# Getting started with Windows kiosk management

Windows kiosk management refers to the process of configuring Windows devices into a specific, restricted environment known as “Kiosk Mode.” Retail checkout terminals, hospital patient-intake stations, warehouse scanning stations, and shared front-desk PCs all face the same risk: a general-purpose Windows machine left unlocked invites accidental or deliberate misuse. Kiosk Mode removes that risk at fleet scale, without needing a technician to lock down each machine by hand.

By leveraging Hexnode UEM, administrators can transform standard PCs into dedicated purpose-built terminals. This configuration enhances security by limiting user interaction to only approved applications and settings, making it ideal for public-facing displays, digital signage, or task-specific workstations.

Prerequisites: Enrollment and App Setup 
----------------------------------------

To successfully deploy a Windows kiosk configuration, specific foundational steps must be completed.

- [**Device Enrollment**:](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-windows-laptops-in-hexnode-mdm/)
    - Devices must first be enrolled in the Hexnode UEM console.
    - **Supported OS**: Windows 10 and Windows 11.
- [**App Installation**](https://www.hexnode.com/mobile-device-management/help/how-to-install-apps-in-windows-devices-using-hexnode-mdm/): 
    - Before activating kiosk mode, the target applications must be installed on the device.
    - **App Sources**: Administrators can deploy Microsoft Store apps or Enterprise (in-house) apps via the UEM console prior to locking the device.

Single App Kiosk Mode 
----------------------

This [mode ](https://www.hexnode.com/mobile-device-management/help/how-to-lock-down-windows-devices-to-a-single-app-kiosk-mode/)is designed for devices that perform a solitary function, such as a self-check-in station or an interactive information board.

- **Definition**: Locks the **Windows kiosk** device to a single application.
- **Behavior**: The application launches automatically upon login. All other system functionalities, including the Start menu, taskbar, and desktop, are completely inaccessible.
- **Use Case**: Digital signage, ATM-style interfaces, and public web browsers.

Multi-App Kiosk Mode 
---------------------

This This [mode ](https://www.hexnode.com/mobile-device-management/help/how-to-lock-down-windows-devices-in-multi-app-kiosk-mode-using-hexnode/) offers a restricted yet flexible environment suitable for frontline workers or shared corporate devices.

- **Definition**: Restricts the Windows kiosk device to a curated list of essential applications.
- **Behavior**: Users can switch between the allowlisted apps via a simplified Start menu or tile interface. Access to non-approved apps, system settings, and the file explorer is blocked.
- **Use Case**: Shared workstations, inventory management tablets, and educational devices.

Exiting Kiosk Mode 
-------------------

Administrators maintain control over the device lifecycle and can disable the **Windows kiosk** environment when necessary.

- **Policy Removal**: Disassociating or archiving the Kiosk Lockdown Policy from the Hexnode console automatically reverts the device to its standard interface.
- **User Switching**: If configured, the device screen can be locked (**CTRL+ALT+DEL**), allowing a different user account to sign in to a non-restricted desktop session.

Troubleshooting Windows Kiosk Issues 
-------------------------------------

The following table addresses common errors encountered during **Windows kiosk** deployment and their respective resolutions.

Symptom / ErrorProbable CauseResolution StrategyBlack screen upon loginExplorer.exe shell conflict or app path error.**Check App Path**: For enterprise apps, ensure the file path (AUMID or executable path) provided in the policy is exact. Reboot the device remotely.Cannot exit Kiosk ModeNetwork disconnection prevents policy removal.**Network Check**: Ensure the device has internet access to receive the “Disassociate Policy” command. If offline, a local administrator login (if enabled) may be required.### Why lockdown validation happens centrally?

A misconfigured kiosk isn’t just a bug — it’s a customer-facing failure on a device the public interacts with directly. This is why lockdown validation happens centrally rather than per-device.