Kiosk Profile
The Kiosk Profile payload for Windows allows IT administrators to lock down devices into either Single App Kiosk or Multi App Kiosk mode. Using NextGen kiosk capabilities built on Microsoft Assigned Access, administrators can easily restrict user access, control app execution, manage taskbar and Start menu layouts, and restrict File Explorer access.
To configure kiosk profile on the enrolled device(s), follow these steps:
Navigate to SureMDM Web Console > Profiles > Windows > Add > Kiosk Profile > Configure.
In the configuration window, select either Single App Kiosk or Multi App Kiosk.
Enter a Profile Name.
Configure Kiosk Profile settings and click Save.
Single App Kiosk Mode
Single App Kiosk mode restricts the device to running a single application in the foreground, automatically launching it when the target user logs in.
| Settings | Description |
|---|---|
| User Logon Type | Select the logon method used to enforce kiosk mode. - Auto logon- Automatically signs in to the configured kiosk account. - User Account - Uses an existing Windows user account to access the kiosk. |
Auto Logon
When Auto logon is selected, configure the following settings:
| Setting | Description |
|---|---|
| Kiosk Account Display Name | Specifies the display name of the account used for the kiosk session. |
| Type | Select Application List or Custom App. |
| Application Name | Select the application to run from the available application list. |
| Shortcut/Breakout Sequence to Exit Kiosk | Specifies the keyboard shortcut that allows the user to exit the kiosk mode. |
User Account
When User Account is selected, configure the following settings:
| Setting | Description |
|---|---|
| Specify the Username | Enter the account that will be used to access the kiosk. |
| Type | Select Application List or Custom App. |
| Application Name / AUMID | Specify the application that should run in kiosk mode. |
| Shortcut/Breakout Sequence to Exit Kiosk | Specify alternate keyboard shortcut or BreakoutSequence to exit Kiosk experience and reach login screen. Ctrl+Alt+Del is the default sequence of keys to exit the kiosk. |
- The Username field accepts a Local account, Domain account, or Microsoft Entra account. Use the following formats:
- Local user: DeviceName\User, .\User, or User
- Active Directory User: Domain\samAccountName (Example: contoso\user)
- Microsoft Entra (fka AzureAD) User: AzureAD\user@contoso.onmicrosoft.com
- Before deploying the profile, make sure the specified user account is available on the device, otherwise it fails. For local accounts, you can use the User Account Management job to create the required account.
Application Type
For Single App Mode, you can configure the application using either of the following options.
Application List
Select Application List to configure an application from the available application list.
Custom App
Use the application's AUMID to specify the application to launch.
- For an optimal kiosk experience, use Standard User accounts in the profile configuration.
- Don't use Users or Groups in the profile that are targeted by any conditional access policies that require user interaction. e.g. MFA or T&C acceptance.
Multiple App Mode
Multiple App Mode allows administrators to configure several applications that users can access while the device is operating in kiosk mode.
User Logon Type
Select how the kiosk user signs in:
| Option | Description |
|---|---|
| Auto logon | Automatically signs in to the configured kiosk account. |
| User Account | Uses a specified Windows user account. |
| Apply to All Standard Users | Applies the kiosk configuration to all standard user accounts on the device. |
| User Group | Applies the kiosk configuration to users belonging to a specified user group. |
When Auto logon is selected, specify the Kiosk Account Display Name.
The Group Name field accepts local groups, Active Directory groups, and Microsoft Entra groups. Use the following formats:
- Local Group:
Groupname - Active Directory Group:
Domain\GroupName
Example:contoso\KioskUsers - Microsoft Entra Group: Enter the Group Object ID (GUID).
Example:12345678-90ab-cdef-1234-567890abcdef
For Microsoft Entra groups, the device must have internet connectivity when users belonging to the group sign in.
Nested groups are not supported. For example, if User A is a member of Group A, Group A is a member of Group B, and Group B is specified in the profile, User A will not receive the kiosk experience when signing in.
Add Applications
Click Add to add applications to the kiosk.
The application list displays configured applications along with information such as their type, Start menu tile configuration, auto-launch status, and pinning settings.
You can Edit or Delete configured applications as required.
Add Application
When adding an application, select one of the following options.
Application List
Select Application List to configure an application that is available in the application list.
Depending on the application, configure the following settings:
| Setting | Description |
|---|---|
| Package Name | Select the application package from the available applications. |
| AUMID | Displays the Application User Model ID associated with the selected application, where applicable. |
| Path | Specifies the application path when required. |
| Start Menu Tile Size | Specifies the size of the application's Start menu tile. This setting is available on Windows 10. |
| Pin to Start Menu | Adds the application to the Start menu. |
| Pin to Taskbar | Pins the application to the Windows taskbar. This setting is available on Windows 11. |
| Shortcut Path | Specifies the shortcut path for the application. |
| Auto Launch | Automatically launches the application when the kiosk session starts. |
| Auto Launch Aruguments | Specify the Auto Lauch Arguments if any. |
Custom App
Select Custom App to configure an application manually.
For a custom application, select the Application Type:
- Store app
- Win32 app
Depending on the selected application type, provide the required application details, including Application Name and AUMID.
You can also configure the following settings:
- Start Menu Tile Size – Specifies the tile size on Windows 10.
- Pin to Start Menu – Pins the application to the Start menu.
- Pin to Taskbar – Pins the application to the taskbar on Windows 11.
If Pin to Taskbar is enabled for an application, ensure that Show Windows Taskbar is enabled under Taskbar Configuration.
Taskbar Configuration
The Taskbar Configuration section controls whether the Windows taskbar is available to kiosk users.
Show Windows Taskbar
Enable this option to display the Windows taskbar while the device is in kiosk mode.
This setting is particularly relevant when applications are configured with Pin to Taskbar.
File Explorer Restrictions
The File Explorer Restrictions section controls the locations that users can access through File Explorer while the device is in kiosk mode.
Select one of the following options:
- Block All Access
- Allow Access to Downloads Folder Only
- Allow Access to Removable Drives Only
- Allow Access to Downloads and Removable Drives
- Allow All Locations Without Restrictions
This allows administrators to control access to local and removable storage based on the kiosk use case.
Start Layout Configuration
The Start Layout Configuration section allows administrators to apply an alternate Windows Start layout.
Use Alternative Start Layout
Enable this option to use a custom Start layout instead of the standard Start layout.
This setting is available for Windows 10.
When enabled, provide the Custom Start Menu Layout XML by either uploading the XML file or entering the XML content directly.
Configuring an alternate Start layout overrides app-specific Start layout settings configured earlier.
The newly created profile will be listed in the Profiles section.
Go back to the Home tab and select the Windows device(s) or group(s).
Click Apply to launch the Apply Job/Profile To Device prompt.
Select the profile under All Jobs/Profiles.
Click Apply in the Apply/Profile To Device prompt.