Forum Discussion

DeepJin's avatar
DeepJin
Copper Contributor
Apr 29, 2025

Kiosk profile with Azure AD user

Setting User logon type to "Azure AD user or group" does nothing. Event viewer states "No mapping between account names and SIDs was done". Hovering over the Logon Name column info icon states

To configure an AAD account for kiosk mode, use this format: AzureAD\email address removed for privacy reasons.

I can only pick from a list, so unsure what this is referencing.

5 Replies

  • DeepJin's avatar
    DeepJin
    Copper Contributor

    Hi Bogdan,

     

    We want to setup a Kiosk Windows computer with AD Service account which is being sync to Entra ID. When we are trying to use this service account against KIOSK Profile config then we get below error at Intune console:

     

    In the event viewer of the machine, we get below error :

     

    At present there is no special license assigned to service account as well to the machine.

     

    //DeepJin

    • Bogdan_Guinea's avatar
      Bogdan_Guinea
      Iron Contributor

      Hy,

      hmm strange, just a few steps for you in order to check and troubleshoot:

      1. Auto logon account is not a Microsoft 365 user
        • Kiosk mode profiles that use auto logon with a local or service account might not properly receive Store app assignments because these require user-based targeting.
        • Solution:
          • Use Microsoft Edge in kiosk mode (e.g., InPrivate mode) instead of the Kiosk Browser app, as Edge is pre-installed and does not require separate installation.
          • Alternatively, ensure the kiosk account is a valid Azure AD user with app assignments.
      2. Conflicting or legacy policies
        • Old or conflicting Intune policies, especially those restricting Store access or app installations, can block kiosk app deployment.
        • Solution:
          • Review and clean up legacy policies that might interfere.
          • Check device compliance and policy conflict reports.
      3. Windows version and feature support
        • Some kiosk modes or apps might not be fully supported on certain Windows versions (e.g., multi-app kiosk mode on Windows 11 had issues as of early 2024).
        • Solution:
          • Verify device OS version compatibility with the kiosk profile and app.
          • Consider fallback to supported configurations like single app kiosk with Edge.
      4. Network or connectivity issues
        • If devices cannot reach Microsoft Store or Intune services due to firewall or proxy restrictions, app installation and kiosk profile application will fail.
        • Solution:
          • Ensure network connectivity and required URLs are whitelisted.
          • Check logs for connectivity errors.

       

      Good luck!

  • DeepJin's avatar
    DeepJin
    Copper Contributor

    Hi Bogdan,

     

    Thanks for the reply. Sorry I did not get you. Which kind of license will we need to use a service account to setup a single app Kiosk Profile ?

     

    //DeepJin

Resources

OSZAR »