# Getting Started with Android Kiosk Management

**Android kiosk management** refers to the process of locking down a device to a specific environment, limiting it to a single application or a restricted set of apps. This ensures devices used for specific purposes; such as retail POS, digital signage, or education, remain secure and focused.

With Hexnode UEM, administrators can easily transform standard Android devices into dedicated kiosks.

Enrollment Prerequisites 
-------------------------

Before configuring **Android kiosk management** profiles, devices must be properly enrolled.

- [**Standard Enrollment**](https://www.hexnode.com/mobile-device-management/help/enroll-android-mobile-devices-hexnode-mdm/): Suitable for basic management.
- [**Android Enterprise**](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-organization-in-android-in-the-enterprise-using-hexnode-mdm/) **(Device Owner)**: Required for the most robust kiosk security. You must enroll your organization in the Android Enterprise program first.
- [**Custom ROM Enrollment**](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-android-devices-in-hexnode-mdm-by-configuring-rom/): Devices flash with a custom ROM are automatically enrolled upon first boot.

Kiosk Modes and Configuration 
------------------------------

Hexnode offers versatile kiosk modes depending on the use case.

### Single App Kiosk 

Locks the device to a [single application](https://www.hexnode.com/mobile-device-management/help/lock-android-devices-single-app-kiosk-mode/). The user cannot minimize the app or access the home screen.

- **Best for**: Self-service terminals, ticket machines.

### Multi-App Kiosk 

Allows access to a specific list of [“Allowlisted” apps](https://www.hexnode.com/mobile-device-management/help/enable-multi-app-kiosk-mode-android-devices/). Users can switch between these approved apps but cannot access unapproved software or device settings.

- **Best for**: Employee devices, logistics field tools.

### Digital Signage & Screensavers 

- **[Digital Signage](https://www.hexnode.com/mobile-device-management/help/how-to-lockdown-your-devices-onto-digital-signage-kiosk-using-hexnode/)**: Transforms the device into a media streaming tool, playing images or videos in a continuous loop.
- **[Kiosk Screensaver](https://www.hexnode.com/mobile-device-management/help/how-to-enable-screensaver-for-android-devices-locked-in-kiosk-mode/)**: Displays audio, video, or images when the device is idle.

Web Kiosk Settings 
-------------------

For devices intended to [browse the web](https://www.hexnode.com/mobile-device-management/help/how-to-set-up-a-website-kiosk-with-hexnode-mdm/), Hexnode allows you to block unapproved URLs and strictly allow [essential websites](https://www.hexnode.com/mobile-device-management/help/how-to-configure-advanced-web-kiosk-settings-with-hexnode-mdm/).

**Hexnode Browser Modes:**

- **Single Tab**: Opens one web app.
- **Multi-Tab**: Allows switching between allowlisted websites (Android 5.0+).
- **Web View**: Opens web apps in full screen with periodic refresh capabilities.

**External Browsers:**

You can also choose a third-party browser (e.g., Chrome) by installing it and adding it to the Kiosk allowlist.

App Management in Kiosk Mode 
-----------------------------

### Installing Apps 

You can push applications from various sources to a Kiosk device:

- [Store Apps](https://www.hexnode.com/mobile-device-management/help/install-android-app/) (Google Play)
- [Enterprise Apps](https://www.hexnode.com/mobile-device-management/help/distribute-android-enterprise-apps/) (APKs)
- [Web Apps](https://www.hexnode.com/mobile-device-management/help/how-to-add-web-app-as-kiosk-using-mdm/) (URLs)
- [Managed Google Apps](https://www.hexnode.com/mobile-device-management/help/how-to-approve-and-add-afw-apps-using-hexnode-mdm/)
- [Bundle IDs](https://www.hexnode.com/mobile-device-management/help/add-apps-using-bundle-id-in-android-kiosk-mode-using-hexnode-mdm/)

Silent Installation Support:

To install apps without user interaction (Silent Install), the device must be:

- [Samsung Knox ](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-for-samsung-knox-devices/)
- [LG GATE](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-for-lg-gate-devices/)
- [Kyocera Business Phone](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-for-kyocera-business-phones/)
- Rooted Android
- Android Enterprise (Device Owner)
- [Device with Hexnode UEM as a System App](https://www.hexnode.com/mobile-device-management/help/system-agent-app/)

### Updating Apps 

Hexnode allows you to [update apps](https://www.hexnode.com/mobile-device-management/help/how-to-update-enterprise-kiosk-app-for-android-devices-with-mdm/) **without exiting kiosk mode**.

- **Store/Enterprise Apps**: Deploy the new version via policy; the app updates in the background or upon restart depending on the configuration.
- **Hexnode UEM Agent**: The Hexnode UEM agent can be updated while the device remains locked.

### Background Apps (Hidden Apps) 

- **Function**: Allows an app to run in the background without showing an icon on the kiosk screen.
- **Use Case**: Critical for **dependency management**. If a Kiosk app requires a second app/package to function, that second app must be added as a “[Background App.](https://www.hexnode.com/mobile-device-management/help/how-to-hide-apps-in-android-kiosk-mode-with-mdm/)” If not, the device may show a “Blocked Package” error.

Exit Kiosk Mode 
----------------

Administrators can disable **Android kiosk management** to return the device to normal functionality. This is done via the “[Disable Kiosk Mode](https://www.hexnode.com/mobile-device-management/help/how-to-exit-android-kiosk-mode-in-hexnode-mdm/)” action in the Hexnode console.

Troubleshooting Android Kiosk Management 
-----------------------------------------

Common issues encountered during Android kiosk management and their solutions.

### 1: “Blocked Package” Error Message 

**Cause**: The active kiosk app is trying to call a background process or another app that is not in the allowlist.

**Solution**: Identify the dependent package name and add it to the Background Apps section of the Kiosk Lockdown policy.

### 2: Physical Buttons (Home/Back) still work 

**Cause**: The kiosk profile has not restricted hardware keys, or the device is not in “Device Owner” mode.

**Solution**: Ensure “Peripheral Settings” are configured to [disable hardware keys](https://www.hexnode.com/mobile-device-management/help/how-to-disable-hardware-buttons-on-android-devices-using-hexnode-mdm/).

### 3: Web Kiosk is showing an “Access Denied” error 

**Cause**: The URL being accessed attempts to redirect to a domain not on the allowlist.

**Solution**: Check the URL structure. If a login page redirects to an authentication server (e.g., sso.company.com), that redirect URL must also be allowlisted.