Intune supports one kiosk profile per device. Design the device around its job, not the other way round.
Menu boards, order terminals, stock handhelds, ticket printers and the tablets that pass between shifts all need pinning to the work they exist to do. Windows, Android and Apple each provide a route there, the routes behave differently, and the Android one starts by erasing the device, which is a plan you need before the hardware ships rather than after.

- One profilePer device, unless you use custom settings
- Single or multi appThe Windows kiosk modes
- Factory resetRequired for Android dedicated enrollment
- Unattended supportAvailable on Android dedicated devices
Decide the device role before the devices arrive.
Of every population in a fleet, shared and single-purpose devices punish a late decision hardest, because reaching the correct management state usually means erasing the hardware first.
- Android Enterprise dedicated enrollment requires a factory reset. Hardware already deployed and running has to be wiped to get there, which costs nothing when the devices are still boxed in a stockroom and a great deal when they are two hundred live terminals in stores.
- Only one kiosk profile applies to a device, so it does the job you configured and nothing else. Where a single unit genuinely has to behave differently in different contexts, that is a custom settings conversation rather than a request for a second profile.
- On Windows the single app and multi app experiences differ substantially, and the current guidance describes Intune multi-app kiosk configuration on Windows 10 while directing readers elsewhere for Windows 11. Since Windows 10 left support in October 2025, verify this against your own machines rather than assuming.
- Getting the sequence right pays back disproportionately. A properly dedicated device cannot be repurposed, cannot drift away from its job, needs no user account administration, and on Android can be supported remotely with nobody present to approve the connection.
Eight facts that shape how a dedicated device gets built.
Single app kiosk, which is genuinely locked
One user account, one browser or application, launched automatically at sign-in, and no route to opening anything else or swapping what is running. Microsoft illustrates it with Edge pinned to a single site. This is the mode behind a lobby display, a wayfinding screen, or any terminal built to do exactly one thing.
Multi app kiosk, for a role rather than a task
A defined collection of Store applications, Win32 applications, browsers or built-in Windows applications, with nothing available beyond what you listed. Microsoft describes the payoff as an experience people can understand immediately, where the tools the job needs are present and everything irrelevant has been taken off the screen. That maps neatly onto shift work.
The Windows 11 multi-app caveat, which affects planning
The current documentation describes configuring a multi-app kiosk through Intune on Windows 10 devices and points readers elsewhere for Windows 11. With Windows 10 having reached end of support on October 14, 2025, any multi-app kiosk plan needs this checked against the machines you actually operate instead of assumed either way.
One kiosk profile per device
Intune allows a single kiosk profile on any given device, and where more than one is genuinely needed the documented route is custom settings. The ceiling rarely causes trouble, but it does mean a device is committed to one identity, which surfaces whenever somebody wants the same tablet behaving one way at reception and another way in a back office.
Android dedicated devices, and what they are for
Company-owned single-use and kiosk hardware, with digital signage, ticket printing and inventory management named as the intended jobs. You define which applications and web links exist and block anything beyond the assigned purpose. In American retail, hospitality, distribution and facilities work that describes a very large share of the equipment on the floor.
The Android factory reset, which has to be planned
Dedicated device enrollment under Android Enterprise cannot happen without wiping the hardware, per the published table. Sealed boxes make that trivial; two hundred terminals already running in stores make it a project with a maintenance window and an explanation. More than anything else, this single requirement separates a smooth Android kiosk deployment from a painful one, and it belongs in the purchasing conversation.
Unattended remote support, on exactly this population
Remote Help can connect a technician to an Android device without anybody at the far end accepting the session, and that capability is available specifically where the device is enrolled as an Android Enterprise dedicated device. The pairing is deliberate rather than incidental: these are the devices with nobody standing in front of them, and it converts a site visit into a remote fix.
Devices with no Google services have their own route
Company hardware built on the Android Open Source Project without Google Mobile Services has a userless enrollment option with nobody assigned to it, intended for shared equipment of the sort found in a library or a lab. Rugged and purpose-built units frequently sit here, and it is a separate enrollment path rather than a setting on the standard one.
Four habits that keep a dedicated device genuinely dedicated.
We settle what the device is for before picking a platform or a mode
How many applications, whether a person signs in at all, which web links belong in scope, and whether the unit will ever need to be something different. Those answers settle single app against multi app, dedicated against fully managed, and standard configuration against a custom one. Picking a mode first and bending the job to fit it is how these deployments end up compromised.
We raise the factory reset before devices are ordered
Dedicated enrollment on Android wipes the hardware, which is nothing at all for boxed stock and genuinely disruptive for units already running in stores, warehouses or clinics. Brought up during purchasing it costs five minutes. Brought up after distribution it becomes a scheduled outage and somebody explaining to a regional manager why the terminals are down.
We build the support path for a device with nobody at it
A display in a hallway, a terminal in a stockroom, a handheld on a charging rack. There is no one present to approve a remote session and no one who will complain when it stops working. Unattended access on Android dedicated devices, together with alerting for units that stop checking in, is what keeps these supportable without dispatching a vehicle.
We keep the configuration narrow deliberately
A dedicated device is valuable precisely because of what it refuses to do, so every additional application and every extra permitted link chips away at the point of it. The multi app benefit is described as clearing away the tools people do not need, and the discipline is holding that list to what the job genuinely requires and no more.
Six US situations where dedicated devices are the right answer.
Retail and hospitality terminals
Ordering screens, queue displays, ticket printers, customer-facing information panels and stock lookup units. Ticket printing and signage appear by name among the dedicated device use cases, and constraining the available applications and links is what stops a counter tablet turning into a general browser.
Warehouse and logistics handsets
Inventory management is another named use case, and it accounts for a large slice of the hardware in any distribution operation. A good deal of that equipment ships without Google Mobile Services, which places it on the Android Open Source Project route rather than the standard Android Enterprise one.
Reception, wayfinding and meeting room displays
Screens in public space showing one thing, reachable by anyone and supervised by no one. Single app kiosk mode holds the device to one browser on one site with no path to anything else, which is both the correct configuration and markedly safer than a general-purpose machine that happens to be displaying a page.
Shop floor and site terminals used across shifts
Hardware belonging to a role rather than a person, passing through several pairs of hands in a day. Multi app kiosk delivers exactly the applications that role needs and removes the rest from view, which cuts support load and shrinks the surface where things can go wrong at the same time.
Shared devices in education and training
Lab machines, library terminals, training room hardware and tablets held in a cart. The Android Open Source Project userless option is intended for shared equipment of precisely that kind, and having no user attached to the device is the property that makes managing it feasible at all.
A regulated environment with public-facing devices
Branch terminals, queue systems, self-service kiosks, check-in tablets in a clinic waiting room. What is required here is restriction you can demonstrate rather than restriction by convention, because a public-area machine running general software is a finding waiting to be written up. A kiosk profile that forecloses opening anything else is evidence, whether the reviewer works from HIPAA, GLBA or an insurance questionnaire.
How single-purpose devices actually get managed.
| Feature | Properly dedicated | Locked by convention | A general device doing a job |
|---|---|---|---|
Only the intended applications available | Yes | No | No |
Users cannot open anything else | Yes | No | No |
No personal account signed in | Yes | Sometimes | Often there is one |
Device enrolled in the right management state | Yes | Partly | Rarely |
Web browsing restricted to permitted links | Yes | No | No |
Remote support without anybody present | On Android dedicated | No | No |
Updates reach the device reliably | Yes | Sometimes | Rarely |
Somebody notices when it stops reporting | Yes | No | No |
Usable for something it was not intended for | No | Yes | Yes |
How common this is in practice | Uncommon | Common | Very common |
Where each kiosk path lives, and what it suits.
Platform
Windows, single app
- What is available
- One account pinned to a single browser or application, with no way to launch anything else
Platform
Windows, multi app
- What is available
- A named set of Store, Win32, browser and built-in applications, and nothing beyond it
Platform
Windows Holographic for Business
- What is available
- Kiosk settings of its own, for mixed reality hardware
Platform
Android Enterprise dedicated
- What is available
- Single-use and kiosk hardware, applications and links constrained, hardware wiped at enrollment
Platform
Android Enterprise, device experience
- What is available
- Kiosk configuration reached through the Android Enterprise device restriction settings
Platform
Android Open Source Project, userless
- What is available
- Shared hardware with no Google services and nobody assigned to it
Platform
iOS and iPadOS
- What is available
- Kiosk configuration reached through the Apple device restriction settings
Platform
Multiple kiosk profiles on one device
- What is available
- Not available directly. Custom settings are the documented alternative.
Five steps, and the first one happens before procurement.
- 1
Define the device role and the permitted set
One application or several, whether a person signs in, precisely which applications and links are allowed, and whether the unit will ever need to do something else. Every later decision, platform and enrollment method included, follows from those answers.
- 2
Choose the enrollment path, before the devices arrive
Android Enterprise dedicated, the Android Open Source Project userless route for hardware without Google services, or a Windows kiosk profile. Because dedicated enrollment on Android wipes the device, this has to precede distribution or the project quietly acquires an erasure exercise nobody budgeted for.
- 3
Build and test the kiosk configuration
Single app or multi app on Windows, or the equivalent restrictions on Android or Apple hardware, proven on a real device doing the real job. These configurations fail loudly and specifically, almost always a missing application or a link the workflow depends on, and ten minutes of genuine use exposes both.
- 4
Set up support for a device with nobody at it
Unattended access wherever Android Enterprise dedicated enrollment makes it available, plus alerting for devices that stop reporting, because nobody opens a ticket about a hallway screen that went dark. This step decides whether the fleet is still working in month three.
- 5
Deploy, and keep the permitted list short
Rolled out by site or by role, with periodic review to confirm the approved application and link list has not quietly expanded. What a dedicated device cannot do is the entire value of it, and that value erodes one reasonable-sounding addition at a time.
What organizations ask about kiosk and shared devices.
Fifteen questions worth answering first.
The device role
- Does this device do one thing or several?Single app and multi app are different modes.
- Is anybody signed in as a person?A good many of these devices have no user at all.
- Which applications and web links are permitted?Everything omitted should be unreachable.
- Does the device need to behave differently by location?Remember the one-profile-per-device ceiling.
- Is this a frontline worker scenario?That is the framing kiosk mode was built around.
The enrollment path
- Which platform, and which enrollment method?What each permits varies substantially.
- Are the devices already deployed?Android dedicated enrollment wipes the hardware.
- Do the Android devices have Google services?Without them the AOSP userless route applies.
- Are you on Windows 10 or Windows 11?It changes the multi-app kiosk picture.
- Who will enroll them, and how many?Ordinary accounts stop at fifteen devices.
Running them
- How do you support a device with nobody at it?Unattended access covers Android dedicated devices.
- How do updates reach a device nobody logs into?Design this rather than hoping.
- What happens if one is stolen or moved?Physical exposure comes with the territory.
- Who notices when one stops checking in?A dark screen in a hallway files no ticket.
- Is the device physically secured?Locked software on unlocked hardware is half a control.
The pages around this one.
Android Enterprise management
A closer look at the enrollment methods, including the factory reset table and the zero-touch route for volume deployment.
Device enrollment design
The enrollment decision across every platform, and which routes begin by erasing the machine.
Microsoft Intune
The platform these configurations live inside, alongside compliance, application delivery and reporting.
Settle the enrollment path before the hardware is distributed.
Dedicated enrollment on Android begins with a wipe, which costs nothing for boxed stock and becomes a real project for terminals already running on shop floors and sites. Half an hour spent on this during purchasing is the cheapest part of the entire deployment.
Related Services
Explore more solutions that work great with this service