Kiosk
26 TopicsKiosk Mode not logging in - "kioskUser0 the user name or password is incorrect"
I am working with creating a Device Configuration Profile for Kiosk Mode. The device is Windows 10 1809 and is Azure AD joined only and is syncing and receiving policies, updates, and software. When the device is restarted the Kiosk policy attempts to force the Auto-login option but fails. It is showing User "kioskUser0" and giving the generic message of "username/password is incorrect". I wait a minute or 2 and the timeout for attempting the login with the kiosk user occurs, then I am able to then login with any azure ad user I attempt. When the policy is applied is it creating kioskUser0 as a local account on the device? Other than restarting, is there any way for the device to attempt to log back into the kiosk section? (logging in and signing out does not seem to trigger this)61KViews0likes11CommentsIntune - how to exit Kiosk mode
Dear forum members, I have found when a device is in kiosk mode (in my case, an iPad), removing the kiosk device restriction configuration profile will not take the device out of the kiosk mode, even after a restart. I will have to assign the device to a different group to receive another configuration profile that has kiosk mode not turned on, or wipe the device. Has anyone experience this too? Thanks.Solved25KViews0likes4CommentsWindows 10 multi-app kiosk mode - Teams desktop app
I want to build a Windows 10 kiosk, showing 2 apps: Edge and Microsoft Teams desktop app. I've tried using the multi-app kiosk configuration in Intune and publishing Edge is no problem, but I don't succeed in publishing the Teams desktop app. Either it's telling me the AUMID is incorrect or when I try to publish it as an Win32 App nothing shows up. I've solved it for now by using the Teams web app in Edge, but the customer wants the desktop app so I have to figure out an other way of publishing it.23KViews0likes7CommentsProblem with autologin on multi app Kiosk Win 10
Hello guys, I have a problem with multiple Windows machines. All machines are Dell optiplex 7060 and few Intel NUC's and all have enabled TPM (or PTT). They have latest W10 2004 installed, fully updated. All machines are deployed through Intune as multi app kiosk, with two apps - Zoom Rooms and Teamviewer. Process for setup is I import csv file from machine (I manually add group tag kiosk). It's assigned to dynamic group, from there it gets Deployment profile. Everything work as expected with Windows 1903 or 1909 until last update. For already deployed machines, few of them (not all) after update to 2004 were unable to autologin. Initial setup goes perfectly, unfortunately when it's done I don't get autologin. It asks me for user and when I enter .\kioskUser0 it goes in and works as expected. I’ve accessed devices also with my admin account, updated everything (Windows and drivers), still the same. I also changed the registry for WinLogon - AutoAdminLogon to 1 (keeps reseting to 0), DefaultPassword (whole entry keeps deleting), DefaultUserName (set to kioskUser0). Nothing helped. I've also done several manual syncs through Intune for all devices that have autologin issue, also didn't help. I've done also some further testing with one dell optiplex 7060 and now all new deployements (tried with 1909 and 2004) had autologin problem. I've attached few screenshots for configuration. Any ideas how can I solve this issue?Solved22KViews0likes14CommentsAble to exit Single-app Kiosk mode on Android
Recently I was testing Single-app Kiosk mode with Android Enterprise. When I created a Device configuration profile with the Kiosk settings (and Edge as the only app) and I entered Kiosk mode on the assigned device, only Edge would start. When I closed it, it would reappear. All these features are ofcourse expected from Single-app Kiosk, so everything looked fine. However I was able to press the Overview button (the button that shows all active apps) and press the Multiview settings on the top right. Then I am able to go back a few times until I reach the device settings. There I am able to do everything (including factory reset). Is this normal that the settings are available when Kiosk mode has been assigned? The only setting I changed in my Device configuration profile was the Kiosk mode to Single App.Solved20KViews0likes2CommentsIssues with Kiosk Mode Refresh
I am having issues with Edge in Kiosk Mode not wanting to refresh the page as we need it to. I am trying to accomplish this with command line arguments, as follows: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --kiosk https://www.contoso.com --kiosk-idle-timeout-minutes=15 This solution is not refreshing the session at all - is there a way to do what I'm trying? I know that there are Extensions that will auto-refresh pages, but they do not currently work in Kiosk mode.17KViews0likes6CommentsiOS Update Installation Failure - Status -2016330697
Dear Forum Members, I have an iPad configured in Kiosk mode and locked in with single app Edge browser. I also configured an iOS update policy to update the iOS from 12.4.6 to 13.0.0. I didn't work and received an installation failure status -2016330697 (It is a minus sign, not a hyphen). The error is from Intune - Software Updates - Installation failures for iOS devices. Can anyone tell me what is this error mean and direct me where to troubleshoot next? Thank you all so much!15KViews0likes6CommentsAndroid device password not applying in Kiosk mode
Hi everyone, I'm not sure if I'm missing something here and please correct me if what I'm doing is not possible or by design. I'm setting up an Android tablet for single application use in Kiosk mode. I'm using a QR code to enrol the device and get it configured. Everything is working perfectly *except* no device password is being applied and I can specifically see the password policies failing to apply. I've configured the device password in the same policy that deploys the single use app. So... Device Configuration -> Profiles -> Platform = Android Enterprise, Profile Type = Device Restrictions (Device Owner). I've enforced to at least use a numeric pin, minimum lenght = 4, Keyguard = Not configured. My question ultimately is ..... is it possible to configure a device/screen lock password/pin on a kiosk device? My use case here is the device is for single app use, by a trusted person. The person will know the pin to unlock the device, but the device does not have any other purpose than running this one application, and the device should not be used for anything else other than running this one application. I can see all the settings I've configured applying successfully, except the device password ones. Any advise on if this is possible and if so, where I can start troubleshooting?Solved13KViews0likes13CommentsManaged Home Screen Woes
Setting up a Company Owned Dedicated (kiosk) Android device can be a bit challenging to get just right. After several hours of reading Reddit, Microsoft, and Personally owned blogs and threads, I figured I would consolidate everything I have found to hopefully have this show up on someone else's Google results. (Main link for Managed Home Screen Configuration: https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-managed-home-screen-app ) Calling issues with Managed Home Screen The Issue: Devices were able to receive phone calls, but the only notification was in the default system's notification tray; this was while the device was locked and unlocked. This posed an issue as we would like to 1) disable the default system tray and 2) We need at least the phone to light up when it was locked to let the users know they're getting a call. The Solution: After researching it is my assumption that the underlying issue is that while the phone is managed, and enrolled as a Company Owned Dedicated Device, for some reason the UI elements are NOT identified as managed items. So the administrator must deploy the following applications as Android Enterprise System Apps and set them as required installs: com.samsung.android.incallui --- I named this Call UI, Publisher Android com.android.server.telecom --- I named this Telecom (1 of 2 Req for Phone App), Publisher Android com.samsung.android.app.telephonyui --- I named this Telephony UI (2 of 2 Req for Phone App), Publisher Android (Yes, these are probably not the "Android Designated Application Name" but that's what they're staying as in my tenant.) That's it. Done. Phone was able to receive calls with the normal quarter of the top screen notification, as well as a full screen notification if the device was locked. However, some previous research also let me to these other items that may help someone else from googling: The Android Phone App Package ID / Android Phone App Bundle ID / Samsung Phone App is: com.samsung.android.dialer --- I named this Phone, Publisher Samsung (unsure for Google, Motorola, etc phones, this works for Samsung) This needs to be set as required as well, and assumedly placed on the managed home screen for the user to make calls (unsure if it is needed to receive calls only... if you have some type of use case for that?). Most predominant links relating to the issue: Article 1: https://www.reddit.com/r/Intune/comments/t427kv/shared_android_phonecalls_from_kiosk_mode/ Article 2: https://www.reddit.com/r/Intune/comments/vxw8xn/comment/ifylsaz/?utm_source=share&utm_medium=web2x&context=3 Managed Home Screen Conflicts App Configuration Policies currently don’t really show you any information as to why or what a conflict is; just that it’s conflicting (thanks, Microsoft). Some common issues I’ve seen around is that while some configurations are available in both the Device Configuration Profile and the App Configuration Policy; you should not apply these settings in both places (see the tables of configurations on the Microsoft doc for Managed Home Screen at the top of this article). Personally, I like having the configurations setup as: Managed Home Screen App Config Policy: Configuration Key Value Type Configuration Value Exit lock task mode password string 123456 MAX time outside MHS integer 600 MAX inactive time outside MHS integer 180 Enable MAX time outside MHS bool TRUE Enable MAX inactive time outside MHS bool TRUE Enable easy access of debug menu bool TRUE Define Theme Color string light Applications in folder are ordered by name bool TRUE Application order enabled bool TRUE Device's serial number choice {{SerialNumber}} Show device name bool TRUE Show Device Info setting bool TRUE Show Volume setting bool TRUE Show Flashlight setting bool TRUE Show Bluetooth setting bool TRUE Show Managed Setting bool TRUE Show Wi-Fi setting bool TRUE Battery and Signal Strength indicator bar bool TRUE Set device wall paper string https://i.imgur.com/OPlCeFG.jpg Lock Home Screen bool TRUE Enable notifications badge bool TRUE (Exiting Kiosk mode is then within the Device Managed Settings > i > Exit Kiosk Mode with the ‘Exit lock task mode password’ pin.) Dedicated Device Configuration Policy: (In my experience, this is an overview of the settings that should / shouldn’t be set with Managed Home Screen. This is not all the settings, that’s a lot of typing. But this will give you a good start. I am sure not all of these affect the Managed Home Screen as well, but at least the ones under Device Experience do.) General: Permission Policy – Default Date and Time – Block Factory Reset, Status Bar – Blocked Skip first hints – Enable Power Button Menu – Block System Error Warnings – Allow Enabled System Navigation Features – Home and overview buttons System Notifications and Information – Show both Device Experience: Enrollment Type – Dedicated Device Kiosk Mode – Multi-App Custom Layout – Enable (Note: all of these apps need to be deployed and set as required) App Notification Badges – Enable Virtual Home Button thru Wi-Fi Configuration– ALL Not Configured (as these are configured within the App Configuration Policy!) Bluetooth, Flashlight, Media, Quick access to device info – Enabled Managed Home Screen Background I found that the best place to configure this is only within the App Configuration Policy. The main issue everyone seems to face is that the image URL must end with a ‘.jpg’. This is very easily overcome; find an image on Google, Download it, Go to Imgur, Upload it (watch your ad), Right click it afterwards, then click Copy Image Link. Boom imgur.com/somerandomletters.jpg Finding the Android App Identifier Honestly, this is a lot more complicated than it needs to be. Note: Adding the Managed Home Screen app to the Home Screen shows up as Managed Settings and works great. Here’s a list of the common ones: App Name Store URL App Identifier Calendar https://play.google.com/store/apps/details?id=com.samsung.android.calendar com.samsung.android.calendar Camera https://play.google.com/store/apps/details?id=com.sec.android.app.camera com.sec.android.app.camera Clock https://play.google.com/store/apps/details?id=com.google.android.deskclock&hl=en-US com.google.android.deskclock Gallery https://play.google.com/store/apps/details?id=com.sec.android.gallery3d com.sec.android.gallery3d Google Play Store com.android.vending Microsoft Intune https://play.google.com/store/apps/details?id=com.microsoft.intune&hl=en-US com.microsoft.intune Managed Home Screen https://play.google.com/store/apps/details?id=com.microsoft.launcher.enterprise&hl=en-US com.microsoft.launcher.enterprise Microsoft OneDrive https://play.google.com/store/apps/details?id=com.microsoft.skydrive&hl=en-US com.microsoft.skydrive Microsoft Outlook https://play.google.com/store/apps/details?id=com.microsoft.office.outlook&hl=en-US com.microsoft.office.outlook Microsoft Teams https://play.google.com/store/apps/details?id=com.microsoft.teams&hl=en-US com.microsoft.teams Phone https://play.google.com/store/apps/details?id=com.samsung.android.dialer com.samsung.android.dialer Samsung Notes https://play.google.com/store/apps/details?id=com.samsung.android.app.notes&hl=en-US com.samsung.android.app.notes Settings https://play.google.com/store/apps/details?id=com.android.settings com.android.settings There were a LOT of articles and treads I read about these issues and I cannot possibly find them all again to post here. But here are a few to try and give credit: https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-managed-home-screen-app https://www.reddit.com/r/Intune/comments/t427kv/shared_android_phonecalls_from_kiosk_mode/ https://www.reddit.com/r/Intune/comments/vxw8xn/comment/ifylsaz/?utm_source=share&utm_medium=web2x&context=3 https://github.com/petarov/google-android-app-ids (Some of these are incorrect for my use cases (needed Android apps not Google Apps)) https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work?WT.mc_id=Portal-Microsoft_Intune_DeviceSettings https://learn.microsoft.com/en-us/mem/intune/apps/apps-ae-system#enable-a-system-app-in-intune13KViews4likes2CommentsMS Edge kiosk mode offer to translate webpage
I have created a Microsoft Edge Kiosk mode based on the manual at: https://docs.microsoft.com/en-us/deployedge/microsoft-edge-configure-kiosk-mode#microsoft-edge-with-assigned-access, using Windows Settings I have previously used kiosk mode, both "Digital/Interactive Signage" and "Public-Browsing" with the old Edge, without problems. Then I created a new Kiosk machine, based on Edge Chromium, an "Digital/Interactive Signage". It works well, except for it will always ask to set over the page from Norwegian to English! The page is a room plan for the building, updated regularly at: https://tp.uio.no/timeplan/skjerm.php?area=BL&more=1&building%5B%5D=BL09&building%5B%5D=BL10&building%5B%5D=BL11&room=&zoom=1.5&hide=1 It's impossible to get rid of this message, it's popping up all the time. Normally there is an option "Do not offer translation from Norwegian to English", but it's not there. If I translate from Norwegian to English, it has forgotten that choice next time the page is reloaded. If I choose "Not now", it's forgotten next time the page is reloaded. If I accept Edge to set over from Norwegian to English, it does so, but the choice is forgotten next time the webpage is reloaded. I also tried to set over from Norwegian to Norwegian, but at next refresh the choice was forgotten. I have set up two computers with this kiosk configuration, one in Active Directory, one stand-alone, same result The computer is Win10, Edge 97.0.1072.2510KViews0likes9Comments