Forum Discussion
Kiosk profile with Azure AD user
Setting User logon type to "Azure AD user or group" does nothing. Event viewer states "No mapping between account names and SIDs was done". Hovering over the Logon Name column info icon states
To configure an AAD account for kiosk mode, use this format: AzureAD\email address removed for privacy reasons.
I can only pick from a list, so unsure what this is referencing.
5 Replies
- DeepJinCopper Contributor
Hi Bogdan,
We want to setup a Kiosk Windows computer with AD Service account which is being sync to Entra ID. When we are trying to use this service account against KIOSK Profile config then we get below error at Intune console:
In the event viewer of the machine, we get below error :
At present there is no special license assigned to service account as well to the machine.
//DeepJin
- Bogdan_GuineaIron Contributor
Hy,
hmm strange, just a few steps for you in order to check and troubleshoot:
- Auto logon account is not a Microsoft 365 user
- Kiosk mode profiles that use auto logon with a local or service account might not properly receive Store app assignments because these require user-based targeting.
- Solution:
- Use Microsoft Edge in kiosk mode (e.g., InPrivate mode) instead of the Kiosk Browser app, as Edge is pre-installed and does not require separate installation.
- Alternatively, ensure the kiosk account is a valid Azure AD user with app assignments.
- Conflicting or legacy policies
- Old or conflicting Intune policies, especially those restricting Store access or app installations, can block kiosk app deployment.
- Solution:
- Review and clean up legacy policies that might interfere.
- Check device compliance and policy conflict reports.
- Windows version and feature support
- Some kiosk modes or apps might not be fully supported on certain Windows versions (e.g., multi-app kiosk mode on Windows 11 had issues as of early 2024).
- Solution:
- Verify device OS version compatibility with the kiosk profile and app.
- Consider fallback to supported configurations like single app kiosk with Edge.
- Network or connectivity issues
- If devices cannot reach Microsoft Store or Intune services due to firewall or proxy restrictions, app installation and kiosk profile application will fail.
- Solution:
- Ensure network connectivity and required URLs are whitelisted.
- Check logs for connectivity errors.
Good luck!
- Auto logon account is not a Microsoft 365 user
- DeepJinCopper Contributor
Hi Bogdan,
Thanks for the reply. Sorry I did not get you. Which kind of license will we need to use a service account to setup a single app Kiosk Profile ?
//DeepJin
- Bogdan_GuineaIron Contributor
Hy,
is that what i mean:
Microsoft Intune announces device-only subscription for shared resources | Microsoft Community Hub
Maybe you could provide some more info on your problem and what you want to achieve as well as what you have done so far, thanks.
Good luck
- Bogdan_GuineaIron Contributor
Hy,
do you have the right license and maybe checked the prerequisites one more time hier https://learn.microsoft.com/en-us/autopilot/self-deploying
Good luck!