Edit

Share via


Deploy Restrict Known Folder Move from Office Group Policy

The Restrict Known Folder Move from Office (Restrict KFM from Office) Group Policy allows administrators to control whether Office apps display prompts encouraging users to back up their files to Microsoft OneDrive.

When this policy is enabled and deployed, Office doesn't display the message bar, even if users are eligible for the Known Folder Move (KFM) feature. This policy applies only to Office apps and doesn't affect other OneDrive or KFM configurations. It's available in the Administrative Template files for Microsoft Office (version 5497.1000 or newer).

Tip

  • Enable this policy if you don’t want users to see prompts to back up their files.
  • If KFM is blocked in your organization, the message bar doesn't appear, even if users are eligible.
  • Microsoft respects existing policies that block KFM and doesn't display prompts in those environments.

What users see when eligible

When the policy isn't enabled, eligible users might see a message bar in Microsoft Word, Excel, and PowerPoint (Windows desktop versions) prompting them to enroll in OneDrive Known Folder Move (KFM). The message bar allows users to select folders to back up to OneDrive.

Important

If users aren't enrolled in KFM, they might see the message:
"BACK UP THIS DOCUMENT: Share and work with others in this and other files using OneDrive."

Selecting Open OneDrive lets users choose which folders to back up.

By enabling and deploying the Restrict KFM from Office Group Policy, administrators can prevent these prompts and maintain control over KFM adoption.

When the Message Bar isn't displayed

The message bar doesn't appear under the following conditions:

Deployment methods

Option 1: Deploy via Group Policy (Active Directory or hybrid environments)

If you're using Active Directory, Microsoft Entra, or a hybrid environment, you can deploy the policy using Group Policy Objects (GPOs).

  1. Download the Administrative Template files (ADMX/ADML) for Microsoft Office.
  2. Select Download, then choose the 32-bit (x86), 64-bit (x64), or both versions.
  3. Select Next, then choose a ___location to save the file.
  4. Run the downloaded admintemplates_XXXXXXX_en-us.exe and follow the prompts to extract the files.
  5. After extracting, you'll see admin and admx folders.
  6. On your Active Directory server:
    • Copy the .admx files into %SYSTEMROOT%\PolicyDefinitions
    • Copy the corresponding language .adml files into %SYSTEMROOT%\PolicyDefinitions[Language-CountryRegion]
      • For example, copy U.S. English .adml files into the en-us folder.
  7. Open Group Policy Management.
  8. Under Domains, select the appropriate policy (for example, Default Domain Policy) and choose Edit.
  9. In the Group Policy Management Editor, go to:
    User Configuration > Policies > Administrative Templates: Policy Definitions > All Settings
  10. Locate Restrict KFM from Office, right-click it, and select Edit.
  11. Change the setting from Not Configured to Enabled, then select Apply and OK.
  12. The policy setting should now display as Enabled.

Screenshot shows comment being added to the Restrict KFM from Office tool.

Screenshot that shows the disabling KFM pop ups via the Group Policy Management editor.

Note

It might take up to 24 hours for the policy to take effect.

Option 2: Deploy via Cloud Policy service

You can also deploy this policy using the Cloud Policy service for Microsoft 365. This method works even if the device isn't ___domain-joined. When a user signs into Microsoft 365 Apps for Enterprise on a device, the policy settings roam to that device. See Overview of Cloud Policy to learn more about cloud policies for Microsoft 356 Apps.

To deploy the policy:

  1. Sign in to the Microsoft 365 Apps admin center with administrative credentials.
  2. Under Customization, select Policy Management.
  3. On the Policy configurations page, select Create.
  4. On the Start with the basics page, enter a Name (required) and Description (optional), then select Next.
  5. On the Choose the scope page, select whether the policy applies to:
    • All users
    • Specific groups
    • Users accessing Office for the web anonymously
  6. If applying to specific groups, select Add Groups and choose the relevant groups.

Note

Adding multiple groups to a single policy configuration allows for the same group to be included in multiple policy configurations, facilitating a more streamlined and efficient policy management process.

  1. Select Next.
  2. On the Configure Settings page:
    • Search for Restrict KFM from Office or use a filter.
    • Set the configuration to Enabled, then select Apply.
  3. Review your selections and choose Create.
  4. Select Done.

screenshot of KFM configuration settings

Once configured, the policy will apply to eligible users the next time they sign in to Microsoft 365 Apps on any device.