IntuneHow-to

Android Enterprise dedicated devices: Managed Home Screen kiosks and shared device sign-in

Build a locked-down Android kiosk with Intune: dedicated device enrollment tokens, multi-app kiosk mode with Managed Home Screen, Entra shared device mode sign-in, and fixes for missing apps.

Frontline scanners, signage tablets and shared ward devices all want the same thing: a corporate-owned Android device that boots into exactly the apps you chose and nothing else. Intune delivers that with Android Enterprise dedicated device enrollment plus Microsoft Managed Home Screen (MHS) as the launcher. In this post I'll walk through the enrollment profile, kiosk configuration, shared device mode sign-in, and what to check when apps or the launcher don't appear.

How this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (4 steps: Create the enrollment profile and token; Enroll the devices; Configure kiosk mode in a device restrictions profile; Add an app configuration policy for Managed Home Screen). 3. Verify. 4. Tips & gotchas. Toolbox: Templates › Device restrictions, Create › Managed devices, afw#setup, Devices › All devices.1Prerequisites2Step-by-step3Verify4Tips & gotchas1Create the enrollmentprofile and token2Enroll the devices3Configure kiosk mode ina device restrictions pro…4Add an app configurationpolicy for Managed Hom…TOOLBOXTemplates › Device restrictionsCreate › Managed devicesafw#setupDevices › All devicesHow this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (4 steps: Create the enrollment profile and token; Enroll the devices; Configure kiosk mode in a device restrictions profile; Add an app configuration policy for Managed Home Screen). 3. Verify. 4. Tips & gotchas. Toolbox: Templates › Device restrictions, Create › Managed devices, afw#setup, Devices › All devices.1Prerequisites2Step-by-step1Create the enrollment profile and token2Enroll the devices3Configure kiosk mode in a device restrictionsprofile4Add an app configuration policy for ManagedHome Screen3Verify4Tips & gotchasTOOLBOXTemplates › Device restrictionsCreate › Managed devicesafw#setupDevices › All devices
At a glance: how this guide is organised · 4 steps · 4 key settings and tools

Prerequisites#

  • Devices: Android 8.0 or later with Google Mobile Services, Play Protect certified, and Android Enterprise available in your country or region. Dedicated enrollment requires a factory reset.
  • Tenant: MDM authority set to Intune and the tenant connected to Managed Google Play (Devices › Enrollment › Android › Managed Google Play).
  • Apps: every app you want on the device, including Managed Home Screen itself, added from Managed Google Play and assigned as Required to the device group. Dedicated devices install only required apps.
  • A device group: either a static group selected in the enrollment profile, or a dynamic group with the rule (device.enrollmentProfileName -eq "Your profile name").
  • Built-in apps: the Microsoft Intune app is installed automatically during enrollment and can't be removed; the shared device mode token also installs Microsoft Authenticator and Company Portal.

Step-by-step#

Step 1: Create the enrollment profile and token#

Go to Devices › Enrollment › Android › Corporate-owned dedicated devices › Create profile. Choose the Token type: Corporate-owned dedicated device for a plain kiosk, or Corporate-owned dedicated device with Microsoft Entra ID shared mode when users will sign in and out of apps that support shared device mode (single sign-in and sign-out across participating apps). Set the token expiry (up to 65 years), optionally a naming template such as WH-{{SERIAL}}, pick the device group for enrollment-time grouping, and add scope tags if regional admins own these devices. After creation, open the profile and select Token to show the 20-digit string and QR code; from there you can replace, revoke or export it as JSON for Google Zero-touch or Knox Mobile Enrollment. Profiles tied to expired tokens disappear from the list unless you filter on inactive policies.

Step 2: Enroll the devices#

On a factory-reset device, tap the first setup screen repeatedly to launch the QR reader (Android 9 and later ship with one), scan the code and follow the prompts. Where QR isn't practical, type afw#setup on the Google sign-in screen, install Android Device Policy, and enter the token manually. Tell technicians not to restart a device mid-enrollment: it can end up looking enrolled while receiving no policy.

Watch out: Android enrollment authenticates through a Chrome tab. If a Conditional Access policy that requires a compliant device, or a block policy, applies to all cloud apps on Android browsers, exclude the Microsoft Intune cloud app or enrollment fails.

Step 3: Configure kiosk mode in a device restrictions profile#

Create a profile under Devices › Manage devices › Configuration › Create › New policy › Android Enterprise › Templates › Device restrictions for fully managed, dedicated and corporate-owned work profile devices. Under Device experience, set Device experience type to Kiosk mode and choose:

  • Single app: one app runs at boot and the user can't leave it. The app must be added in Intune and assigned to the device group.
  • Multi-app: Managed Home Screen becomes the launcher and shows the apps you add under Home screen. MHS itself doesn't have to be in the list, but it must be added from Managed Google Play and assigned as required, and so must every app you list.

Multi-app mode exposes the common MHS settings here too: app layout and grid size, folders, lock home screen, virtual home button, screen saver, Wi-Fi/Bluetooth/flashlight/volume toggles, and Leave kiosk mode with a 4–6 digit code for technicians. Pair it with the General settings for kiosk-mode devices: End-user access to device settings Block, Power button menu Block, Factory reset Block and Status bar Block. Kiosk mode doesn't stop an allowed app from launching other apps, including Settings, so uninstall what you don't need.

Step 4: Add an app configuration policy for Managed Home Screen#

Settings not exposed in the device restrictions template live in an app configuration policy: Apps › Configuration › Create › Managed devices, platform Android Enterprise, profile type Fully Managed, Dedicated, and Corporate-Owned Work Profile Only, targeted at Managed Home Screen. The configuration designer covers most keys; allow-listed applications, pinned web links, managed folders and widgets are JSON-only. For shared devices, the keys that matter are Enable sign in, Sign in type (Microsoft Entra ID), Enable session PIN, Enable auto sign out with its inactivity timer, and Configure offline app access / Configure app access without sign in for apps that must work before sign-in. MHS also supports QR code authentication with a PIN, which spares frontline staff from typing long UPNs.

Tip: Several MHS features need Android permissions: the virtual home button, screen saver and auto sign-out need the overlay permission, and on Android 14 and later the screen saver, auto sign-out and auto-relaunch need the exact alarm (Alarms & Reminders) permission. Grant them through OEMConfig where the OEM supports it, so users aren't sent into Settings to approve prompts.

Verify#

  • The device appears under Devices › All devices with ownership Corporate, no primary user, and the expected enrollment profile name; it lands in your device group.
  • After the first sync, the device reboots into Managed Home Screen showing only the allowed apps. The device restrictions profile and the app configuration policy both report Succeeded for the device.
  • Pressing Back repeatedly reaches the debug menu, where the exit kiosk option asks for your leave-kiosk code; from there you can also view and upload MHS logs.
  • On shared device mode tokens, MHS shows the sign-in screen, a sign-in flows through to the other participating apps, and sign-out (manual or after inactivity) clears them.

Tips & gotchas#

  • An app is missing from the home screen. It's either not assigned as Required to a group the device is in, not yet installed (MHS only shows installed apps), or not added to the kiosk app list or allow list. If an app in the multi-app list isn't required or assigned, devices can lock users out with the message Contact your IT admin. This phone will be erased., so fix assignments before touching the device.
  • MHS never launches. Confirm Managed Home Screen is assigned as required to the device group and that the device restrictions profile is set to multi-app kiosk mode and targets the same group. Two profiles with different kiosk settings aimed at one device will conflict.
  • Users bypass the sign-in or PIN screen. Enabling the Overview button under Enabled system navigation features, or showing notifications via System notifications and information, lets users dismiss those screens. If you need either, set End-user access to device settings to Block and consider Silence apps while Managed Home Screen requires authentication.
  • Overlay features stopped working. Notification windows set to Disable in device restrictions breaks everything that relies on the overlay permission: virtual home button, screen saver, auto sign-out.
  • Need to work on a device remotely? Use the Suspend Managed Home Screen remote action (Devices › All devices › (device) › Remote actions) and Restore Managed Home Screen afterwards. The device needs the Alarms & Reminders permission granted to MHS, and the Help Desk Operator role includes both permissions. Remote Help also supports unattended sessions on dedicated devices.
  • Wi-Fi from MHS is limited by design. Users can switch networks but can't turn Wi-Fi on or off or join enterprise networks from the MHS menu. Deploy Wi-Fi profiles instead, and consider the Network escape hatch for devices that boot without connectivity.
  • User attributes don't exist here. Certificate profiles that use variables such as {{UserPrincipalName}} fail on dedicated devices; use device certificates for Wi-Fi.
  • Recent change (September 2026): on shared device mode kiosks, MAM-integrated apps now send users back to MHS to sign in or enter the session PIN before opening protected content, as long as an app protection policy targets both the app and the signed-in user.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)