Hi @Rajdip das,
You can create a configurations profile for windows 10 or later.
You can limit locations with Intune;
With GPO you can explicit desktop Only
Computer Configuration > Policy > Windows Settings > Security Settings > File System.
Right-click and add %userprofile%\Desktop (or other folders you want to restrict).
Always consider the trade-off between security and user experience when implementing these restrictions.