A Group Policy desktop wallpaper setup has two parts: copy the image to every PC, then point the “Desktop Wallpaper” policy at that local copy so users see the same background at every sign-in. The lock screen needs a separate computer policy that only works on Enterprise, Education and Server editions. This guide covers both, plus a default wallpaper users can change, Windows 11 Pro workarounds, Intune and troubleshooting.
Short answer: Use a Group Policy Preferences Files item to copy wallpaper.jpg to C:\ProgramData\Contoso\Branding, then enable User Configuration » Policies » Administrative Templates » Desktop » Desktop » "Desktop Wallpaper" with that local path and the style Fill. For the lock screen on Enterprise or Education, enable Computer Configuration » Policies » Administrative Templates » Control Panel » Personalization » "Force a specific default lock screen and logon image". Users see the change at their next sign-in.
Table of Contents
Which method to use
| Method | What it sets | Editions | User can change it? |
|---|---|---|---|
| “Desktop Wallpaper” policy (User Configuration) | Desktop background and style | Pro, Enterprise, Education, Server | No |
GPP Registry item in HKCU\Control Panel\Desktop | Default desktop background | All domain-joined editions | Yes, if applied once |
| “Force a specific default lock screen and logon image” (Computer Configuration) | Lock screen and sign-in image | Enterprise, Education, Server only | No, with “Prevent changing lock screen and logon image” |
| Intune Personalization CSP | Desktop and lock screen image from a URL | Enterprise and Education; Pro with conditions | No |
| GPP Registry for the PersonalizationCSP key | Lock screen on Pro | Pro (undocumented) | No |
For most domains, the Group Policy desktop wallpaper setting plus the lock screen policy covers everything. Pro devices need one of the alternatives for the lock screen only; the desktop policy works on Pro.
Prerequisites
- Windows 11 Pro, Enterprise or Education joined to the domain, or Windows Server 2016 to 2025.
- Rights to create and link GPOs, and GPMC.
- An image in JPEG (
.jpg) or bitmap (.bmp) format for the policy. Microsoft recommends a 16:9 image (for example 1600 x 900 or 1920 x 1080) and keeping logos and text inside the centre 4:3 area, because other screen shapes crop the edges. - A share that computer accounts can read, such as
\\contoso.com\NETLOGON\Brandingor a dedicated file share with Domain Computers read access.
Step 1: Stage the image on each PC
The Desktop Wallpaper policy only stores a path. If the file is not available when the user signs in, Windows shows no wallpaper at all. A UNC path works on the office network but fails on laptops that sign in before the VPN connects, so copy the image locally first.
- Copy
wallpaper.jpg(andlockscreen.jpgif needed) to\\contoso.com\NETLOGON\Branding. - Create a GPO named, for example, CFG – Branding and link it to the OU that holds the computer objects.
- Edit it and go to
Computer Configuration » Preferences » Windows Settings » Files, then choose New » File. - Set Action to Replace, Source file(s) to
\\contoso.com\NETLOGON\Branding\wallpaper.jpgand Destination File toC:\ProgramData\Contoso\Branding\wallpaper.jpg. Parent folders are created as needed. - Add a second item for
lockscreen.jpg, then rungpupdate /forceon a test PC and check that both files exist.
We use Replace because Update only copies the file when it is missing and otherwise just adjusts attributes, so a new image with the same name would never arrive. Computer-side file items run as SYSTEM and read the share with the computer account, which is why Domain Computers need read access.
Method 1: The Desktop Wallpaper policy
This is the core Group Policy desktop wallpaper setting. It is a user setting, so link it to the OU that holds the user accounts, or to the computer OU with loopback processing.
- Create or edit a GPO linked to the user OU, for example USR – Desktop Wallpaper.
- Go to
User Configuration » Policies » Administrative Templates » Desktop » Desktopand open “Desktop Wallpaper”. - Select Enabled. In Wallpaper Name type
C:\ProgramData\Contoso\Branding\wallpaper.jpg. - In Wallpaper Style choose Fill for photos or Fit for logos on a plain background, then click OK.
- Sign out and back in on a test PC.
The policy writes the values Wallpaper and WallpaperStyle under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System. While it applies, the Background page in Settings is locked. Microsoft notes that the setting does not apply to remote desktop server sessions, so do not expect it on RDS hosts.
Lock the background picker completely
For shared or kiosk PCs, also enable User Configuration » Policies » Administrative Templates » Control Panel » Personalization » "Prevent changing desktop background". It writes NoChangingWallPaper = 1 under HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop and greys out every background option. Microsoft states that you must also enable “Desktop Wallpaper” to stop users changing the image itself, so use the two together.
Apply it per computer with loopback
To give meeting-room PCs a different image from office desks, put the Group Policy desktop wallpaper setting in a GPO linked to the meeting-room computer OU and enable Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Configure user Group Policy loopback processing mode" in Merge mode on that OU. The user setting from the computer OU then wins on those PCs only.
Method 2: A default wallpaper users can change
If you only want to set a starting image, skip the policy and use a Group Policy Preferences registry item, which writes the normal user value instead of a policy value.
- In a GPO linked to the user OU, go to
User Configuration » Preferences » Windows Settings » Registryand choose New » Registry Item. - Action Update, hive HKEY_CURRENT_USER, key path
Control Panel\Desktop, value nameWallpaper, type REG_SZ, dataC:\ProgramData\Contoso\Branding\wallpaper.jpg. - Add
WallpaperStyle(REG_SZ) with10for Fill or6for Fit, andTileWallpaper(REG_SZ) with0. - On the Common tab of each item, tick “Apply once and do not reapply” so users can pick their own picture later.
Windows reads these values at sign-in, so the image appears at the next sign-in, not immediately. Do not combine this with the Group Policy desktop wallpaper policy for the same users: the policy value always wins, and the registry item then has no visible effect.
Method 3: Lock screen policy (Enterprise and Education)
- In a GPO linked to the computer OU, go to
Computer Configuration » Policies » Administrative Templates » Control Panel » Personalization. - Open “Force a specific default lock screen and logon image”, select Enabled and enter
C:\ProgramData\Contoso\Branding\lockscreen.jpg. The same image is used for the lock screen and the sign-in screen. - Enable “Prevent changing lock screen and logon image” in the same node so users cannot pick another picture.
- Run
gpupdate /forceand lock the PC with Win+L.
The settings write LockScreenImage and NoChangingLockScreen = 1 under HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization. Microsoft states that the lock screen policy applies only to Enterprise, Education and Server editions. On Windows 11 Pro the registry value appears, but the lock screen does not change.
Method 4: Intune (Personalization CSP)
For Entra-joined or co-managed devices:
- In the Intune admin center, create Devices » Configuration » Create » New policy, platform Windows 10 and later, profile type Settings catalog.
- Add the Personalization category and select Desktop Image Url and Lock Screen Image Url.
- Enter an
https://URL to a.jpg,.jpegor.pngfile, for example on a public storage account or your intranet. The CSP also acceptsfile://URLs to a local image. - Assign to a device group and sync.
These map to ./Vendor/MSFT/Personalization/DesktopImageUrl and ./Vendor/MSFT/Personalization/LockScreenImageUrl. The read-only DesktopImageStatus and LockScreenImageStatus nodes report 1 when the download succeeded, and 3, 4, 5 or 6 for failures such as a bad file type or URL scheme. Microsoft’s configuration page lists Pro as supported, but the CSP reference adds conditions for Pro devices (shared PC settings), so test on a Pro device before you rely on it. If you prefer the classic policy, the settings catalog also contains Administrative Templates » Desktop » Desktop » Desktop Wallpaper (User).
Windows 11 Pro lock screen workaround
Many admins set the lock screen on Pro by writing the values that the Personalization CSP uses locally, with Group Policy Preferences registry items under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PersonalizationCSP:
LockScreenImagePath REG_SZ C:\ProgramData\Contoso\Branding\lockscreen.jpg
LockScreenImageUrl REG_SZ C:\ProgramData\Contoso\Branding\lockscreen.jpg
LockScreenImageStatus REG_DWORD 1
This location is not documented by Microsoft and is not a supported policy, so a feature update can change the behaviour. Test it on your Windows 11 builds, keep it in a separate GPO targeted with item-level targeting on the Operating System edition, and move to Enterprise or Intune where you can.
Multiple monitors, RDS and VDI
A few environments need extra thought before you roll out a Group Policy desktop wallpaper setting to everyone:
- Multiple monitors: Fill repeats the image on each screen. Span stretches one image across all screens, which only looks right when every desk has the same layout. For mixed desks, stay with Fill and a plain background with the logo in the centre.
- RDS session hosts: the Desktop Wallpaper policy does not apply to remote desktop server sessions, and a wallpaper adds bandwidth to every session. Most farms leave the session desktop plain and brand the RemoteApp or web client instead.
- Non-persistent VDI: bake the image into the master image under
C:\ProgramDataso it exists before the first sign-in, and keep the policy for the path. - Laptops off the network: once the Files item has copied the image, the local copy keeps working offline. Only the first copy needs access to the share, so run it while the device is still in the office.
If you manage several brands or regions, keep one image per region on the share and one Files item per region with item-level targeting, so each GPO stays small and easy to read.
Targeting and exceptions
- Different images per site or department: use one GPO with several Files and Registry items and item-level targeting on Site or Security Group, or separate GPOs with security filtering.
- Exempt IT staff: add a group such as SEC-Wallpaper-Exempt to the user-side GPO’s Delegation » Advanced list with Deny on Apply group policy. Keep Authenticated Users with Read so computers can still read the GPO.
- Servers: link the lock screen GPO to server OUs only if you want the branding there; servers support the lock screen policy.
- System information on the desktop: tools such as Sysinternals BGInfo render a bitmap with host details and set it as wallpaper at sign-in. They conflict with the Group Policy desktop wallpaper policy, which always wins, so use one or the other on a machine.
Verify it works
- Check the GPOs apply:
gpupdate /force
gpresult /scope user /r
gpresult /scope computer /r - Check the files and values:
Test-Path C:\ProgramData\Contoso\Branding\wallpaper.jpg
reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v Wallpaper
reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization" - Sign out and in, then open Settings » Personalization » Background. A message that some settings are managed by your organisation confirms the Group Policy desktop wallpaper policy is active.
- Press Win+L to check the lock screen, and sign out to see the sign-in screen.
- For Intune, check the status nodes in Devices » device » Device configuration, or on the device read
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PersonalizationCSP.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Black or empty desktop | File missing at sign-in, or UNC path unreachable | Stage the image locally and point the policy at the local path |
| Old image still shown | Files item uses Update, so the new file never copied | Use Replace, or change the file name for each new version |
| Wallpaper appears only after a second sign-in | Files item copied the image after the user profile loaded | Enable “Always wait for the network at computer startup and logon”, or restart once after linking |
| Lock screen unchanged on Pro | Policy only applies to Enterprise, Education and Server | Use Intune, the PersonalizationCSP workaround, or upgrade the edition |
| Files item fails with access denied | Computer account cannot read the share | Grant Domain Computers read on the share and NTFS |
| Image stretched or cropped | Wrong style for the screen shape | Use a 16:9 image and Fill, or Fit for logos |
Setting missing in gpresult | User GPO linked to computer OU without loopback | Link to the user OU or enable loopback on the computer OU |
If the GPO is not applied at all, check security filtering, WMI filters and events 1058 and 1030 in the System log.
Roll back or undo
- Set “Desktop Wallpaper”, “Prevent changing desktop background”, “Force a specific default lock screen and logon image” and “Prevent changing lock screen and logon image” to Not Configured, or unlink the GPOs. Policy values are removed at the next refresh and users can pick their own image after signing in again.
- Registry items set with “Apply once” stay as normal user settings; users change them in Settings.
- Delete the PersonalizationCSP values if you used the Pro workaround, or tick “Remove this item when it is no longer applied” before unlinking.
- In Intune, unassign the profile and sync.
Keep the image share and the Files items in place until every Group Policy desktop wallpaper and lock screen setting is gone, so no PC points at a missing file.
Group Policy desktop wallpaper at a glance

Official documentation: Configure the desktop and lock screen background, ADMX_ControlPanelDisplay Policy CSP, Personalization CSP.
Related guides: Deploy registry settings with Group Policy Preferences · Screen Lock Group Policy: Lock Windows After Inactivity the Right Way · Group Policy loopback processing: merge vs replace for RDS hosts and kiosks.
Frequently asked questions
Why does the lock screen Group Policy not work on Windows 11 Pro?
Microsoft limits “Force a specific default lock screen and logon image” to Enterprise, Education and Server editions. On Pro, use Intune’s Personalization settings or the undocumented PersonalizationCSP registry workaround, and test it on your builds.
Should the Desktop Wallpaper policy point to a UNC path or a local file?
Use a local file. If the image is not available when the user signs in, Windows shows no wallpaper, which often happens on laptops before the VPN connects. Copy the image with a Group Policy Preferences Files item first.
Can I set a default wallpaper that users can still change?
Yes. Use a Group Policy Preferences registry item for Wallpaper under HKCU\Control Panel\Desktop with “Apply once and do not reapply” instead of the Desktop Wallpaper policy, which locks the setting.
What image format and size should I use?
Use JPEG for the Group Policy setting and JPEG or PNG for Intune. A 16:9 image such as 1920 x 1080 works well, with text and logos kept inside the centre 4:3 area.
How do I update the wallpaper image later?
Replace the file on the share and make sure the Files item uses the Replace action, or use a new file name and update the policy path. Users see the new image at their next sign-in.