Let’s discuss Deploy Kiosk End Session Button Policy for Full Browser Reset with Intune. policy setting controls the availability and function of an “End Session” button within the Microsoft Kiosk Browser application using Microsoft Intune.
When clicked, it prompts the user for confirmation and then performs a full reset of the browsing session: clearing all browsing data (cache, cookies, form data, etc.) and automatically navigating the browser back to the default starting URL.
Organizations choose to enable or disable the “End Session” button based on the intended use case and the required level of user control and privacy. Primary reason to enable this policy is to enhance user privacy and data security on shared devices.
In scenarios where users are dealing with sensitive information (e.g., banking, health records, personal logins), providing a clear “End Session” button offers peace of mind and is a standard best practice for public terminals.
Table of Contents
Deploy Kiosk End Session Button Policy for Full Browser Reset with Intune
The “End Session” button is a key component of the security and user management design for public-access kiosks. sers log into various personal accounts (email, social media). Enabling the button allows users to responsibly end their web access and ensures the computer is returned to a clean, default state for the next patron.
- Enable Forward Back Buttons to Navigate Browsing History for Kiosk Users using Intune
- Block URL Exceptions for Kiosk Browser to Enforce Least Privilege for Web Access using Intune
- How Idle Time Controls Kiosk Browser Session Restart using Intune Policy
Configure Policy from Intune Portal
By sign in to Microsoft Intune Admin center you can easily configure Windows Apps Access policy. Sign in with Microsoft Intune Admin center. Go to Devices > Configuration > +Create >+ New Policy.

Profile Creation of Policy
After that, you can Create a Profile for the policy which you want to configure. To create a profile you have to select platform and profile type. Here I selected Windows 10 and later as the Platform and Settings catalog as the profile type. Then click on the Create button.

Filling Basic Details
On the Basic tab you can add Name and Description for the policy for further reference. The Name field is necessary to identify the purpose of the policy and description shows more information. The Name is mandatory and if you like to add description you can add. Click on the Next Button.

Configure the Windows Apps Access Tasks
The Configuration settings page is provided to select the settings to create the policy. The Settings Catalog provides a huge number of settings. To select a settings click on the +Add settings hyperlink. Then you will get Settings Picker. Choose Kiosk Browser and select End Session Button Policy. Then I close the Settings Picker.

Disable End Session Button
The dedicated End session button is not visible in the Kiosk browser interface. This is the default value for this policy setting. If you want to go with this section, click on the Next button.

Enable End Session Button
When it enabled, End session button is visible within the Kiosk browser interface. So users can select this button when they are finished using the Kiosk. Click on the Next button.

Scope Tags
By using scope tags you can restrict the visiblity of End Session Button Policy. It is helps to organize resources as well. Here I would like to skip this section, because it is not mandatory. Click on the Next button.

Assignment Tab for Selecting Group
To assign the policy to specific groups, you can use the Assignment Tab. Here I click, +Add groups option under Included groups. I choose a group from the list of groups and click on the Select button. Again, I click on the Select button to continue.

Final Step of Policy Creation
To complete the policy creation you can review all the policy details on the Review + create tab. It helps to avoid mistakes and successfully configure the policy. After varifying all the details click on the Create Button. After creating the policy you will get success message.

Monitoring Status
The Monitoring Status page shows whether the policy has succeeded or not. To quickly configure the policy and take advantage of the policy sync, the device on the Company Portal, Open the Intune Portal. Go to Devices > Configuration > Search for the Policy. Here, the policy shows as successful.

Client Side Verification with Event Viewer
If you get success message, that doesn’t means you will get the policy advanatges. To varify the policy successfully configured to client device check the Event Viwer. Filter for Event ID 813: This will help you quickly find the relevant logs.
Open Event Viewer: Go to Start > Event Viewer. Navigate to Logs: In the left pane, go to Application and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin.
| Details of Event ID |
|---|
| MDM PolicyManager: Set policy int, Policy: (EnableEndSessionButton), Area: (KioskBrowser), EnrollmentID requesting merge: (EB427D85-802F-46D9-A3E2-D5B414587F63), Current User: (Device), Int: (0x1), Enrollment Type: (0x6), Scope: (0x0). |

Removing the Assigned Group from End Session Button Policy
If you want to remove the Assigned group from the policy, it is possible from Intune Portal. To do this open the Policy on Intune Portal and Edit the Assignments tab and Remove the Policy.
To get more detailed information, you can refer to our previous post – Learn How to Delete or Remove App Assignment from Intune using by Step-by-Step Guide.

How to Delete End Session Button Policy
You can easily delete the Policy from Intune Portal From the Configuration section you can delete the policy. It will completely remove from the client devices.
For detailed information, you can refer to our previous post – How to Delete Allow Clipboard History Policy in Intune Step by Step Guide.

Windows CSP Details
When the policy is enabled, the Kiosk Browser app shows a button to reset the browser. When the user selects the button, the app will prompt the user for confirmation to end the session. When the user confirms, the Kiosk browser will clear all browsing data (cache, cookies, etc.) and navigate back to the default URL.

Need Further Assistance or Have Technical Questions?
Join the LinkedIn Page and Telegram group to get the step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.
Author
Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Entra, Microsoft Security, Career, etc.
