$env:PUBLIC\Desktop" -Filter *.url - Open Event Viewer » Windows Logs » Application and filter on the source Group Policy Shortcuts. A warning (event ID 4098) names the item and the error code when it fails.
- For detail, enable
Computer Configuration » Policies » Administrative Templates » System » Group Policy » Logging and tracing » "Configure Shortcuts preference logging and tracing"; trace files are written to%SystemDrive%\ProgramData\GroupPolicy\Preference\Trace.
Troubleshooting
When a desktop shortcut Group Policy item fails, the cause is usually scope, permissions or the action type:
| Symptom | Cause | Fix |
|---|---|---|
| No shortcut, GPO not in gpresult | Wrong OU link, security filtering or a WMI filter | Link the user GPO to the user OU, or use loopback for computer OUs |
| Event 4098 with 0x80070005 | SYSTEM or the user cannot write the folder, often All Users Desktop from a user-context item | Create Public Desktop items under Computer Configuration |
| Blank or generic icon | Icon path unreachable or resolved on the admin PC | Store icons locally or on NETLOGON; use %<ProgramFiles>% syntax |
| Changes not reaching users | Action set to Create | Change the action to Replace or Update |
| Duplicate “-PCNAME” shortcuts | OneDrive KFM syncing per-user copies | Move the item to All Users Desktop |
| Shortcut to mapped drive fails | Drive not mapped yet or item runs as SYSTEM | Use a UNC path, or tick “Run in logged-on user’s security context” |
If the GPO is missing entirely, work through the general Group Policy checks (gpresult /h, events 1058 and 1030) before looking at the preference item.
Roll back or remove shortcuts
- Items with “Remove this item when it is no longer applied”: unlink the GPO, delete the item, or remove users from the targeting group. Shortcuts are deleted at the next refresh.
- Items without that option: change the action to Delete with the same name, target type and location, leave it in place for a few weeks, then remove the item.
- GPP Files copies: add a Files item with action Delete for the destination path.
- Scripts and Intune: run the
Remove-Itemline as a new script, or assign the Win32 app as Uninstall.
Test every desktop shortcut Group Policy change on a pilot OU first, and keep shortcut names stable: the Delete action and removal both match on the name.
Desktop shortcut Group Policy at a glance

Official documentation: Configure a Shortcut Item (Group Policy Preferences), Configure Common Options for preference items, Use PowerShell scripts on Windows devices in Intune.
Related guides: Map Network Drives Group Policy: 2026 Item-Level Targeting Made Easy · Deploy registry settings with Group Policy Preferences · Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030.
Frequently asked questions
Should I use Create, Replace or Update for GPP shortcuts?
Use Replace for most shortcuts. It rewrites the file on every refresh so edits reach clients, and it is required when you tick “Remove this item when it is no longer applied”. Create never pushes later changes.
Why does the shortcut come back after users delete it?
Replace and Update recreate a missing shortcut at every Group Policy refresh. Tick “Apply once and do not reapply” on the Common tab if users may delete it permanently.
How do I put a shortcut on the desktop for all users of a PC?
Create the item under Computer Configuration with the location set to All Users Desktop. It writes to C:\Users\Public\Desktop, which every profile shows and OneDrive does not sync.
Can Intune deploy desktop shortcuts?
Yes, but there is no shortcut profile. Deploy a PowerShell platform script that runs as SYSTEM, or a Win32 app with a file detection rule if the shortcut must be restored and removable.
Do GPP shortcuts work on Windows 11 24H2 and 25H2?
Yes. The Shortcuts preference extension is part of Windows and works on domain-joined Windows 11 Pro, Enterprise and Education and on Windows Server 2016 to 2025.