Configure Managed Home Screen
In brief
The app-exclusion setting description now spells out “Managed Home Screen” instead of using the abbreviation “MHS” when referring to authentication.
What Intune admins need to know
Administrators can more easily identify that the setting applies while Managed Home Screen requires authentication.
This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
description: Learn how to configure the Microsoft Managed Home Screen app.
ms.date: 2026-09-23T00:00:00.0000000Z
ms.topic: how-to
ms.reviewer: abigailstein
ai-usage: ai-assisted
ms.custom: msecd-doc-authoring-1028
ms.reviewer: abigailstein
locale: en-us
document_id: 5f1cbc09-34f3-e954-098e-9b98d740518a
document_version_independent_id: 5f1cbc09-34f3-e954-098e-9b98d740518a
| Set to the url of wallpaper | string | | Allows you to set a wallpaper of your choice for the sign in screen. To use this setting, enter the URL of the image that you want set for the sign-in screen wallpaper. This image can be different than the Managed Home Screen wallpaper that is configured with Set device wallpaper. This setting can only be used if Enable sign in is set to True. | ✔️ |
| Enable show organization logo on sign in page | bool | TRUE | Turn this setting to True to use a company logo that appears on the sign-in screen. This setting is used with Organization logo on sign in page and can only be used if Enable sign in is set to TRUE. | ✔️ |
| Organization logo on sign in page | string | | Allows you to brand your device with a logo of your choice on the Managed Home Screen sign-in screen. To use this setting, enter the URL of the image that you want set for the logo. This setting can only be used if Enable show organization logo on sign in page and Enable sign in is set to True. | ✔️ |
| Enable session PIN | bool | FALSE | Turn this setting to True if you want end-users to get prompted to create a local Session PIN after they successfully sign in to Managed Home Screen. The Session PIN prompt appears before end-user gets access to the home screen, and can be used in conjunction with other features. The Session PIN lasts during a user's sign in and clears upon sign out. By default, this setting is off. This setting can only be used if Enable sign in is set to True. | ✔️
Note: On devices that have a device configuration profile with the Enabled System Navigation Features setting set to Home and Overview buttons or System notifications and information setting set to Show system notifications and information in device's status bar, end users can ignore and skipdismiss the session PIN screen.screen without entering the PIN. To restrict apps while Managed Home Screen requires authentication, enable Silence apps while Managed Home Screen requires authentication. Use Exclude these apps from the silence setting for apps that must remain active. |
| Complexity of session PIN | string | | Choose whether the local session PIN should be simple, complex, complex numeric only, or alphanumeric complex. If you choose simple, users are required to enter a numeric PIN. If you choose complex, users get prompted to create a PIN with alphanumeric characters and no repeating (444) or ordered sequences (123, 432, 246) are allowed. Evaluation of repeating and sequential patterns begins at three (3) digits/characters. If you choose complex numeric only, users get prompted to create a PIN with numerals only and no repeating (444) or ordered sequences (123, 432, 246) are allowed. Evaluation of repeating and sequential patterns begins at three (3) digits/characters. If you choose alphanumeric complex, then users get prompted to create a PIN with alphanumeric characters, and at least one symbol or letter is required. No repeating (444) or ordered sequences (123, 432, 246) are allowed. Evaluation of repeating and sequential patterns begins at three (3) characters. The default value for this setting is one (1), where one (1) means that the user must have at least one character in their Session PIN. This setting can only be used if Enable session PIN and Enable sign in are set to True. | ✔️
Note: The complex numeric only and alphanumeric complex options are only available in app config today. |
| Minimum length for session PIN | string | | Define the minimum length a user's session PIN must adhere to. This setting can be used with any of the complexity values for session PIN. This setting can only be used if Enable session PIN and Enable sign in is set to True. | ❌ |
| Maximum number of attempts for session PIN | string | | Define the maximum number of times a user can attempt to enter their session PIN before getting automatically logged out from Managed Home Screen. The default value is zero (0), where zero (0) means the user gets infinite tries. This setting can be used with any of the complexity values for session PIN. This setting can only be used if Enable session PIN and Enable sign in is set to True. | ❌ |
| Offline work time before required sign-in | Integer | 60 | Set the time (in seconds) users can stay offline after the network is detected before they must sign in. This setting only applies when Configure offline app access is set to true for at least one application. | ❌ |
| Configure app access without sign in | bundleArray | See Enter JSON Data section of this document | Select which apps are available to users from the sign-in screen before signing in to Managed Home Screen. These apps are available via entry point on the top bar regardless of network status. This setting can only be used if Enable sign in is set to true. | ✔️ |
| Silence apps while Managed Home Screen requires authentication | bool | FALSE | Silence apps whenever MHS is prompting the user for authentication, such as during the sign-in or session PIN screens. Silenced apps can't start activities, show notifications, appear in recent apps, or trigger alerts like toasts, dialogs, or ringing. Apps are automatically unsilenced when the device is unlocked. | ❌ |
| Exclude these apps from the silence setting | bundleArray | See Enter JSON Data section of this document | Specify apps to exclude from silencing while MHS is requiringManaged Home Screen requires authentication. These apps can start activities, show notifications, appear in recent apps, or trigger alerts like toasts, dialogs, or ringing while the device is locked. You can specifySpecify the apps by entering the app package name of the appsfor each app that you want to be excluded.exclude.
Note: For MAM-integrated apps that you exclude from silencing, assign an Intune app protection policy to both the app and the signed-in user. No specific app protection policy setting is required. If a user opens protected app content while Managed Home Screen requires sign-in or session PIN authentication, the app redirects the user to Managed Home Screen to authenticate. | ❌ |
Note
@@ -16,9 +16,9 @@ ms.subservice: apps description: Learn how to configure the Microsoft Managed Home Screen app. ms.date: 2026-09-23T00:00:00.0000000Z ms.topic: how-to-ms.reviewer: abigailstein ai-usage: ai-assisted ms.custom: msecd-doc-authoring-1028+ms.reviewer: abigailstein locale: en-us document_id: 5f1cbc09-34f3-e954-098e-9b98d740518a document_version_independent_id: 5f1cbc09-34f3-e954-098e-9b98d740518a@@ -228,7 +228,7 @@ The automatic relaunch functionality requires granting exact alarm permission (O | Set to the url of wallpaper | string | | Allows you to set a wallpaper of your choice for the sign in screen. To use this setting, enter the URL of the image that you want set for the sign-in screen wallpaper. This image can be different than the Managed Home Screen wallpaper that is configured with **Set device wallpaper**. This setting can only be used if **Enable sign in** is set to True. | ✔️ |
| Enable show organization logo on sign in page | bool | TRUE | Turn this setting to True to use a company logo that appears on the sign-in screen. This setting is used with **Organization logo on sign in page** and can only be used if **Enable sign in** is set to TRUE. | ✔️ |
| Organization logo on sign in page | string | | Allows you to brand your device with a logo of your choice on the Managed Home Screen sign-in screen. To use this setting, enter the URL of the image that you want set for the logo. This setting can only be used if **Enable show organization logo on sign in page** and **Enable sign in** is set to True. | ✔️ |
-| Enable session PIN | bool | FALSE | Turn this setting to True if you want end-users to get prompted to create a local Session PIN after they successfully sign in to Managed Home Screen. The Session PIN prompt appears before end-user gets access to the home screen, and can be used in conjunction with other features. The Session PIN lasts during a user's sign in and clears upon sign out. By default, this setting is off. This setting can only be used if **Enable sign in** is set to True. | ✔️ <br>**Note:** On devices that have a device configuration profile with the [**Enabled System Navigation Features** setting](../../device-configuration/templates/ref-device-restrictions-android-enterprise) set to **Home and Overview buttons** or [**System notifications and information** setting](../../device-configuration/templates/ref-device-restrictions-android-enterprise) set to **Show system notifications and information in device's status bar**, end users can ignore and skip the session PIN screen. |
+| Enable session PIN | bool | FALSE | Turn this setting to True if you want end-users to get prompted to create a local Session PIN after they successfully sign in to Managed Home Screen. The Session PIN prompt appears before end-user gets access to the home screen, and can be used in conjunction with other features. The Session PIN lasts during a user's sign in and clears upon sign out. By default, this setting is off. This setting can only be used if **Enable sign in** is set to True. | ✔️ <br>**Note:** On devices that have a device configuration profile with the [**Enabled System Navigation Features** setting](../../device-configuration/templates/ref-device-restrictions-android-enterprise) set to **Home and Overview buttons** or [**System notifications and information** setting](../../device-configuration/templates/ref-device-restrictions-android-enterprise) set to **Show system notifications and information in device's status bar**, end users can dismiss the session PIN screen without entering the PIN. To restrict apps while Managed Home Screen requires authentication, enable **Silence apps while Managed Home Screen requires authentication**. Use **Exclude these apps from the silence setting** for apps that must remain active. |
| Complexity of session PIN | string | | Choose whether the local session PIN should be **simple**, **complex**, **complex numeric only**, or **alphanumeric complex**. If you choose **simple**, users are required to enter a numeric PIN. If you choose **complex**, users get prompted to create a PIN with alphanumeric characters and no repeating (444) or ordered sequences (123, 432, 246) are allowed. Evaluation of repeating and sequential patterns begins at three (3) digits/characters. If you choose **complex numeric only**, users get prompted to create a PIN with numerals only and no repeating (444) or ordered sequences (123, 432, 246) are allowed. Evaluation of repeating and sequential patterns begins at three (3) digits/characters. If you choose **alphanumeric complex**, then users get prompted to create a PIN with alphanumeric characters, and at least one symbol or letter is required. No repeating (444) or ordered sequences (123, 432, 246) are allowed. Evaluation of repeating and sequential patterns begins at three (3) characters. The default value for this setting is one (1), where one (1) means that the user must have at least one character in their Session PIN. This setting can only be used if **Enable session PIN** and **Enable sign in** are set to True. | ✔️ <br>**Note:** The **complex numeric only** and **alphanumeric complex** options are only available in app config today. |
| Minimum length for session PIN | string | | Define the minimum length a user's session PIN must adhere to. This setting can be used with any of the complexity values for session PIN. This setting can only be used if **Enable session PIN** and **Enable sign in** is set to True. | ❌ |
| Maximum number of attempts for session PIN | string | | Define the maximum number of times a user can attempt to enter their session PIN before getting automatically logged out from Managed Home Screen. The default value is zero (0), where zero (0) means the user gets infinite tries. This setting can be used with any of the complexity values for session PIN. This setting can only be used if **Enable session PIN** and **Enable sign in** is set to True. | ❌ |
@@ -244,7 +244,7 @@ The automatic relaunch functionality requires granting exact alarm permission (O | Offline work time before required sign-in | Integer | 60 | Set the time (in seconds) users can stay offline after the network is detected before they must sign in. This setting only applies when **Configure offline app access** is set to true for at least one application. | ❌ |
| Configure app access without sign in | bundleArray | See **Enter JSON Data** section of this document | Select which apps are available to users from the sign-in screen before signing in to Managed Home Screen. These apps are available via entry point on the top bar regardless of network status. This setting can only be used if **Enable sign in** is set to true. | ✔️ |
| Silence apps while Managed Home Screen requires authentication | bool | FALSE | Silence apps whenever MHS is prompting the user for authentication, such as during the sign-in or session PIN screens. Silenced apps can't start activities, show notifications, appear in recent apps, or trigger alerts like toasts, dialogs, or ringing. Apps are automatically unsilenced when the device is unlocked. | ❌ |
-| Exclude these apps from the silence setting | bundleArray | See **Enter JSON Data** section of this document | Specify apps to exclude from silencing while MHS is requiring authentication. These apps can start activities, show notifications, appear in recent apps, or trigger alerts like toasts, dialogs, or ringing while the device is locked. You can specify the apps by entering the app package name of the apps that you want to be excluded. | ❌ |
+| Exclude these apps from the silence setting | bundleArray | See **Enter JSON Data** section of this document | Specify apps to exclude from silencing while Managed Home Screen requires authentication. These apps can start activities, show notifications, appear in recent apps, or trigger alerts like toasts, dialogs, or ringing while the device is locked. Specify the apps by entering the package name for each app that you want to exclude. <br>**Note:** For MAM-integrated apps that you exclude from silencing, assign an [Intune app protection policy](../protection/create-policy) to both the app and the signed-in user. No specific app protection policy setting is required. If a user opens protected app content while Managed Home Screen requires sign-in or session PIN authentication, the app redirects the user to Managed Home Screen to authenticate. | ❌ |
Note