On your Windows OS Desktop, a wallpaper is an image displayed behind the graphical user interface when the user’s desktop is visible.
In this blog post, we will discuss, how to configure Windows 10 / Windows 11 Desktop wallpaper using Microsoft Intune Device Restriction Policy.
The device restriction policies help administrator control Windows, Android, Mac and iOS devices. These restrictions let you control a wide range of settings and features to protect your organization resource.
Configure Desktop Wallpaper
In the Microsoft Endpoint Manager admin center, Select Devices | Configuration profiles and click on Create a profile.
Select the following details in “Create a profile” pane and click on Create.
- Platform: Windows 10 and later
- Profile type: Templates
- Template name: Device restrictions

In the Locked Screen Experience section, configure the settings as required. For Windows 10 Lock screen, we will select Locked screen picture URL (Desktop only). You need to provide picture URL which is publicly accessible. For corporate environment, the URL should be accessible from company network.

In the Personalization section, provide the URL for Desktop background under Desktop background picture URL (Desktop only).
Click on Next to move to Assignment page.

In the Assignment page, add the Azure AD group on which you want to target the wallpaper settings and click on Next.

In the Review + create page, review the settings and click on Create.

The Device restriction policy has been now created. You can validate policy per-setting status from from Device blade.
- Go to Device | Configuration Profiles
- Click on the Device configuration profile
- Click on Per-setting status

Once policy successfully applied to Windows 10 , you can also find following details in Registry. This is useful in case you are not getting desired result and troubleshooting the issue. More details about PersonalizationCSP can be found here.

End User Experience
Desktop Wallpaper:

Lock Screen:

Related Posts
- Manage Edge Chromium favorites with Endpoint Manager | Intune
- Configure Edge Chromium Homepage & Startup Page
- Configure Microsoft Edge Sleeping Tabs using Intune
- Configure Google Chrome settings using Administrative templates | Intune | Endpoint Manager
- Block USB Device with Exception
- Deny Write Access to USB Devices Using Intune Catalog Settings
This only works for Windows Enterprise and Education versions.
Do you happen to have a workaround to make it work on Windows Pro?
The Personalization CSP settings are applicable for Enterprise and Education Edition.
https://docs.microsoft.com/en-us/windows/client-management/mdm/personalization-csp
Not tried any workarounds yet.
It works, but user can’t change the desktop wallpaper once the policy is applied. Any option to enable user to select other desktop wallpaper as well?