We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Intune
  2. Kiosk and shared devices
Kiosk and shared devices

Intune supports one kiosk profile per device. Design the device around its job, not the other way round.

Menu boards, order terminals, stock handhelds, ticket printers and the tablets that pass between shifts all need pinning to the work they exist to do. Windows, Android and Apple each provide a route there, the routes behave differently, and the Android one starts by erasing the device, which is a plan you need before the hardware ships rather than after.

Book a shared device reviewSee the platform options
Shared terminals and single-purpose tablets in a US workplace
  • One profilePer device, unless you use custom settings
  • Single or multi appThe Windows kiosk modes
  • Factory resetRequired for Android dedicated enrollment
  • Unattended supportAvailable on Android dedicated devices
The sequencing that decides the cost

Decide the device role before the devices arrive.

Of every population in a fleet, shared and single-purpose devices punish a late decision hardest, because reaching the correct management state usually means erasing the hardware first.

  • Android Enterprise dedicated enrollment requires a factory reset. Hardware already deployed and running has to be wiped to get there, which costs nothing when the devices are still boxed in a stockroom and a great deal when they are two hundred live terminals in stores.
  • Only one kiosk profile applies to a device, so it does the job you configured and nothing else. Where a single unit genuinely has to behave differently in different contexts, that is a custom settings conversation rather than a request for a second profile.
  • On Windows the single app and multi app experiences differ substantially, and the current guidance describes Intune multi-app kiosk configuration on Windows 10 while directing readers elsewhere for Windows 11. Since Windows 10 left support in October 2025, verify this against your own machines rather than assuming.
  • Getting the sequence right pays back disproportionately. A properly dedicated device cannot be repurposed, cannot drift away from its job, needs no user account administration, and on Android can be supported remotely with nobody present to approve the connection.
Ask us to scope the device roles before you buy
How it works

Eight facts that shape how a dedicated device gets built.

A Windows machine running as a kiosk, described by Microsoft as a dedicated device, can be held to a single application or to a defined handful, and the scenario is framed around frontline workers. Android and Apple reach a similar destination through separate mechanisms with capabilities of their own.

Single app kiosk, which is genuinely locked

One user account, one browser or application, launched automatically at sign-in, and no route to opening anything else or swapping what is running. Microsoft illustrates it with Edge pinned to a single site. This is the mode behind a lobby display, a wayfinding screen, or any terminal built to do exactly one thing.

Multi app kiosk, for a role rather than a task

A defined collection of Store applications, Win32 applications, browsers or built-in Windows applications, with nothing available beyond what you listed. Microsoft describes the payoff as an experience people can understand immediately, where the tools the job needs are present and everything irrelevant has been taken off the screen. That maps neatly onto shift work.

The Windows 11 multi-app caveat, which affects planning

The current documentation describes configuring a multi-app kiosk through Intune on Windows 10 devices and points readers elsewhere for Windows 11. With Windows 10 having reached end of support on October 14, 2025, any multi-app kiosk plan needs this checked against the machines you actually operate instead of assumed either way.

One kiosk profile per device

Intune allows a single kiosk profile on any given device, and where more than one is genuinely needed the documented route is custom settings. The ceiling rarely causes trouble, but it does mean a device is committed to one identity, which surfaces whenever somebody wants the same tablet behaving one way at reception and another way in a back office.

Android dedicated devices, and what they are for

Company-owned single-use and kiosk hardware, with digital signage, ticket printing and inventory management named as the intended jobs. You define which applications and web links exist and block anything beyond the assigned purpose. In American retail, hospitality, distribution and facilities work that describes a very large share of the equipment on the floor.

The Android factory reset, which has to be planned

Dedicated device enrollment under Android Enterprise cannot happen without wiping the hardware, per the published table. Sealed boxes make that trivial; two hundred terminals already running in stores make it a project with a maintenance window and an explanation. More than anything else, this single requirement separates a smooth Android kiosk deployment from a painful one, and it belongs in the purchasing conversation.

Unattended remote support, on exactly this population

Remote Help can connect a technician to an Android device without anybody at the far end accepting the session, and that capability is available specifically where the device is enrolled as an Android Enterprise dedicated device. The pairing is deliberate rather than incidental: these are the devices with nobody standing in front of them, and it converts a site visit into a remote fix.

Devices with no Google services have their own route

Company hardware built on the Android Open Source Project without Google Mobile Services has a userless enrollment option with nobody assigned to it, intended for shared equipment of the sort found in a library or a lab. Rugged and purpose-built units frequently sit here, and it is a separate enrollment path rather than a setting on the standard one.

How we approach it

Four habits that keep a dedicated device genuinely dedicated.

This is the least glamorous corner of a fleet and frequently the most exposed one, since the hardware sits in public view performing a job that nobody reviews from one year to the next.

We settle what the device is for before picking a platform or a mode

How many applications, whether a person signs in at all, which web links belong in scope, and whether the unit will ever need to be something different. Those answers settle single app against multi app, dedicated against fully managed, and standard configuration against a custom one. Picking a mode first and bending the job to fit it is how these deployments end up compromised.

We raise the factory reset before devices are ordered

Dedicated enrollment on Android wipes the hardware, which is nothing at all for boxed stock and genuinely disruptive for units already running in stores, warehouses or clinics. Brought up during purchasing it costs five minutes. Brought up after distribution it becomes a scheduled outage and somebody explaining to a regional manager why the terminals are down.

We build the support path for a device with nobody at it

A display in a hallway, a terminal in a stockroom, a handheld on a charging rack. There is no one present to approve a remote session and no one who will complain when it stops working. Unattended access on Android dedicated devices, together with alerting for units that stop checking in, is what keeps these supportable without dispatching a vehicle.

We keep the configuration narrow deliberately

A dedicated device is valuable precisely because of what it refuses to do, so every additional application and every extra permitted link chips away at the point of it. The multi app benefit is described as clearing away the tools people do not need, and the discipline is holding that list to what the job genuinely requires and no more.

Where this matters most

Six US situations where dedicated devices are the right answer.

Digital signage, ticket printing and inventory management are named directly in the documentation, and those three categories run straight through American retail, logistics and healthcare.

Retail and hospitality terminals

Ordering screens, queue displays, ticket printers, customer-facing information panels and stock lookup units. Ticket printing and signage appear by name among the dedicated device use cases, and constraining the available applications and links is what stops a counter tablet turning into a general browser.

Warehouse and logistics handsets

Inventory management is another named use case, and it accounts for a large slice of the hardware in any distribution operation. A good deal of that equipment ships without Google Mobile Services, which places it on the Android Open Source Project route rather than the standard Android Enterprise one.

Reception, wayfinding and meeting room displays

Screens in public space showing one thing, reachable by anyone and supervised by no one. Single app kiosk mode holds the device to one browser on one site with no path to anything else, which is both the correct configuration and markedly safer than a general-purpose machine that happens to be displaying a page.

Shop floor and site terminals used across shifts

Hardware belonging to a role rather than a person, passing through several pairs of hands in a day. Multi app kiosk delivers exactly the applications that role needs and removes the rest from view, which cuts support load and shrinks the surface where things can go wrong at the same time.

Shared devices in education and training

Lab machines, library terminals, training room hardware and tablets held in a cart. The Android Open Source Project userless option is intended for shared equipment of precisely that kind, and having no user attached to the device is the property that makes managing it feasible at all.

A regulated environment with public-facing devices

Branch terminals, queue systems, self-service kiosks, check-in tablets in a clinic waiting room. What is required here is restriction you can demonstrate rather than restriction by convention, because a public-area machine running general software is a finding waiting to be written up. A kiosk profile that forecloses opening anything else is evidence, whether the reviewer works from HIPAA, GLBA or an insurance questionnaire.

Three positions

How single-purpose devices actually get managed.

The right-hand column shows up constantly: a tablet or terminal performing a job while running a general-purpose configuration, which anybody passing by can pick up and use for something else entirely.
Only the intended applications available
Properly dedicatedYes
Locked by conventionNo
A general device doing a jobNo
Users cannot open anything else
Properly dedicatedYes
Locked by conventionNo
A general device doing a jobNo
No personal account signed in
Properly dedicatedYes
Locked by conventionSometimes
A general device doing a jobOften there is one
Device enrolled in the right management state
Properly dedicatedYes
Locked by conventionPartly
A general device doing a jobRarely
Web browsing restricted to permitted links
Properly dedicatedYes
Locked by conventionNo
A general device doing a jobNo
Remote support without anybody present
Properly dedicatedOn Android dedicated
Locked by conventionNo
A general device doing a jobNo
Updates reach the device reliably
Properly dedicatedYes
Locked by conventionSometimes
A general device doing a jobRarely
Somebody notices when it stops reporting
Properly dedicatedYes
Locked by conventionNo
A general device doing a jobNo
Usable for something it was not intended for
Properly dedicatedNo
Locked by conventionYes
A general device doing a jobYes
How common this is in practice
Properly dedicatedUncommon
Locked by conventionCommon
A general device doing a jobVery common
Feature
Properly dedicated
Locked by convention
A general device doing a job
Only the intended applications available
YesNoNo
Users cannot open anything else
YesNoNo
No personal account signed in
YesSometimesOften there is one
Device enrolled in the right management state
YesPartlyRarely
Web browsing restricted to permitted links
YesNoNo
Remote support without anybody present
On Android dedicatedNoNo
Updates reach the device reliably
YesSometimesRarely
Somebody notices when it stops reporting
YesNoNo
Usable for something it was not intended for
NoYesYes
How common this is in practice
UncommonCommonVery common
By platform

Where each kiosk path lives, and what it suits.

Kiosk configuration exists for Windows, for Windows Holographic for Business, for Android in both device administrator and Android Enterprise forms, and for iOS and iPadOS. These are distinct configurations with distinct capabilities rather than one feature wearing four hats.

Platform

Windows, single app

What is available
One account pinned to a single browser or application, with no way to launch anything else

Platform

Windows, multi app

What is available
A named set of Store, Win32, browser and built-in applications, and nothing beyond it

Platform

Windows Holographic for Business

What is available
Kiosk settings of its own, for mixed reality hardware

Platform

Android Enterprise dedicated

What is available
Single-use and kiosk hardware, applications and links constrained, hardware wiped at enrollment

Platform

Android Enterprise, device experience

What is available
Kiosk configuration reached through the Android Enterprise device restriction settings

Platform

Android Open Source Project, userless

What is available
Shared hardware with no Google services and nobody assigned to it

Platform

iOS and iPadOS

What is available
Kiosk configuration reached through the Apple device restriction settings

Platform

Multiple kiosk profiles on one device

What is available
Not available directly. Custom settings are the documented alternative.
PlatformWhat is available
Windows, single appOne account pinned to a single browser or application, with no way to launch anything else
Windows, multi appA named set of Store, Win32, browser and built-in applications, and nothing beyond it
Windows Holographic for BusinessKiosk settings of its own, for mixed reality hardware
Android Enterprise dedicatedSingle-use and kiosk hardware, applications and links constrained, hardware wiped at enrollment
Android Enterprise, device experienceKiosk configuration reached through the Android Enterprise device restriction settings
Android Open Source Project, userlessShared hardware with no Google services and nobody assigned to it
iOS and iPadOSKiosk configuration reached through the Apple device restriction settings
Multiple kiosk profiles on one deviceNot available directly. Custom settings are the documented alternative.
How a deployment runs

Five steps, and the first one happens before procurement.

Two to four weeks covers a defined population. Building the configuration is quick work; the enrollment route and the physical logistics are what consume the calendar.
  1. 1

    Define the device role and the permitted set

    One application or several, whether a person signs in, precisely which applications and links are allowed, and whether the unit will ever need to do something else. Every later decision, platform and enrollment method included, follows from those answers.

  2. 2

    Choose the enrollment path, before the devices arrive

    Android Enterprise dedicated, the Android Open Source Project userless route for hardware without Google services, or a Windows kiosk profile. Because dedicated enrollment on Android wipes the device, this has to precede distribution or the project quietly acquires an erasure exercise nobody budgeted for.

  3. 3

    Build and test the kiosk configuration

    Single app or multi app on Windows, or the equivalent restrictions on Android or Apple hardware, proven on a real device doing the real job. These configurations fail loudly and specifically, almost always a missing application or a link the workflow depends on, and ten minutes of genuine use exposes both.

  4. 4

    Set up support for a device with nobody at it

    Unattended access wherever Android Enterprise dedicated enrollment makes it available, plus alerting for devices that stop reporting, because nobody opens a ticket about a hallway screen that went dark. This step decides whether the fleet is still working in month three.

  5. 5

    Deploy, and keep the permitted list short

    Rolled out by site or by role, with periodic review to confirm the approved application and link list has not quietly expanded. What a dedicated device cannot do is the entire value of it, and that value erodes one reasonable-sounding addition at a time.

Straight answers

What organizations ask about kiosk and shared devices.

Single app runs the machine under one account pinned to a single browser or application, launching it at sign-in with no route to opening anything new or switching what is running. Multi app presents a named set of Store applications, Win32 applications, browsers or built-in Windows applications, and nothing outside that list exists. One suits a screen doing a job; the other suits a person doing a role.

Not directly. A device carries one kiosk profile, and where several are genuinely required the documented route is custom settings. In day-to-day terms that means the unit does the job you configured it for, which is normally the outcome you want, and it occasionally becomes a discussion when somebody wants one tablet behaving differently in two parts of a building.

Kiosk configuration through a template covers Windows and Windows Holographic for Business, with separate paths for Android device administrator, for Android Enterprise through device experience settings, and for iOS and iPadOS through the Apple device restriction settings. Treat them as four distinct configurations with different capabilities rather than one feature applied four times.

It does. Dedicated device enrollment under Android Enterprise requires a factory reset according to the published table. Sealed hardware makes that a non-event, while hardware already deployed and running makes it genuinely disruptive, which is exactly why the decision belongs at procurement rather than after distribution. It is the most common avoidable problem in these projects.

Then you are on the Android Open Source Project route. Corporate-owned userless devices are described as built from AOSP without Google Mobile Services, carrying no associated user and intended for sharing in settings like a library or a lab. Rugged handsets, purpose-built terminals and a great deal of industrial equipment fall into this group, and it is a separate path rather than a variation.

Through unattended remote access, where the platform permits it. Remote Help connects a technician to an Android device without the person at the other end approving each session, and that capability requires the device to be enrolled as an Android Enterprise dedicated device. The requirement is not accidental: this population is defined by having nobody there to approve anything.

Check it against your own machines rather than assuming. The current guidance describes using Intune to configure a multi-app kiosk on Windows 10 devices and sends readers to separate documentation for setting one up on Windows 11. Since Windows 10 reached end of support on October 14, 2025, confirming this belongs in the design phase of any multi-app kiosk plan.

Yes, and it is the illustration Microsoft uses for single app kiosk mode: Edge running and showing a single site. That is the standard build for signage, wayfinding panels, queue displays and customer information terminals, and it forecloses launching another application or navigating away, neither of which a general machine displaying a page can claim.

For Android dedicated devices the use cases are named outright: digital signage, ticket printing and inventory management, described as company-owned single-use or kiosk hardware. Windows kiosk mode is framed around frontline workers. Between them that covers a great deal of retail, hospitality, logistics, healthcare and facilities equipment.

That is the entire purpose of the configuration. On Android dedicated hardware you constrain the available applications and web links and block use outside the intended scope. Under Windows multi app kiosk only the applications you added exist, with the benefit described as clearing away the tools people do not need. Everything else is unreachable rather than merely discouraged.

It has to be designed rather than assumed, and skipping it is the usual reason these fleets fall behind. With no user attached there is nobody to approve anything, which is exactly why unattended update mechanisms matter for this population, and why alerting on devices that have quietly stopped updating belongs in the design rather than in the postmortem.

A standard non-administrator account stops at fifteen, while a device enrollment manager account reaches a thousand. For kiosk work this matters more than usual, since these devices are typically staged centrally in batches by one person. Discovering the ceiling at device sixteen, halfway through preparing a shipment, is a specific and entirely avoidable frustration.

They do, and it is worth saying plainly, because locked software sitting on unsecured hardware is half a control. By definition this equipment lives in public areas, hallways, shop floors and reception desks. Mounts, cable locks and physical restraint belong in the deployment rather than in a separate conversation, and the management configuration is what caps the damage when a unit walks.

You have to decide that yourself, because nobody else will tell you. A hallway display that has gone dark generates no ticket, and a handheld left on a charging rack that stopped checking in generates none either. Alerting on devices that have not reported, owned by a named person, is the difference between a managed kiosk fleet and a collection of units somebody finds broken during a walkthrough.

Scoped per engagement, driven by how many device roles are in play, which platforms are involved, and whether hardware has already gone out, since that determines whether a factory reset is a plan or a problem. At no charge, the first conversation will tell you which enrollment path each population belongs on, because that decision carries the largest cost consequence.
Before deploying

Fifteen questions worth answering first.

The opening group fixes what the device is for. The second settles the enrollment route, which is where the wipe decision lives. The third deals with the day-to-day reality of hardware nobody personally owns.

The device role

  • Does this device do one thing or several?
    Single app and multi app are different modes.
  • Is anybody signed in as a person?
    A good many of these devices have no user at all.
  • Which applications and web links are permitted?
    Everything omitted should be unreachable.
  • Does the device need to behave differently by location?
    Remember the one-profile-per-device ceiling.
  • Is this a frontline worker scenario?
    That is the framing kiosk mode was built around.

The enrollment path

  • Which platform, and which enrollment method?
    What each permits varies substantially.
  • Are the devices already deployed?
    Android dedicated enrollment wipes the hardware.
  • Do the Android devices have Google services?
    Without them the AOSP userless route applies.
  • Are you on Windows 10 or Windows 11?
    It changes the multi-app kiosk picture.
  • Who will enroll them, and how many?
    Ordinary accounts stop at fifteen devices.

Running them

  • How do you support a device with nobody at it?
    Unattended access covers Android dedicated devices.
  • How do updates reach a device nobody logs into?
    Design this rather than hoping.
  • What happens if one is stolen or moved?
    Physical exposure comes with the territory.
  • Who notices when one stops checking in?
    A dark screen in a hallway files no ticket.
  • Is the device physically secured?
    Locked software on unlocked hardware is half a control.
Related reading

The pages around this one.

Android Enterprise management

A closer look at the enrollment methods, including the factory reset table and the zero-touch route for volume deployment.

Learn more

Device enrollment design

The enrollment decision across every platform, and which routes begin by erasing the machine.

Learn more

Microsoft Intune

The platform these configurations live inside, alongside compliance, application delivery and reporting.

Learn more
Next step

Settle the enrollment path before the hardware is distributed.

Dedicated enrollment on Android begins with a wipe, which costs nothing for boxed stock and becomes a real project for terminals already running on shop floors and sites. Half an hour spent on this during purchasing is the cheapest part of the entire deployment.

Book a shared device reviewSee Android Enterprise management

Related Services

Explore more solutions that work great with this service

Microsoft Intune

Device management and endpoint security

Learn more

Endpoint Security

Endpoint security for US businesses using Microsoft Defender for

Learn more

Managed IT Services

Complete outsourced IT department

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA