Kiosk mode set up - azure ad log in - multi app

Iron Contributor

Hello everyone,


I'm struggling to enable kiosk mode and need some help. What I'm aiming for is to have users have access to only Edge, Office apps (including OneNote), Settings, and Python.

Users will use Azure AD for device login, as they are managed through Intune.

I attempted to follow the instructions at but encountered difficulties getting it to work.

When applying the policy I created, I encountered an error: -2016281112.

Any suggestions or ideas on how to resolve this issue would be greatly appreciated.

2 Replies

Hi @ABill1,

The error code -2016281112 encountered during the setup of a multi-app kiosk mode with Azure AD login may be connected to users being targeted by conditional access policies needing user interaction, such as Multi-Factor Authentication (MFA) or maybe even Terms of Use (TOU).

To troubleshoot (resolve) this issue, cyou can follow these steps:

  1. Exclude kiosk users from any conditional access policies mandating user interaction, such as MFA or TOU.
  2. If the kiosk user has MFA enabled, disable it, as MFA is currently not supported in multi-app kiosk mode scenarios.

Users can't log on to Windows 10 computers with multi-app kiosk profile assigned - Intune | Microsof...

Windows 11 kiosk with multiple Azure AD users - Microsoft Q&A

Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.

If the post was useful in other ways, please consider giving it Like.

Kindest regards,

Leon Pavesic


So I dont use MFA however I have gone the device config way which has worked better however I have encountered some errors


Current set up 


Screenshot 2023-12-06 at 13.08.03.png


 This works but I need to set up pinned apps to be the ones I have added. Also some more which I am yet to add like onenote and powerpoint. 


What would the Start layout be to get this done?