Get fresh insights, pro tips, and thought starters–only the best of posts for you.
Setting up kiosk mode in Windows 10 locks a device to a single app or a controlled set of apps, preventing users from reaching the desktop, settings, or unauthorized peripherals. It’s ideal for retail POS systems, digital signage, self-service terminals, and public-facing machines. You can configure a Windows 10 kiosk natively with the built-in Assigned Access feature, or manage it at scale with a Unified Endpoint Management (UEM) solution.
Before you begin, confirm your device meets these requirements:
Best for a quick, single-device test when setting up Windows 10 kiosk mode manually. It locks the machine to one Universal Windows Platform (UWP) app.
The limitation: Native Assigned Access is primarily intended for single-app kiosks using Edge or UWP apps. Advanced scenarios, including multi-app configurations and certain Win32 deployments, require Assigned Access XML or other methods. Shell Launcher is a separate feature available only on supported Enterprise, Education, and IoT Enterprise editions.
Native settings don’t support scale or legacy software. Hexnode UEM pushes a Windows 10 kiosk policy to hundreds of devices remotely, supports Win32 apps, and enables multi-app lockdown.
Hexnode lets you add supported Windows desktop apps, including MSI, Win32, and EXE apps, to a kiosk policy.
| Feature | Assigned Access | Hexnode UEM |
|---|---|---|
| Setup | Manual (device-by-device) | Remote bulk deployment |
| App Support | Mostly UWP/Store | UWP, Store & Win32 |
| Kiosk Type | Single app only | Single & multi-app |
| Peripheral Control | Limited | Windows restrictions |
Native tools handle basic single-app locking, but a UEM is essential for securely deploying multi-app kiosks and Win32 apps at enterprise scale.
No. Hexnode Windows kiosk mode requires a supported Windows 10 Pro, Enterprise, or Education edition. You must upgrade a device running Windows 10 Home to a supported Windows edition.
Not natively; Assigned Access needs physical sign-in. Use a UEM to deploy policies over-the-air.
For Hexnode-managed devices, disassociate or archive the kiosk policy and restart the device to remove kiosk mode. Pressing Ctrl + Alt + Del allows a different account to sign in, but the original kiosk account remains in kiosk mode.