Frontline scanners, signage tablets and shared ward devices all want the same thing: a corporate-owned Android device that boots into exactly the apps you chose and nothing else. Intune delivers that with Android Enterprise dedicated device enrollment plus Microsoft Managed Home Screen (MHS) as the launcher. In this post I'll walk through the enrollment profile, kiosk configuration, shared device mode sign-in, and what to check when apps or the launcher don't appear.
Prerequisites#
- Devices: Android 8.0 or later with Google Mobile Services, Play Protect certified, and Android Enterprise available in your country or region. Dedicated enrollment requires a factory reset.
- Tenant: MDM authority set to Intune and the tenant connected to Managed Google Play (Devices › Enrollment › Android › Managed Google Play).
- Apps: every app you want on the device, including Managed Home Screen itself, added from Managed Google Play and assigned as Required to the device group. Dedicated devices install only required apps.
- A device group: either a static group selected in the enrollment profile, or a dynamic group with the rule
(device.enrollmentProfileName -eq "Your profile name"). - Built-in apps: the Microsoft Intune app is installed automatically during enrollment and can't be removed; the shared device mode token also installs Microsoft Authenticator and Company Portal.
Step-by-step#
Step 1: Create the enrollment profile and token#
Go to Devices › Enrollment › Android › Corporate-owned dedicated devices › Create profile. Choose the Token type: Corporate-owned dedicated device for a plain kiosk, or Corporate-owned dedicated device with Microsoft Entra ID shared mode when users will sign in and out of apps that support shared device mode (single sign-in and sign-out across participating apps). Set the token expiry (up to 65 years), optionally a naming template such as WH-{{SERIAL}}, pick the device group for enrollment-time grouping, and add scope tags if regional admins own these devices. After creation, open the profile and select Token to show the 20-digit string and QR code; from there you can replace, revoke or export it as JSON for Google Zero-touch or Knox Mobile Enrollment. Profiles tied to expired tokens disappear from the list unless you filter on inactive policies.
Step 2: Enroll the devices#
On a factory-reset device, tap the first setup screen repeatedly to launch the QR reader (Android 9 and later ship with one), scan the code and follow the prompts. Where QR isn't practical, type afw#setup on the Google sign-in screen, install Android Device Policy, and enter the token manually. Tell technicians not to restart a device mid-enrollment: it can end up looking enrolled while receiving no policy.
Watch out: Android enrollment authenticates through a Chrome tab. If a Conditional Access policy that requires a compliant device, or a block policy, applies to all cloud apps on Android browsers, exclude the Microsoft Intune cloud app or enrollment fails.
Step 3: Configure kiosk mode in a device restrictions profile#
Create a profile under Devices › Manage devices › Configuration › Create › New policy › Android Enterprise › Templates › Device restrictions for fully managed, dedicated and corporate-owned work profile devices. Under Device experience, set Device experience type to Kiosk mode and choose:
- Single app: one app runs at boot and the user can't leave it. The app must be added in Intune and assigned to the device group.
- Multi-app: Managed Home Screen becomes the launcher and shows the apps you add under Home screen. MHS itself doesn't have to be in the list, but it must be added from Managed Google Play and assigned as required, and so must every app you list.
Multi-app mode exposes the common MHS settings here too: app layout and grid size, folders, lock home screen, virtual home button, screen saver, Wi-Fi/Bluetooth/flashlight/volume toggles, and Leave kiosk mode with a 4–6 digit code for technicians. Pair it with the General settings for kiosk-mode devices: End-user access to device settings Block, Power button menu Block, Factory reset Block and Status bar Block. Kiosk mode doesn't stop an allowed app from launching other apps, including Settings, so uninstall what you don't need.
Step 4: Add an app configuration policy for Managed Home Screen#
Settings not exposed in the device restrictions template live in an app configuration policy: Apps › Configuration › Create › Managed devices, platform Android Enterprise, profile type Fully Managed, Dedicated, and Corporate-Owned Work Profile Only, targeted at Managed Home Screen. The configuration designer covers most keys; allow-listed applications, pinned web links, managed folders and widgets are JSON-only. For shared devices, the keys that matter are Enable sign in, Sign in type (Microsoft Entra ID), Enable session PIN, Enable auto sign out with its inactivity timer, and Configure offline app access / Configure app access without sign in for apps that must work before sign-in. MHS also supports QR code authentication with a PIN, which spares frontline staff from typing long UPNs.
Tip: Several MHS features need Android permissions: the virtual home button, screen saver and auto sign-out need the overlay permission, and on Android 14 and later the screen saver, auto sign-out and auto-relaunch need the exact alarm (Alarms & Reminders) permission. Grant them through OEMConfig where the OEM supports it, so users aren't sent into Settings to approve prompts.
Verify#
- The device appears under Devices › All devices with ownership Corporate, no primary user, and the expected enrollment profile name; it lands in your device group.
- After the first sync, the device reboots into Managed Home Screen showing only the allowed apps. The device restrictions profile and the app configuration policy both report Succeeded for the device.
- Pressing Back repeatedly reaches the debug menu, where the exit kiosk option asks for your leave-kiosk code; from there you can also view and upload MHS logs.
- On shared device mode tokens, MHS shows the sign-in screen, a sign-in flows through to the other participating apps, and sign-out (manual or after inactivity) clears them.
Tips & gotchas#
- An app is missing from the home screen. It's either not assigned as Required to a group the device is in, not yet installed (MHS only shows installed apps), or not added to the kiosk app list or allow list. If an app in the multi-app list isn't required or assigned, devices can lock users out with the message Contact your IT admin. This phone will be erased., so fix assignments before touching the device.
- MHS never launches. Confirm Managed Home Screen is assigned as required to the device group and that the device restrictions profile is set to multi-app kiosk mode and targets the same group. Two profiles with different kiosk settings aimed at one device will conflict.
- Users bypass the sign-in or PIN screen. Enabling the Overview button under Enabled system navigation features, or showing notifications via System notifications and information, lets users dismiss those screens. If you need either, set End-user access to device settings to Block and consider Silence apps while Managed Home Screen requires authentication.
- Overlay features stopped working. Notification windows set to Disable in device restrictions breaks everything that relies on the overlay permission: virtual home button, screen saver, auto sign-out.
- Need to work on a device remotely? Use the Suspend Managed Home Screen remote action (Devices › All devices › (device) › Remote actions) and Restore Managed Home Screen afterwards. The device needs the Alarms & Reminders permission granted to MHS, and the Help Desk Operator role includes both permissions. Remote Help also supports unattended sessions on dedicated devices.
- Wi-Fi from MHS is limited by design. Users can switch networks but can't turn Wi-Fi on or off or join enterprise networks from the MHS menu. Deploy Wi-Fi profiles instead, and consider the Network escape hatch for devices that boot without connectivity.
- User attributes don't exist here. Certificate profiles that use variables such as
{{UserPrincipalName}}fail on dedicated devices; use device certificates for Wi-Fi. - Recent change (September 2026): on shared device mode kiosks, MAM-integrated apps now send users back to MHS to sign in or enter the session PIN before opening protected content, as long as an app protection policy targets both the app and the signed-in user.