Configure KFM
Step-by-step guide to configuring OneDrive Known Folder Move (KFM) on macOS. Learn best practices, troubleshooting tips, and how to optimize KFM settings for your organization's needs.
Last updated
Was this helpful?
Step-by-step guide to configuring OneDrive Known Folder Move (KFM) on macOS. Learn best practices, troubleshooting tips, and how to optimize KFM settings for your organization's needs.
KFM is only supported by the standalone OneDrive sync app (e.g. contained in Microsoft 365 Apps package in Intune). The version from macOS App Store does not support KFM.
The following settings control the behavoiur of KFM: We are forcing KFM and enable it silently for Desktop and Documents. We also activate the KFM wizard to prompt users for activation (e.g.: kicks in if errors occur).
You can download a ready to use KFM policy from here. Right click and select "Save as ..." to save it locally on your device.
Go to the Intune Portal and sign in.
Select Create -> Import Policy and Upload the .json file that you have downloaded earlier.
Edit the policy and replace "XYZ" with your Tenant ID (two times).
Assign the policy to the desired (test) group.
OneDrive needs to run in background. Since macOS 13 (Ventura) this has to be consented explicitly. If you already have a policy for Service Management (Managed Login Items) you can add OneDrive there, too.
You can download a ready to use Service Management policy from here. Right click and select "Save as ..." to save it locally on your device.
Go to the Intune Portal and sign in.
Select Create -> Import Policy and Upload the .json file that you have downloaded earlier.
Assign the policy to the desired (test) group.
OneDrive needs Full Disk Access for KFM. If you already have a policy for Privacy Preferences Policy Control (that grants "System Policy All Files") you can add OneDrive there, too.
You can download a ready to use Full Disk Access policy from here. Right click and select "Save as ..." to save it locally on your device.
Go to the Intune Portal and sign in.
Select Create -> Import Policy and Upload the .json file that you have downloaded earlier.
Assign the policy to the desired (test) group.
Last updated
Was this helpful?
Was this helpful?