Kiosk Managementback-iconHow do I set up kiosk mode in windows 10?

How do I set up kiosk mode in windows 10?

Setting up kiosk mode in Windows 10 locks a device to a single app or a controlled set of apps, preventing users from reaching the desktop, settings, or unauthorized peripherals. It’s ideal for retail POS systems, digital signage, self-service terminals, and public-facing machines. You can configure a Windows 10 kiosk natively with the built-in Assigned Access feature, or manage it at scale with a Unified Endpoint Management (UEM) solution.

Prerequisites for Windows Kiosk Mode

Before you begin, confirm your device meets these requirements:

  • Windows Edition: Windows 10 Pro, Enterprise, or Education (Home is not supported).
  • User Account: A standard local user account for the kiosk profile.
  • User Account Control (UAC): Must be enabled for Assigned Access to work.
  • Login Method: Sign in physically; Remote Desktop does not support kiosk mode.

Method 1: Native “Assigned Access” (Manual)

Best for a quick, single-device test when setting up Windows 10 kiosk mode manually. It locks the machine to one Universal Windows Platform (UWP) app.

  1. Create a User: Go to Settings > Accounts > Other users and add a new local user.
  2. Access Settings: On the same page, click Set up a kiosk > Get started.
  3. Name the Kiosk: Enter a name for the kiosk account.
  4. Choose the App: Select a UWP app such as Edge or Calculator.
  5. Finish Setup: Close settings, restart, and log in as the kiosk user.

The limitation: Native Assigned Access is primarily intended for single-app kiosks using Edge or UWP apps. Advanced scenarios, including multi-app configurations and certain Win32 deployments, require Assigned Access XML or other methods. Shell Launcher is a separate feature available only on supported Enterprise, Education, and IoT Enterprise editions.

Method 2: Enterprise Kiosk Management with Hexnode

Native settings don’t support scale or legacy software. Hexnode UEM pushes a Windows 10 kiosk policy to hundreds of devices remotely, supports Win32 apps, and enables multi-app lockdown.

  1. Create the Policy: In the Hexnode UEM portal, create or edit a policy, then go to Kiosk Lockdown > Windows Kiosk Lockdown.
  2. Select Platform: Choose Windows.
  3. Choose Kiosk Type: Select Single App or Multi App mode. For Multi App, configure a custom or auto-generated Start menu layout.
  4. Add Applications: Add supported UWP, Store, or Windows desktop apps. To restrict the device to selected websites, configure a separate Windows Website Kiosk policy using Hexnode Kiosk Browser or Edge.
  5. Configure Auto-Launch: Optionally select an app to launch automatically after the kiosk user signs in.
  6. Associate Targets: Apply the policy to the required devices or groups, then restart the devices for the kiosk policy to take effect.

Hexnode lets you add supported Windows desktop apps, including MSI, Win32, and EXE apps, to a kiosk policy.

Assigned Access vs. Hexnode UEM

Feature Assigned Access Hexnode UEM
Setup Manual (device-by-device) Remote bulk deployment
App Support Mostly UWP/Store UWP, Store & Win32
Kiosk Type Single app only Single & multi-app
Peripheral Control Limited Windows restrictions

Key Takeaway

Native tools handle basic single-app locking, but a UEM is essential for securely deploying multi-app kiosks and Win32 apps at enterprise scale.

FAQ

No. Hexnode Windows kiosk mode requires a supported Windows 10 Pro, Enterprise, or Education edition. You must upgrade a device running Windows 10 Home to a supported Windows edition.

Not natively; Assigned Access needs physical sign-in. Use a UEM to deploy policies over-the-air.

For Hexnode-managed devices, disassociate or archive the kiosk policy and restart the device to remove kiosk mode. Pressing Ctrl + Alt + Del allows a different account to sign in, but the original kiosk account remains in kiosk mode.