# Folder Redirection Group Policy: 7 Steps for Windows 11

Source: https://srvscripts.com/guides/folder-redirection-group-policy/
Updated: 2026-10-05
Publisher: srvScripts (https://srvscripts.com/)

A folder redirection Group Policy object moves user folders such as Documents and Desktop from the local profile to a file share, so the data lives on a server that you back up and users see the same files on any domain computer. You need it for shared desks, Remote Desktop hosts, and any site where files on local disks are a backup risk. This guide covers the share and NTFS permissions Microsoft recommends, basic and advanced targets, the Settings tab, Offline Files, the conflict with OneDrive Known Folder Move, verification, troubleshooting and redirecting back.

**Short answer:** Create a share such as `\\fs1.contoso.com\Users$` with Microsoft’s NTFS permissions, then create a GPO filtered to a Folder Redirection Users group. In `User Configuration » Policies » Windows Settings » Folder Redirection` open **Documents**, choose **Basic – Redirect everyone’s folder to the same location** and **Create a folder for each user under the root path**, enter the UNC root path and sign the user in twice.

In short: Create a share such as \\fs1.contoso.com\Users$ with Microsoft’s NTFS permissions, then create a GPO filtered to a Folder Redirection Users group.

## Which method to use

| Approach | Where data lives | Pros | Cons |
| --- | --- | --- | --- |
| Folder Redirection, Basic target | One file share for everyone | Simple; one GPO | One server for all users |
| Folder Redirection, Advanced target | Different shares per security group | Per-site or per-department servers | More groups to maintain |
| Folder Redirection with Offline Files | File share, cached locally | Laptops keep working offline | Sync conflicts; cache to manage |
| OneDrive Known Folder Move | OneDrive for Business | No file server; version history; works off-network | Needs Microsoft 365; conflicts with existing redirection |
| Roaming user profiles | Whole profile copied at logon and logoff | Roams settings too | Slow logons; best combined with redirection, not instead of it |

For on-premises file servers, use a Basic folder redirection Group Policy target for Documents and Desktop. If the organisation already uses Microsoft 365, compare with Known Folder Move before you build anything new.

## Prerequisites

Prepare the following before you create the folder redirection Group Policy object:

- Clients: Windows 11 or Windows 10, or Windows Server 2016 to 2025 for Remote Desktop hosts, joined to the domain. Microsoft does not support Folder Redirection on ARM-based clients.

- A file server with enough space and a backup. If you use DFS Namespaces, give each folder a single target; with DFS Replication, users must only use the source server. Disable continuous availability on clustered shares.

- Membership of Domain Admins or Group Policy Creator Owners, plus GPMC and Active Directory Administrative Center.

- A global security group, for example Folder Redirection Users, containing the pilot users.

## Step 1: Create the share with Microsoft’s permissions

- In **Server Manager » File and Storage Services » Shares**, choose **Tasks » New Share** and select **SMB Share – Quick** (or **SMB Share – Advanced** with File Server Resource Manager, where you set Folder Usage to User Files).

- Name it with a trailing `$`, for example `Users$`, to hide it from browse lists.

- On **Other Settings** clear **Enable continuous availability**. Optionally tick **Enable access-based enumeration** and **Encrypt data access**.

- On **Permissions** choose **Customize permissions**, click **Disable inheritance** and choose **Convert inherited permissions into explicit permissions on this object**, then set the NTFS permissions below.

NTFS permissions on the root folder, as Microsoft documents them for a file server that does not host Remote Desktop Services:

| Account | Permission | Applies to |
| --- | --- | --- |
| SYSTEM | Full control | This folder, subfolders and files |
| Administrators | Full control | This folder only |
| CREATOR OWNER | Full control | Subfolders and files only |
| Folder Redirection Users | List folder / read data, Create folders / append data, Read attributes, Read extended attributes, Read permissions, Traverse folder / execute file (advanced permissions) | This folder only |
| Any other account | None (remove) |  |

Users can create their own folder in the root but cannot see or open anyone else’s. The wizard’s share permission is Everyone with Full Control; NTFS does the real access control. The same ACL from PowerShell:

```
New-Item -Path 'D:\Shares\Users' -ItemType Directory
New-SmbShare -Name 'Users$' -Path 'D:\Shares\Users' -FullAccess 'Everyone' -FolderEnumerationMode AccessBased
icacls 'D:\Shares\Users' /inheritance:r
icacls 'D:\Shares\Users' /grant:r 'SYSTEM:(OI)(CI)F' 'BUILTIN\Administrators:F' `
    'CREATOR OWNER:(OI)(CI)(IO)F' 'CONTOSO\Folder Redirection Users:(RD,AD,RA,REA,RC,X)'
icacls 'D:\Shares\Users'
```

If the file server also hosts Remote Desktop Services, Microsoft’s table differs: Administrators get Full control on this folder, subfolders and files, there is no user group entry, and you pre-create each user’s folder with that user as Full control.

## Step 2: Create and scope the GPO

Link the folder redirection Group Policy object to users, not computers: the settings live under User Configuration and are ignored in a GPO that only reaches computer accounts, unless you use loopback processing.

- In GPMC, right-click the OU that contains the user accounts and choose **Create a GPO in this domain, and Link it here**. Name it USR – Folder Redirection.

- Right-click the link and clear **Link Enabled** while you configure it.

- On the **Scope** tab, remove **Authenticated Users** from **Security Filtering** and add Folder Redirection Users.

- On the **Delegation** tab, add **Authenticated Users** with **Read**, so computers can still read the GPO.

## Step 3: Configure the folder redirection Group Policy settings

- Edit the GPO and go to `User Configuration » Policies » Windows Settings » Folder Redirection`.

- Right-click **Documents** and choose **Properties**.

- On the **Target** tab set **Setting** to **Basic – Redirect everyone’s folder to the same location**.

- Under **Target folder location** choose **Create a folder for each user under the root path** and enter the root path, for example `\\fs1.contoso.com\Users$`. Always use a UNC path, never a mapped drive letter.

- Open the **Settings** tab (see below), click **OK** and accept the warning.

- Repeat for **Desktop**. For **Pictures**, **Music** and **Videos** you can choose **Follow the Documents folder**.

Other target options are **Redirect to the following location** (a fixed path, usually with `%USERNAME%`), **Redirect to the local userprofile location** (used to send folders back) and, for Documents only, **Redirect to the user’s home directory**, which uses the Home folder set on the user account.

### Advanced: different servers per group

Choose **Advanced – Specify locations for various user groups**, click **Add…** and pair each security group with its own root path, for example London Users with `\\lon-fs1\Users$` and New York Users with `\\nyc-fs1\Users$`. Users in no listed group are not redirected. Keep the groups mutually exclusive so each user has one clear target.

### The Settings tab

| Option | Effect | Recommendation |
| --- | --- | --- |
| Grant the user exclusive rights to Documents | New folders get permissions for the user and SYSTEM only; administrators cannot open them without taking ownership | Clear it if IT or backup software needs access through the Administrators group |
| Move the contents of Documents to the new location | Copies existing local files to the share at first redirection | Leave ticked for existing users |
| Also apply redirection policy to Windows 2000 … Windows Server 2003 | Legacy clients only | Leave cleared |
| Policy Removal | “Leave the folder in the new location when policy is removed” or “Redirect the folder back to the local userprofile location when policy is removed” | Choose “Redirect the folder back” if you may ever roll back |

If you clear exclusive rights, Windows applies inherited permissions instead, so check the CREATOR OWNER and Administrators entries on the root. Changing the option later does not change folders that already exist.

### Which folders to redirect

- **Documents and Desktop:** the usual pair, where users keep their work.

- **Pictures, Music, Videos:** “Follow the Documents folder”, or leave local to save server space.

- **AppData (Roaming):** we do not recommend it. Applications that keep open files or databases there, such as mail clients, perform badly or fail over the network.

- **Downloads:** usually left local; it fills quickly with installers.

## Step 4: Offline Files and caching

Offline Files is on by default on Windows clients and off on Windows Server. Redirected folders are made available offline automatically when Offline Files is enabled.

- **Laptops that leave the office:** keep Offline Files on. The share must allow caching, which is the default (Only the files and programs that users specify are available offline).

- **Desktops and RDS hosts:** turn it off with `Computer Configuration » Policies » Administrative Templates » Network » Offline Files » "Allow or Disallow use of the Offline Files feature"` set to Disabled, or set the share’s caching to none with `Set-SmbShare -Name 'Users$' -CachingMode None`.

- To stop the automatic offline copy but keep Offline Files for other shares, enable `User Configuration » Policies » Administrative Templates » System » Folder Redirection » "Do not automatically make all redirected folders available offline"`.

## Step 5: Make redirection apply at first logon

Folder Redirection only applies during foreground (logon) processing, and Windows logs on with cached credentials by default, so the first redirection often happens at the second logon. Enable `Computer Configuration » Policies » Administrative Templates » System » Logon » "Always wait for the network at computer startup and logon"` in a computer GPO to apply it at the first logon. Then enable the GPO link.

## OneDrive Known Folder Move: comparison and conflict

Known Folder Move (KFM) redirects Desktop, Documents, Pictures, Screenshots and Camera Roll into OneDrive using the OneDrive policies **“Silently move Windows known folders to OneDrive”** or **“Prompt users to move Windows known folders to OneDrive”**. Microsoft states that KFM does not work if a folder redirection Group Policy already sends Documents, Pictures or Desktop to another location. Their documented order is:

- Copy the data from the file share into each user’s OneDrive folders (Microsoft suggests Migration Manager).

- Disable the folder redirection GPO while leaving the folders and content on the share.

- Enable the KFM policy; the folders move to OneDrive and merge with the copied data.

Never enable both on the same folders. Use security filtering so each user receives either redirection or KFM.

## Verify it works

Check the result with a pilot account before you add more users to the folder redirection Group Policy scope.

- Sign in as a pilot user (twice if you did not enable “Always wait for the network”). Run `gpresult /scope user /r` and confirm the GPO is applied.

- In File Explorer, right-click **Documents** and open **Properties » Location**. It must show `\\fs1.contoso.com\Users$\username\Documents`.

- Check the shell folder values from PowerShell:

```
Get-ItemProperty 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders' |    Select-Object Personal, Desktop
```

- Open Event Viewer » **Windows Logs » Application** and filter on source Microsoft-Windows-Folder Redirection. Event ID 502 means redirection failed and includes the path and error text; successful redirections are logged as informational events from the same source. More detail is in **Applications and Services Logs » Microsoft » Windows » Folder Redirection » Operational**.

- On the server, confirm the user folder exists and its owner and ACL match what you expect: `icacls '\\fs1.contoso.com\Users$\username'` (run as an account with access).

## Troubleshooting

Most folder redirection Group Policy failures come from permissions, paths or processing timing.

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| Event 502, “Access is denied” | Root NTFS permissions wrong, or user not in the group | Reapply Microsoft’s ACL; check group membership |
| Event 502, “Cannot create folder H:\Documents” | Target uses a mapped drive letter | Use a UNC path |
| Nothing happens at first logon | Cached logon, background processing | Sign in again or enable “Always wait for the network…” |
| GPO filtered out for the user | Authenticated Users removed completely | Add Authenticated Users with Read on the Delegation tab |
| Admins cannot open user folders | “Grant the user exclusive rights” was ticked | Take ownership carefully, or clear the option for new users |
| Slow logon on first redirection | “Move the contents” copying large folders | Pre-stage data or clean up large local folders first |
| Files show sync conflicts | Offline Files on desktops or RDS hosts | Disable Offline Files where it is not needed |
| OneDrive KFM fails | Folder already redirected to a share | Follow Microsoft’s migrate, disable, then enable order |

## Roll back or redirect back

- Make sure **Policy Removal** is set to **Redirect the folder back to the local userprofile location when policy is removed** on every folder, and let that setting apply at a logon before you remove anything.

- Alternatively, change the target to **Redirect to the local userprofile location** with **Move the contents** ticked, and let users sign in once.

- Then remove the user from the security group or unlink the GPO. The data is copied back to the local profile at the next logon.

- Keep the share for a few weeks and compare folder sizes before deleting anything. Files that are only on the server (for example, copied there by another device) must be copied back by hand.

Test each folder redirection Group Policy change with a pilot group, keep a current backup of the share, and document the root path and ACL so a replacement server can be built the same way.

## Folder redirection Group Policy at a glance

**Official documentation:** [Deploy Folder Redirection with Offline Files](https://learn.microsoft.com/en-us/windows-server/storage/folder-redirection/deploy-folder-redirection), [Redirect Windows known folders to OneDrive](https://learn.microsoft.com/en-us/sharepoint/redirect-known-folders).

**Related guides:** [File server share vs NTFS permissions and ABE](/guides/file-server-share-ntfs-permissions/) · [Map Network Drives Group Policy: 2026 Item-Level Targeting Made Easy](/guides/map-network-drives-group-policy/) · [Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030](/guides/group-policy-not-applying/).

## Frequently asked questions

### What NTFS permissions does the folder redirection share need?

Microsoft recommends SYSTEM Full control on the folder, subfolders and files, Administrators Full control on this folder only, CREATOR OWNER Full control on subfolders and files only, and the redirection users group with list, create folders, read attributes, read permissions and traverse on this folder only.

### Why does folder redirection only work after the second logon?

Folder Redirection applies only during foreground processing, and Windows signs in with cached credentials by default. Enable “Always wait for the network at computer startup and logon” to apply it at the first logon.

### Can I use folder redirection and OneDrive Known Folder Move together?

Not on the same folders. Microsoft states that Known Folder Move does not work for folders already redirected to another location, so copy the data to OneDrive, disable redirection and then enable Known Folder Move.

### Should I redirect AppData with Group Policy?

We do not recommend it. Applications that keep open files or databases in AppData perform poorly or fail when the folder is on a network share.

### How do I move redirected folders back to the local profile?

Set Policy Removal to “Redirect the folder back to the local userprofile location when policy is removed”, let it apply at a logon, then remove the GPO. Or change the target to the local userprofile location with Move the contents ticked.
