Skip to main content

Kiosk Profile

The Kiosk Profile payload for Windows allows IT administrators to lock down devices into either Single App Kiosk or Multi App Kiosk mode. Using NextGen kiosk capabilities built on Microsoft Assigned Access, administrators can easily restrict user access, control app execution, manage taskbar and Start menu layouts, and restrict File Explorer access.

To configure kiosk profile on the enrolled device(s), follow these steps:

  1. Navigate to SureMDM Web Console > Profiles > Windows > Add > Kiosk Profile > Configure.

  2. In the configuration window, select either Single App Kiosk or Multi App Kiosk.

  3. Enter a Profile Name.

  4. Configure Kiosk Profile settings and click Save.

Single App Kiosk Mode

Single App Kiosk mode restricts the device to running a single application in the foreground, automatically launching it when the target user logs in.

SettingsDescription
User Logon Type
Select the logon method used to enforce kiosk mode.
- Auto logon- Automatically signs in to the configured kiosk account.
- User Account - Uses an existing Windows user account to access the kiosk.

Auto Logon

When Auto logon is selected, configure the following settings:

SettingDescription
Kiosk Account Display NameSpecifies the display name of the account used for the kiosk session.
TypeSelect Application List or Custom App.
Application NameSelect the application to run from the available application list.
Shortcut/Breakout Sequence to Exit KioskSpecifies the keyboard shortcut that allows the user to exit the kiosk mode.

User Account

When User Account is selected, configure the following settings:

SettingDescription
Specify the UsernameEnter the account that will be used to access the kiosk.
TypeSelect Application List or Custom App.
Application Name / AUMIDSpecify the application that should run in kiosk mode.
Shortcut/Breakout Sequence to Exit KioskSpecify alternate keyboard shortcut or BreakoutSequence to exit Kiosk experience and reach login screen. Ctrl+Alt+Del is the default sequence of keys to exit the kiosk.
note
  • The Username field accepts a Local account, Domain account, or Microsoft Entra account. Use the following formats:
    • Local user: DeviceName\User, .\User, or User
    • Active Directory User: Domain\samAccountName (Example: contoso\user)
    • Microsoft Entra (fka AzureAD) User: AzureAD\user@contoso.onmicrosoft.com
  • Before deploying the profile, make sure the specified user account is available on the device, otherwise it fails. For local accounts, you can use the User Account Management job to create the required account.

Application Type

For Single App Mode, you can configure the application using either of the following options.

Application List

Select Application List to configure an application from the available application list.

Custom App

Use the application's AUMID to specify the application to launch.

note
  • For an optimal kiosk experience, use Standard User accounts in the profile configuration.
  • Don't use Users or Groups in the profile that are targeted by any conditional access policies that require user interaction. e.g. MFA or T&C acceptance.

Multiple App Mode

Multiple App Mode allows administrators to configure several applications that users can access while the device is operating in kiosk mode.

User Logon Type

Select how the kiosk user signs in:

OptionDescription
Auto logonAutomatically signs in to the configured kiosk account.
User AccountUses a specified Windows user account.
Apply to All Standard UsersApplies the kiosk configuration to all standard user accounts on the device.
User GroupApplies the kiosk configuration to users belonging to a specified user group.

When Auto logon is selected, specify the Kiosk Account Display Name.

note

The Group Name field accepts local groups, Active Directory groups, and Microsoft Entra groups. Use the following formats:

  • Local Group: Groupname
  • Active Directory Group: Domain\GroupName
    Example: contoso\KioskUsers
  • Microsoft Entra Group: Enter the Group Object ID (GUID).
    Example: 12345678-90ab-cdef-1234-567890abcdef

For Microsoft Entra groups, the device must have internet connectivity when users belonging to the group sign in.

Nested groups are not supported. For example, if User A is a member of Group A, Group A is a member of Group B, and Group B is specified in the profile, User A will not receive the kiosk experience when signing in.

Add Applications

Click Add to add applications to the kiosk.

The application list displays configured applications along with information such as their type, Start menu tile configuration, auto-launch status, and pinning settings.

You can Edit or Delete configured applications as required.


Add Application

When adding an application, select one of the following options.

Application List

Select Application List to configure an application that is available in the application list.

Depending on the application, configure the following settings:

SettingDescription
Package NameSelect the application package from the available applications.
AUMIDDisplays the Application User Model ID associated with the selected application, where applicable.
PathSpecifies the application path when required.
Start Menu Tile SizeSpecifies the size of the application's Start menu tile. This setting is available on Windows 10.
Pin to Start MenuAdds the application to the Start menu.
Pin to TaskbarPins the application to the Windows taskbar. This setting is available on Windows 11.
Shortcut PathSpecifies the shortcut path for the application.
Auto LaunchAutomatically launches the application when the kiosk session starts.
Auto Launch ArugumentsSpecify the Auto Lauch Arguments if any.

Custom App

Select Custom App to configure an application manually.

For a custom application, select the Application Type:

  • Store app
  • Win32 app

Depending on the selected application type, provide the required application details, including Application Name and AUMID.

You can also configure the following settings:

  • Start Menu Tile Size – Specifies the tile size on Windows 10.
  • Pin to Start Menu – Pins the application to the Start menu.
  • Pin to Taskbar – Pins the application to the taskbar on Windows 11.
note

If Pin to Taskbar is enabled for an application, ensure that Show Windows Taskbar is enabled under Taskbar Configuration.


Taskbar Configuration

The Taskbar Configuration section controls whether the Windows taskbar is available to kiosk users.

Show Windows Taskbar

Enable this option to display the Windows taskbar while the device is in kiosk mode.

This setting is particularly relevant when applications are configured with Pin to Taskbar.


File Explorer Restrictions

The File Explorer Restrictions section controls the locations that users can access through File Explorer while the device is in kiosk mode.

Select one of the following options:

  • Block All Access
  • Allow Access to Downloads Folder Only
  • Allow Access to Removable Drives Only
  • Allow Access to Downloads and Removable Drives
  • Allow All Locations Without Restrictions

This allows administrators to control access to local and removable storage based on the kiosk use case.


Start Layout Configuration

The Start Layout Configuration section allows administrators to apply an alternate Windows Start layout.

Use Alternative Start Layout

Enable this option to use a custom Start layout instead of the standard Start layout.

This setting is available for Windows 10.

When enabled, provide the Custom Start Menu Layout XML by either uploading the XML file or entering the XML content directly.

note

Configuring an alternate Start layout overrides app-specific Start layout settings configured earlier.

The newly created profile will be listed in the Profiles section.

  1. Go back to the Home tab and select the Windows device(s) or group(s).

  2. Click Apply to launch the Apply Job/Profile To Device prompt.

  3. Select the profile under All Jobs/Profiles.

  4. Click Apply in the Apply/Profile To Device prompt.

💬 Help us improve this documentation

Was this information useful?

Your feedback helps us keep our documentation accurate, up to date, and useful.