Reception screens, warehouse terminals, exam labs and loaner laptops all need the same thing: a Windows device that does one job and nothing else, and comes back to a clean state for the next person. Intune covers this with the Kiosk template, Assigned Access XML for Windows 11 multi-app scenarios, and the Shared multi-user device template. In this post I'll walk through each, show how Autopilot self-deploying mode gets a device there without anyone signing in, and list the reasons a kiosk app fails to appear.
Prerequisites#
- Windows edition: Assigned Access works on Pro, Enterprise (including LTSC), Education and IoT Enterprise. User Account Control must stay enabled, and the kiosk experience only works at the console, not over Remote Desktop.
- Account model: the kiosk profile applies to standard users only; it never loads for members of the local Administrators group. Decide between Auto logon (Windows creates and manages a local standard account), a local account you created, or a Microsoft Entra user or group.
- Apps first: any Store app, Win32 app or Kiosk Browser you reference must already be installed on the device before the kiosk configuration applies. Deploy the app as Required to the same device group.
- One kiosk profile per device. If you need more, the documented route is a custom OMA-URI profile with your own Assigned Access XML.
Step-by-step#
Step 1: Single-app kiosk with the Kiosk template#
Go to Devices › Manage devices › Configuration › Create › New policy, choose Windows 10 and later and Templates › Kiosk. Under Select a kiosk mode pick Single app, full-screen kiosk, then set the User logon type and the Application type:
| Application type | Key settings |
|---|---|
| Add Microsoft Edge browser (Edge 87 and later) | Edge Kiosk URL; Microsoft Edge kiosk mode type: Public Browsing (InPrivate) for limited multi-tab browsing or Digital/Interactive Signage (InPrivate) for one full-screen site; Refresh browser after idle time (0 to 1440 minutes) |
| Add Kiosk browser | Deploy the Kiosk Browser app first. Then set the default home page, whether to show home, navigation and end session buttons, idle refresh (1 to 1440 minutes) and an allowed websites list (subdomains are allowed automatically, no wildcards) |
| Add Store app | Pick an app already added to Intune |
Edge's own behaviour (home page, extensions, downloads, printing) isn't configured here; use the settings catalog for Microsoft Edge policies and assign that profile to the same devices as the kiosk profile. The optional Specify Maintenance Window for App Restarts setting lets Store app updates that need a restart happen at a time you choose instead of three days after the update at an unscheduled moment.
Step 2: Multi-app kiosk (restricted user experience)#
The template's Multi app kiosk mode is documented for Windows 10 only: you add Store apps, Win32 apps by executable path and inbox apps by AUMID, pick one app to auto-launch, choose tile sizes or supply an alternative Start layout XML, and decide whether to show the taskbar and allow the Downloads folder. For Windows 11, Microsoft's documented route is an Assigned Access XML file delivered through a custom profile: Templates › Custom, OMA-URI ./Vendor/MSFT/AssignedAccess/Configuration, with the XML as the value (data type String (XML file) to upload the file, or String to paste it). The skeleton looks like this:
<?xml version="1.0" encoding="utf-8"?>
<AssignedAccessConfiguration
xmlns="http://schemas.microsoft.com/AssignedAccess/2017/config"
xmlns:rs5="http://schemas.microsoft.com/AssignedAccess/201810/config"
xmlns:v5="http://schemas.microsoft.com/AssignedAccess/2022/config">
<Profiles>
<Profile Id="{GUID-FROM-NEW-GUID}">
<AllAppsList>
<AllowedApps>
<App AppUserModelId="Microsoft.WindowsCalculator_8wekyb3d8bbwe!App" />
<App DesktopAppPath="%ProgramFiles(x86)%\Microsoft\Edge\Application\msedge.exe" />
</AllowedApps>
</AllAppsList>
<rs5:FileExplorerNamespaceRestrictions>
<rs5:AllowedNamespace Name="Downloads"/>
</rs5:FileExplorerNamespaceRestrictions>
<v5:StartPins><![CDATA[ { "pinnedList": [ {"packagedAppId": "Microsoft.WindowsCalculator_8wekyb3d8bbwe!App"} ] } ]]></v5:StartPins>
<Taskbar ShowTaskbar="true"/>
</Profile>
</Profiles>
<Configs>
<Config>
<AutoLogonAccount rs5:DisplayName="Front desk"/>
<DefaultProfile Id="{GUID-FROM-NEW-GUID}"/>
</Config>
</Configs>
</AssignedAccessConfiguration>Rules worth knowing: an AllAppList profile can be assigned to users or groups, but a KioskModeApp profile only to users; nested groups aren't supported; include dependencies in the allowed list (Edge pinned sites also need msedge_proxy.exe and the Edge AUMID); Windows 11 Start pins use the exported JSON from Export-StartLayout inside v5:StartPins; and the configuration takes effect at the next sign-in of the targeted account. Deleting the policy removes the restrictions but doesn't revert everything, for example the Start layout.
Step 3: Shared PC for multi-user devices#
When several people sign in with their own accounts, create Templates › Shared multi-user device. It drives the SharedPC CSP:
| Setting | What it does |
|---|---|
| Shared PC mode | Enables the mode; one user signed in at a time |
| Guest account | Guest, Domain, or Guest and domain; a guest gets a fresh local account each time |
| Account management and Account Deletion | Immediately after log-out, At storage space threshold, or At storage space threshold and inactive threshold, with start and stop thresholds in percent and an inactive threshold of 0 to 60 days |
| Local Storage | Disable to stop users saving files to the device |
| Power Policies and Sleep time out | Lock power settings; sleep after 0 to 18000 seconds (3600 if unset) |
| Sign-in when PC wakes | Require a password after sleep |
| Maintenance start time | Minutes from midnight for automatic maintenance such as Windows Update |
| Education policies | Stricter defaults for school devices |
Step 4: Provision with Autopilot self-deploying mode#
Self-deploying mode joins the device to Microsoft Entra ID, enrolls it in Intune and holds it at the Enrollment Status Page until policies and apps are down, with no user credentials typed on the device. It's device-based, so the kiosk, Shared PC, app and Edge profiles must all be assigned to device groups, typically a dynamic group built on the Autopilot group tag. It requires TPM 2.0 with attestation (virtual machines fail with 0x800705B4), supports Microsoft Entra join only, and sets no primary user. Combine it with an Auto logon kiosk profile and the device boots straight into the kiosk app after provisioning.
Verify#
- In Intune, open the profile's Device status and confirm Succeeded for the device; an error here usually means malformed XML or an app that wasn't installed yet.
- Restart (or sign out and in as the kiosk account) and confirm the app launches full screen; press Ctrl+Alt+Del to break out, which is the default breakout sequence unless you defined another.
- For Assigned Access XML, Event Viewer under Applications and Services Logs › Microsoft › Windows › AssignedAccess (the Admin and Operational logs) records whether the configuration was applied, and the DeviceManagement-Enterprise-Diagnostics-Provider › Admin log shows whether the CSP accepted the XML at all.
- On a Shared PC, sign in as two different users in turn and confirm the account cleanup behaviour you configured.
Tips & gotchas#
- Kiosk app doesn't launch: the app isn't installed for that account, the AUMID is wrong, the account is a local admin, you're testing over RDP, or the XML references a profile ID that isn't defined. Fix the app deployment first; Assigned Access can't start what isn't there.
- Sign-in blocked: don't target kiosk accounts with Conditional Access that needs interaction (MFA, terms of use); the sign-in has no way to satisfy it. Exchange ActiveSync password restrictions on the device break autologon, and Microsoft also lists the
PreferredAadTenantDomainNamepolicy as one that stops automatic sign-in from working. - Local accounts hidden: on Microsoft Entra joined devices, local users don't appear on the sign-in screen unless you enable the
WindowsLogon/EnumerateLocalUsersOnDomainJoinedComputerspolicy. - Edge kiosk: the template's Edge option needs Edge 87 or later; older builds use the legacy options, which you should avoid on new deployments.
- Security notes: keep the kiosk account a standard user, hide the taskbar and block the Downloads folder unless needed, turn off local storage on Shared PCs, encrypt the disk with BitLocker, keep a LAPS-managed local administrator for recovery, and configure Windows Update and power settings so the device isn't rebooting or sleeping in front of customers.
- Re-provisioning: a device deployed with self-deploying mode can't automatically go through Autopilot again; delete its record in Devices › All devices before resetting it.