Set up Android single app kiosk with Remote Assist in HexnodeSolved

Participant
Discussion
3 weeks ago Sep 14, 2026

I’m setting up an Android tablet that should only run one time clock app. I also need remote access so an admin can help if the device gets stuck or needs changes later.

The tablet is being enrolled through Android Enterprise, and I’m planning to use single app kiosk mode. I’m not fully sure about the right order: enroll first, install the app, enable Remote Assist, then apply kiosk? Also, does the device need a Google account during enrollment?

Replies (5)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 14, 2026
Marked SolutionPending Review

Hi @ruthg_,

For this setup, the recommended approach is to enroll the tablet as an Android Enterprise Device Owner device, deploy the required apps, and then apply the single app kiosk policy.

A typical workflow would be:

  1. Factory reset the Android tablet if it is not already enrolled as Device Owner.
  2. Enroll the device in Hexnode using the Android Enterprise QR code enrollment method.
  3. Install the kiosk app either by:
    • Going to Manage > Devices > select the device > Actions > Applications > Install Application, or
    • Adding it under Policies > Android > App Management > Required Apps.
    • Install Hexnode Remote Assist if you need remote control access.
    • Grant the required Remote Assist permissions on the device so remote control works properly.
    • Create or edit a policy and go to Kiosk Lockdown > Android Kiosk Lockdown > Single App.
    • Add the time clock app as the single kiosk app.
    • Configure Kiosk Exit Settings and set an admin exit passcode.
    • Associate the policy with the tablet and save it.

Once the policy is applied, the device should be locked to the selected app. If Remote Assist is installed and permissions are granted before kiosk lockdown, admins can still use it for remote support.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
3 weeks ago Sep 14, 2026
Marked SolutionPending Review

One thing I ran into: after restarting the tablet, it came back into kiosk mode and I couldn’t find the normal Android navigation. How do admins manually exit kiosk if needed?

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 14, 2026
Marked SolutionPending Review

For Android kiosk mode in Hexnode, the manual exit method is to tap the screen 10 times consecutively and then enter the kiosk exit passcode configured in the policy.

You can configure or update this passcode from the kiosk policy under Kiosk Lockdown > Android Kiosk Lockdown > Kiosk Exit Settings. Make sure the passcode is saved in the policy before applying kiosk lockdown, especially if the device will be deployed remotely.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
3 weeks ago Sep 14, 2026
Marked SolutionPending Review

Do we need to add a Google account on the tablet during enrollment? I noticed some Android Enterprise enrollments create a work account automatically, but the device didn’t ask for Google credentials.

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 14, 2026
Marked SolutionPending Review

Google credentials are not always required during Android Enterprise Device Owner enrollment.

If Google Workspace integration is not configured in the Hexnode portal, enrollment will not enforce Google Workspace user authentication. In that case, the managed work account created during Android Enterprise enrollment can be left as is. Hexnode can still push policies and managed apps to the device.

If your requirement is to force users to authenticate with Google Workspace credentials during enrollment, configure Android Enterprise with Google Workspace integration in Hexnode first. Otherwise, QR code enrollment can proceed without entering Google credentials.

Regards,
Isabel Lora
Hexnode UEM

Save