The easiest way to map network drives with Group Policy is the Drive Maps extension in Group Policy Preferences: one GPO holds every drive letter, and item-level targeting decides which users get which share. This guide covers the Drive Maps actions, labels and letters, targeting by security group, a logon script alternative, the UAC fix for drives missing in elevated programs, an Intune option for cloud devices and the usual red X problems.
Short answer: Create a GPO linked to the OU that holds your user accounts, go to User Configuration » Preferences » Windows Settings » Drive Maps and add a Mapped Drive with action Update, location \\contoso.com\dfs\Sales, a label and letter S. On the Common tab, add item-level targeting for the SG-Sales group. Users get the drive at their next sign-in.
Table of Contents
Which method to use
| Method | Scope | Pros | Cons |
|---|---|---|---|
| GPP Drive Maps | Domain users | No code; per-item targeting; label, letter and hide options | Applies at sign-in; needs a domain |
Logon script (net use, New-PSDrive, New-SmbMapping) | Domain users | Full control, custom logic | Code to maintain; logon scripts are delayed by default |
| Intune platform script | Entra-joined or hybrid devices | Works without a domain GPO | Runs once per change; needs line of sight and Kerberos to the file server |
| Manual mapping | One user | Quick for a test | Not managed, not repeatable |
For a domain, the best way to map network drives with Group Policy is Drive Maps with item-level targeting. Keep scripts for edge cases such as mapping based on data that targeting cannot read.
Prerequisites
- Windows 11 Pro, Enterprise or Education joined to the domain, or Windows Server 2016 to 2025 (for RDS hosts).
- The shares exist and the target users have share and NTFS permissions. We recommend DFS Namespace paths (
\\contoso.com\dfs\Sales) so you can move file servers without editing the GPO. - Security groups per department, for example SG-Sales and SG-Finance.
- Rights to create and link GPOs, and GPMC.
Plan the drive layout first
Before you map network drives with Group Policy, write down one table: letter, label, UNC path and the group that should see it. A short plan avoids letter clashes and makes the GPO easy to audit later.
| Letter | Label | Path | Who |
|---|---|---|---|
| H: | Home | \\contoso.com\dfs\Home\%LogonUser% | All staff |
| P: | Public | \\contoso.com\dfs\Public | All staff |
| S: | Sales | \\contoso.com\dfs\Sales | SG-Sales |
| F: | Finance | \\contoso.com\dfs\Finance | SG-Finance |
Keep one letter per share across the company, even for users in several departments, so shortcuts and linked spreadsheets work on every PC. Access-based enumeration on the file server hides folders a user cannot open, which keeps shared drives such as Public tidy.
Method 1: Group Policy Preferences Drive Maps
Create the drive map item
- In GPMC, right-click the user OU and choose Create a GPO in this domain, and Link it here. Name it, for example, USR – Drive Maps.
- Edit it and go to
User Configuration » Preferences » Windows Settings » Drive Maps. Right-click and choose New » Mapped Drive. - Set Action to Update.
- In Location, type the UNC path, for example
\\contoso.com\dfs\Sales. Hidden shares (\\fs01\Sales$) and subfolders work too. - Tick Reconnect so Windows saves the mapping in the profile and restores it at each sign-in.
- In Label as, type a friendly name such as Sales. It replaces the long share name in File Explorer.
- Under Drive Letter, choose Use and pick S.
- Leave Hide/Show this drive and Hide/Show all drives on No change, then click OK.
Drive Maps run in the signed-in user’s security context automatically, so the user’s own permissions decide access. Do not use Connect as: the password is stored in the GPO in SYSVOL, where any domain user can read it.
Choose the right action
| Action | What it does | When to use it |
|---|---|---|
| Create | Creates the mapping only if the letter is not mapped yet | Rarely; later path changes are ignored |
| Replace | Deletes and recreates the mapping every time, overwriting all settings | When users keep remapping the letter to something else |
| Update | Changes only the settings in the item; creates the mapping if it does not exist | The default choice for most drives |
| Delete | Removes one letter, or all mappings from a letter onwards | Cleaning up old letters |
Ticking “Remove this item when it is no longer applied” on the Common tab switches the action to Replace. It is still useful: when a user leaves SG-Sales or the GPO goes out of scope, the S: drive is removed at the next sign-in instead of lingering.
Home drives with variables
Preference items accept variables (press F3 in the Location box). For a personal drive, use \\contoso.com\dfs\Home\%LogonUser% with letter H and label Home. If you already set the home folder on the user object in Active Directory, do not map the same letter again here.
Order and letters
Items process from top to bottom in the order column. Put Delete items first, then general drives, then department drives, so a later item never removes a letter an earlier one created. Pick letters from the end of the alphabet (H, P, S, T, X): Use first available, starting at is fine for rarely used shares, but a fixed letter keeps shortcuts and macros working. If a USB drive or card reader already holds the letter, the mapping fails with error 0x80070055 (the local device name is already in use).
Item-level targeting by group, OU or site
Item-level targeting lets you map network drives with Group Policy from one GPO for every department:
- Open the drive map item, go to the Common tab and tick Item-level targeting, then click Targeting….
- Choose New Item » Security Group, browse to SG-Sales and leave User in group selected.
- Add more conditions if needed, for example Site to map the branch file server, or Organizational Unit. Use the Item Options menu to switch between And/Or and to add Is Not.
- For RDS hosts, add Terminal Session to map a drive only inside remote sessions.
- Click OK twice.
Targeting reads the user’s security token, so a user added to a group gets the drive after signing out and in again. Nested groups are honoured. Targeting is not a security boundary: every user who can read the GPO can see the paths, so keep share permissions tight.
RDS hosts and shared PCs
Drive Maps live under User Configuration, so they follow the user account. On a Remote Desktop Session Host you may want different drives inside sessions than on the user’s own PC. Two options:
- Add a Terminal Session targeting condition to items that should only map inside remote sessions, and an Is Not version for items that should only map on physical PCs.
- Link a separate drive map GPO to the RDS host OU and enable loopback processing in Merge mode there. The user-side items from the host OU then apply on top of the normal ones on those hosts only.
Either way, you still map network drives with Group Policy from one place, and the file server permissions stay the real control.
Sign-in timing and slow links
Microsoft lists the Drive Maps extension among those that need foreground (synchronous) processing and are not called during background refresh. With Fast Logon Optimization, which is on by default for Windows clients, a new or changed mapping can take up to two sign-ins to appear. To make it apply at the next sign-in:
- Enable
Computer Configuration » Policies » Administrative Templates » System » Logon » "Always wait for the network at computer startup and logon"in a GPO linked to the workstation OU. - Test with a full sign-out and sign-in, not only
gpupdate. - For users who sign in with cached credentials before a VPN connects, the Reconnect option restores the saved mapping when the network comes up, but new mappings wait until the next sign-in with the domain reachable. A device tunnel or pre-logon VPN avoids this.
Method 2: Logon script alternative
A script is useful when the logic does not fit targeting, or when you cannot map network drives with Group Policy Preferences for another reason, such as a third-party tool that owns the letters. Save it in the GPO’s scripts folder and add it under User Configuration » Policies » Windows Settings » Scripts (Logon/Logoff) » Logon (or the PowerShell Scripts tab).
A batch version:
@echo off
net use S: /delete /y >nul 2>&1
whoami /groups | find /i "SG-Sales" >nul && net use S: \\contoso.com\dfs\Sales /persistent:yes
A PowerShell version:
$groups = (whoami /groups /fo csv | ConvertFrom-Csv).'Group Name'
if ($groups -match 'SG-Sales') {
New-PSDrive -Name S -PSProvider FileSystem -Root '\\contoso.com\dfs\Sales' -Persist -Scope Global
}
# Alternative using the SMB cmdlets:
# New-SmbMapping -LocalPath 'S:' -RemotePath '\\contoso.com\dfs\Sales' -Persistent $true
Windows delays Group Policy logon scripts by five minutes by default. Set Computer Configuration » Policies » Administrative Templates » System » Group Policy » "Configure Logon Script Delay" to Enabled with 0 minutes if drives must exist straight after sign-in.
Drives missing in elevated programs (UAC)
With UAC enabled, an administrator who signs in gets two linked logon sessions, one standard and one elevated. Drive mappings belong to one session, so a drive mapped by the GPO does not appear in an elevated Command Prompt, PowerShell or installer. To share mappings between the linked sessions, set this value and restart:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v EnableLinkedConnections /t REG_DWORD /d 1 /f
Deploy it with a Group Policy Preferences registry item under Computer Configuration » Preferences » Windows Settings » Registry. It does not help when the UAC prompt is set to Prompt for credentials, because that creates a third logon session. For admin accounts, the cleaner fix is to use UNC paths in elevated tools.
Method 3: Intune for cloud devices
Intune has no native drive map profile. For Entra-joined or hybrid-joined devices:
- Write a PowerShell script like the one above, using
New-PSDrive -PersistorNew-SmbMapping -Persistent $trueso the mapping survives restarts. - In the Intune admin center go to Devices » Scripts and remediations » Platform scripts » Add » Windows 10 and later, upload the script and set Run this script using the logged on credentials to Yes.
- Assign it to a user group.
Intune runs a platform script once per change, retrying up to three times on failure; it does not run at every sign-in. If mappings must be re-checked at sign-in, have the script register a scheduled task that runs at logon. Entra-joined devices also need network access to the file server and single sign-on to on-premises resources (for example Windows Hello for Business with cloud Kerberos trust) so the user is not prompted for a password.
Verify it works
- Sign in as a test user and check the GPO:
gpresult /scope user /r
gpresult /h C:\Temp\gp-user.html
The drive map GPO must be under Applied Group Policy Objects. In the HTML report, the Drive Maps section lists each item the GPO contains. - List the mappings:
net use
Get-SmbMapping
Get-PSDrive -PSProvider FileSystem - Open the Application log and filter on source Group Policy Drive Maps. Event 4098 is a warning that an item failed, with the error code.
- For detail, enable
Computer Configuration » Policies » Administrative Templates » System » Group Policy » Logging and tracing » "Configure Drive Maps preference logging and tracing"; trace files are written under%ProgramData%\GroupPolicy\Preference\Trace. Turn it off again after testing.
Troubleshooting
Most problems when you map network drives with Group Policy come down to timing, drive letters or permissions:
| Symptom | Likely cause | Fix |
|---|---|---|
| Red X on the drive after sign-in | Drive restored before the network was ready | Enable “Always wait for the network at computer startup and logon”; open the drive once to reconnect |
| Drive appears only after the second sign-in | Fast Logon Optimization | Same policy as above |
Event 4098 with 0x80070055 | Letter already used by a USB drive or manual mapping | Use Replace, a Delete item first, or another letter |
| Drive missing in elevated tools | UAC split token | Set EnableLinkedConnections to 1 and restart |
| Access denied when opening the drive | Share or NTFS permissions | Check effective access for the user on the share |
| Group member does not get the drive | Old security token | Sign out and in; check whoami /groups |
Drive map GPO missing from gpresult /scope user | GPO linked to a computer OU | Link to the user OU, or use loopback processing on the computer OU |
| Script drives appear late | Five-minute logon script delay | Set “Configure Logon Script Delay” to 0 |
Roll back or undo
- If items used “Remove this item when it is no longer applied”, unlink or delete the GPO and the drives disappear at the next sign-in.
- Otherwise, change the item’s action to Delete with the same letter, let it apply for a week, then remove the item.
- For one user, run
net use S: /deleteorRemove-SmbMapping -LocalPath S: -Force. - For Intune, deploy a script that removes the mapping and any scheduled task, then remove the old script assignment.
Once the pilot group works, you can map network drives with Group Policy for the whole company from the same GPO by adding one item per department.
Map network drives with Group Policy at a glance

Official documentation: Group Policy preferences, Mapped drives are not available from an elevated prompt, Use PowerShell scripts on Windows devices in Intune.
Related guides: DFS Namespaces and Replication: Reliable File Server Setup · File server share vs NTFS permissions and ABE · PowerShell logon/startup scripts with Group Policy.
Frequently asked questions
Should I use Create, Update or Replace for drive maps?
Use Update for most drives: it creates the mapping if it is missing and only changes the settings in the item. Use Replace when users keep remapping the letter, because it deletes and recreates the mapping every time.
Why do mapped drives show a red X after sign-in?
Windows restored the drive before the network was ready. Enable “Always wait for the network at computer startup and logon” and open the drive once; the red X clears when the connection is made.
Why can’t I see mapped drives in an elevated PowerShell window?
UAC creates separate standard and elevated logon sessions, and mappings belong to one of them. Set EnableLinkedConnections to 1 under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System and restart, or use UNC paths.
How do I map a drive only for members of one group?
Open the drive map item, enable item-level targeting on the Common tab and add a Security Group condition with User in group. Users get the drive after their next sign-in.
Can Intune map network drives?
Not with a built-in profile. Deploy a PowerShell platform script that runs with the logged-on credentials and creates a persistent mapping, and make sure the device can reach the file server with single sign-on.