This can happen when the Web App Kiosk policy is configured with a specific login URL or path instead of the base domain. In Web App Kiosk, the allowed web app URL should cover the domain that the site uses after authentication. If the login flow redirects from a bookmarked URL to another path on the same website, the redirected URL may be treated as outside the allowed kiosk scope. To resolve this:
1. Edit the Web App used in the iOS Kiosk Lockdown policy.
2. Use the base domain of the website instead of the full login path or bookmarked URL. For example, use https://<domain> instead of https://<domain>/<login-path>.
3. Save the Web App.
4. Re-associate or refresh the Web App Kiosk policy on the device.
5. Open the web app again and complete the login flow.
If no Web Content Filtering policy is configured, the block is most likely caused by the Web App Kiosk URL scope rather than content filtering.