To set up the Windows devices in kiosk mode, you
can use either a domain or a local account for the kiosk user. To set up the assigned access by
using the Windows MDM policy, you must have a user account
- a domain user account or a local user account. The user account must be logged in at least one
time before you can set up the assigned access otherwise the apps are disabled for that
account.
About this task
For the Windows MDM policy, select an app that you want
to set up in kiosk mode. To set up an assigned access by using the MDM, you must use the Universal
Windows Platform (UWP) app that runs on the Windows desktop or tablet devices on the lock
screen.
Note: Windows 11 supports only single-user mode. You do not need to enable the tablet mode.
To improve your kiosk experience, consider applying the optional configurations.
Procedure
- Place the device in tablet mode to allow users to use the touch (on-screen)
keyboard.
- Go to Settings.
- Click System and select Tablet
mode.
- Click On to place the device in tablet mode.
- Hide the Ease of Access feature on the logon screen.
- Go to the Control Panel.
- Click .
- Turn off all the accessibility tools.
- Disable the hardware power button.
- Go to Power Options.
- Click Choose what the power buttons do.
- Change the setting to Do nothing.
- Save your changes.
- Disable the camera.
- Go to Settings.
- Click Privacy and select
Camera.
- Disable Let apps use my camera.
- Prevent the policy from affecting administrator users on the device. Do one of the
following actions:
- Set the username for the kiosk user as a non-administrator (local user) on the
device.
Or,
- Go to the Group Policy Editor and click Computer
Configuration.
- Click Administrative Templates and select
System.
- Click Device Installation and select Device
Installation Restrictions.
- Click Allow administrators to override Device Installation Restriction
policies and select Enabled.
- Remove the power button/shut down options from the sign-in screen.
- Go to the Group Policy Editor and click Computer
Configuration.
- Click Windows Settings and select Security
Settings.
- Click Local Policies.
- Under Security Options, click Shutdown: Allow system
to be shut down without having to log on.
- Click Disabled to remove the power button from the
screen.
- Turn off the app notifications on the lock screen.
- Go to the Group Policy Editor and click Computer
Configuration.
- Click Administrative Templates and select
System.
- Click Logon and select Turn off app notifications on
the lock screen.
- Click Enabled to turn off the app notifications on the lock
screen.
- Disable removable media.
- Go to the Group Policy Editor and click Computer
Configuration.
- Click Administrative Templates and select
System.
- Click Device Installation and select Device
Installation Restrictions.
- Click Prevent installation of removable devices and select
Enabled.
- Review any additional policy settings in Device Installation
Restrictions that apply to your environment.