Microsoft Intune
App management

Configure Managed Home Screen

In brief

The app-exclusion setting description now spells out “Managed Home Screen” instead of using the abbreviation “MHS” when referring to authentication.

What Intune admins need to know

Administrators can more easily identify that the setting applies while Managed Home Screen requires authentication.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

description: Learn how to configure the Microsoft Managed Home Screen app. ms.date: 2026-09-23T00:00:00.0000000Z ms.topic: how-to ms.reviewer: abigailstein ai-usage: ai-assisted ms.custom: msecd-doc-authoring-1028 ms.reviewer: abigailstein locale: en-us document_id: 5f1cbc09-34f3-e954-098e-9b98d740518a document_version_independent_id: 5f1cbc09-34f3-e954-098e-9b98d740518a | Set to the url of wallpaper | string | | Allows you to set a wallpaper of your choice for the sign in screen. To use this setting, enter the URL of the image that you want set for the sign-in screen wallpaper. This image can be different than the Managed Home Screen wallpaper that is configured with Set device wallpaper. This setting can only be used if Enable sign in is set to True. | ✔️ | | Enable show organization logo on sign in page | bool | TRUE | Turn this setting to True to use a company logo that appears on the sign-in screen. This setting is used with Organization logo on sign in page and can only be used if Enable sign in is set to TRUE. | ✔️ | | Organization logo on sign in page | string | | Allows you to brand your device with a logo of your choice on the Managed Home Screen sign-in screen. To use this setting, enter the URL of the image that you want set for the logo. This setting can only be used if Enable show organization logo on sign in page and Enable sign in is set to True. | ✔️ | | Enable session PIN | bool | FALSE | Turn this setting to True if you want end-users to get prompted to create a local Session PIN after they successfully sign in to Managed Home Screen. The Session PIN prompt appears before end-user gets access to the home screen, and can be used in conjunction with other features. The Session PIN lasts during a user's sign in and clears upon sign out. By default, this setting is off. This setting can only be used if Enable sign in is set to True. | ✔️
Note: On devices that have a device configuration profile with the Enabled System Navigation Features setting set to Home and Overview buttons or System notifications and information setting set to Show system notifications and information in device's status bar, end users can ignore and skipdismiss the session PIN screen.screen without entering the PIN. To restrict apps while Managed Home Screen requires authentication, enable Silence apps while Managed Home Screen requires authentication. Use Exclude these apps from the silence setting for apps that must remain active. | | Complexity of session PIN | string | | Choose whether the local session PIN should be simple, complex, complex numeric only, or alphanumeric complex. If you choose simple, users are required to enter a numeric PIN. If you choose complex, users get prompted to create a PIN with alphanumeric characters and no repeating (444) or ordered sequences (123, 432, 246) are allowed. Evaluation of repeating and sequential patterns begins at three (3) digits/characters. If you choose complex numeric only, users get prompted to create a PIN with numerals only and no repeating (444) or ordered sequences (123, 432, 246) are allowed. Evaluation of repeating and sequential patterns begins at three (3) digits/characters. If you choose alphanumeric complex, then users get prompted to create a PIN with alphanumeric characters, and at least one symbol or letter is required. No repeating (444) or ordered sequences (123, 432, 246) are allowed. Evaluation of repeating and sequential patterns begins at three (3) characters. The default value for this setting is one (1), where one (1) means that the user must have at least one character in their Session PIN. This setting can only be used if Enable session PIN and Enable sign in are set to True. | ✔️
Note: The complex numeric only and alphanumeric complex options are only available in app config today. | | Minimum length for session PIN | string | | Define the minimum length a user's session PIN must adhere to. This setting can be used with any of the complexity values for session PIN. This setting can only be used if Enable session PIN and Enable sign in is set to True. | ❌ | | Maximum number of attempts for session PIN | string | | Define the maximum number of times a user can attempt to enter their session PIN before getting automatically logged out from Managed Home Screen. The default value is zero (0), where zero (0) means the user gets infinite tries. This setting can be used with any of the complexity values for session PIN. This setting can only be used if Enable session PIN and Enable sign in is set to True. | ❌ | | Offline work time before required sign-in | Integer | 60 | Set the time (in seconds) users can stay offline after the network is detected before they must sign in. This setting only applies when Configure offline app access is set to true for at least one application. | ❌ | | Configure app access without sign in | bundleArray | See Enter JSON Data section of this document | Select which apps are available to users from the sign-in screen before signing in to Managed Home Screen. These apps are available via entry point on the top bar regardless of network status. This setting can only be used if Enable sign in is set to true. | ✔️ | | Silence apps while Managed Home Screen requires authentication | bool | FALSE | Silence apps whenever MHS is prompting the user for authentication, such as during the sign-in or session PIN screens. Silenced apps can't start activities, show notifications, appear in recent apps, or trigger alerts like toasts, dialogs, or ringing. Apps are automatically unsilenced when the device is unlocked. | ❌ | | Exclude these apps from the silence setting | bundleArray | See Enter JSON Data section of this document | Specify apps to exclude from silencing while MHS is requiringManaged Home Screen requires authentication. These apps can start activities, show notifications, appear in recent apps, or trigger alerts like toasts, dialogs, or ringing while the device is locked. You can specifySpecify the apps by entering the app package name of the appsfor each app that you want to be excluded.exclude.
Note: For MAM-integrated apps that you exclude from silencing, assign an Intune app protection policy to both the app and the signed-in user. No specific app protection policy setting is required. If a user opens protected app content while Managed Home Screen requires sign-in or session PIN authentication, the app redirects the user to Managed Home Screen to authenticate. | ❌ |

Note

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…