OneDrive folder exclusions: the admin control the last few updates didn’t have
OneDrive’s new folder exclusion feature is a genuinely well-governed change: off by default, entirely admin-controlled through Group Policy, with no way for users to enable, disable or override it themselves.
If your organisation has developers or anyone working with tools that generate large local-only folders, this is worth planning for properly, not because it’s risky, but because it’s genuinely useful and easy to configure imperfectly.
What’s changing
Rollout begins worldwide in mid-August 2026 and is expected to complete by late August (Roadmap ID 567470), covering OneDrive for Windows and OneDrive for Mac.
Administrators will be able to define folder names or path patterns that should not sync to OneDrive, commonly things like node_modules, PowerShell module directories, Visual Studio configuration folders and other machine-specific development tooling.
Anything matching a configured rule, along with its contents, stays local to the device rather than uploading to OneDrive. The feature is off by default, and nothing changes for any organisation until an administrator actively configures exclusion rules.
Two behaviours are worth knowing before you configure anything. First, folders already syncing before a rule is applied continue syncing regardless, the rule only takes effect once a user moves that folder out of OneDrive and back into a synchronised location.
Second, moving files that are already syncing directly into a newly excluded folder isn’t currently supported, they’ll need to go through the same move-out, move-back-in process.
OneDrive also needs restarting after any policy change for the new rules to take effect.
Quick summary
Microsoft OneDrive is introducing admin-managed folder exclusions, rolling out from mid-August 2026, covering:
- Group Policy settings letting administrators stop specific folders, such as node_modules, PowerShell modules and Visual Studio configuration folders, from syncing to OneDrive
- the feature is off by default, with no change to sync behaviour unless an administrator configures it
- users cannot create, modify or override exclusion rules themselves, only administrators can
- folders already syncing before a rule is applied keep syncing until manually moved out of OneDrive and back in, and OneDrive needs restarting for policy changes to take effect
For once, this is a straightforwardly good-news admin story: proper Group Policy control, off by default, no user override. The only real trap is the migration step, existing synced folders don’t fall under a new exclusion rule automatically, and moving already-syncing files directly into an excluded folder isn’t currently supported either.
Why this matters
This is a genuinely well-governed feature, and it’s worth saying so plainly rather than hunting for a hidden catch that isn’t there:
- Admin control is real here, not nominal. Exclusion rules are configured entirely through Group Policy, users cannot create, modify or bypass them, and nothing happens automatically. That’s a meaningful contrast to almost everything else covered in this series recently.
- The main risk is operational, not governance-related. Because existing synced folders don’t retroactively pick up a new exclusion rule, a poorly planned rollout could leave administrators assuming a folder is excluded when it’s actually still syncing, simply because nobody moved it out and back in. That’s a rollout-planning problem, not a security one.
- This is squarely an IT and endpoint management task, not a user communications one. Unlike most of what we’ve covered, the main audience here is whoever manages your Group Policy and endpoint configuration, not end users, who won’t notice anything unless something is misconfigured.

Who’s affected
- Organisations using OneDrive for Windows or Mac, particularly those with developers or teams generating large machine-specific folders
- OneDrive administrators managing sync policy through Group Policy Users storing development or machine-specific content inside
- OneDrive-managed locations, who may need to move folders manually for a new exclusion rule to apply
What we’d recommend doing now
Action is only required if you intend to use this feature, but it’s worth a proper look if storage consumption from local development tooling is already a known issue:
- Identify local-only or machine-specific folders worth excluding, node_modules and similar development tooling are the obvious starting point, but review your own environment rather than assuming Microsoft’s examples cover everything relevant.
- Plan for the migration step explicitly. Existing synced folders won’t pick up a new exclusion rule automatically; build the move-out-and-back-in step into your rollout plan rather than assuming a policy change alone is sufficient.
- Pilot exclusion rules with a small group before wider deployment, given the manual migration step, this is not a change to push tenant-wide without testing first.
- Document excluded folders in your endpoint management standards, and brief helpdesk on the expected behaviour so support tickets about “missing” files can be diagnosed quickly.
Where this fits with your wider Microsoft 365 storage and governance strategy
Unlike the Copilot updates we’ve covered recently, this one is a genuine win for administrators who want tighter control over what OneDrive actually stores, and it’s worth pairing with a broader look at storage management if cloud consumption has been creeping up across your organisation.
If you’d like support planning this properly, we can help in a few ways:
- Get in touch with our support team if you’d like help planning and piloting exclusion rules before wider rollout.
- Talk to a consultant if this is part of a wider Microsoft 365 storage or device management review.
- Book a free Microsoft 365 risk and cost health check if you’re not sure how much of your OneDrive storage is being consumed by local-only, machine-specific content.
Learn more
- IT Admins – Use OneDrive policies to control sync settings – Microsoft Learn
Frequently Asked Questions
Can users exclude their own folders from OneDrive sync?
No. Exclusion rules are configured entirely by administrators through Group Policy. Users cannot create, modify or override them, and the feature is off by default until an administrator configures it.
Will existing synced folders be automatically excluded once a rule is applied?
No. Folders already syncing before a rule is applied continue syncing as normal. The exclusion only takes effect once the folder is manually moved out of OneDrive and back into a synchronised location.
Do you need to restart OneDrive after changing exclusion policies?
Yes. OneDrive must be restarted after any policy change for the updated exclusion rules to take effect.
What kind of folders is this designed for?
Machine-specific or development-related folders that don’t need to live in the cloud, common examples include node_modules, PowerShell module directories and Visual Studio configuration folders.
When is this rolling out?
General availability begins worldwide in mid-August 2026 and is expected to complete by late August 2026, associated with Roadmap ID 567470.
This update is based on Microsoft 365 Roadmap ID 567470, published 17 July 2026. Rollout dates are provided by Microsoft and may change.
