Intune supports one kiosk profile per device. Design the device around its job, not the other way round.
Signage, ordering terminals, inventory handsets, ticket printers and shared floor devices all need locking to their purpose. Windows, Android and iOS each have a kiosk path, they behave differently, and the Android route requires a factory reset that has to be planned before devices are distributed.

- One profilePer device, unless you use custom settings
- Single or multi appThe Windows kiosk modes
- Factory resetRequired for Android dedicated enrolment
- Unattended supportAvailable on Android dedicated devices
Decide the device role before the devices arrive.
Shared and single-purpose devices are the population where a late decision is most expensive, because the correct enrolment path frequently requires wiping the device.
- Android Enterprise dedicated device enrolment requires a factory reset. Devices already distributed and in use have to be wiped to reach the right management state, which is straightforward for a stockroom of new handsets and awkward for two hundred terminals already running in stores.
- Intune supports one kiosk profile per device, so a device does the job you configured it for. Where a single device genuinely needs to behave differently in different contexts, that is a custom settings conversation rather than a second kiosk profile.
- On Windows, the single app and multi app modes are meaningfully different experiences, and Microsoft currently documents Intune multi-app kiosk configuration for Windows 10, pointing at separate documentation for Windows 11. With Windows 10 out of support since October 2025, that needs verifying against your estate rather than assumed.
- The reward for getting this right early is disproportionate. A properly dedicated device cannot be used for anything else, cannot wander off its purpose, needs no user account management, and on Android can be supported remotely without anybody present to accept a connection.
Eight things about kiosk and shared devices that shape the design.
Single app kiosk, which is genuinely locked
The device runs as a single user account and is locked to a single web browser or application, so a specific application starts when the user signs in, and the mode restricts users from opening new applications or changing the running one. Microsoft gives the example of running Edge showing only one site. This is the mode for signage, a wayfinding screen or a single-purpose terminal.
Multi app kiosk, for a role rather than a task
The device runs multiple Store applications, Win32 applications, web browsers or built-in Windows applications, with only the applications you add being available. Microsoft describes the benefit as an easy to understand experience where users access only the applications they need and the ones they do not need are removed from view, which is exactly right for a shift-based role.
The Windows 11 multi-app caveat, which affects planning
Microsoft states that currently you can use Intune to configure a multi-app kiosk on Windows 10 devices, directing readers to separate documentation for Windows 11 multi-app kiosk support. Given Windows 10 reached end of support on 14 October 2025, any multi-app kiosk plan on Windows needs that checked against your current position rather than assumed.
One kiosk profile per device
Microsoft states Intune supports one kiosk profile per device, and that if you need multiple kiosk profiles on a single device you can use custom settings instead. That constraint is usually fine and it does mean a device cannot be two things, which occasionally surfaces where somebody wants the same tablet to behave differently in different areas of a building.
Android dedicated devices, and what they are for
Microsoft describes enrolling corporate-owned single use or kiosk devices for things like digital signage, ticket printing and inventory management, limiting the applications and web links available and preventing people using the device outside its intended scope. In this market that covers a large share of retail, hospitality, logistics and facilities equipment.
The Android factory reset, which has to be planned
Android Enterprise dedicated device enrolment requires a factory reset, per Microsoft published table. That is fine for devices still in boxes and a real problem for devices already deployed and in use. It is the single planning fact that most often determines whether an Android kiosk project is straightforward or painful, and it belongs at procurement.
Unattended remote support, on exactly this population
Remote Help allows helpers to connect to Android devices without the user accepting the connection each time, and Microsoft states this requires the device to be enrolled as an Android Enterprise dedicated device. That is not a coincidence: these are precisely the devices with nobody sitting in front of them to accept anything, and it turns a site visit into a remote fix.
Devices with no Google services have their own route
For corporate-owned devices built from the Android Open Source Project without Google Mobile Services, there is a userless enrolment option with no associated user, which Microsoft describes as intended to be shared, like in a library or lab. Rugged and purpose-built hardware frequently falls here, and it is a different enrolment path rather than a variation of the same one.
Four things that make a dedicated device actually dedicated.
We define the device role before choosing a platform or a mode
One application or several, a signed-in person or nobody, which web links are permitted, and whether the device ever needs to be something else. Those answers determine single app against multi app, dedicated against fully managed, and whether the standard route or a custom configuration is needed. Choosing the mode first and fitting the job to it is how these deployments end up compromised.
We raise the factory reset before devices are ordered
Android Enterprise dedicated enrolment requires a wipe, which is trivial for devices in boxes and painful for devices already running in stores, sites or clinics. Raising it at procurement is a five minute conversation. Raising it after distribution is a project with a rollout window and somebody explaining why the terminals will be down.
We build the support path for a device with nobody at it
Signage in a corridor, a terminal in a stockroom, a handset on a charging rack. Nobody is present to accept a remote session, and nobody complains when it stops working. Unattended remote access on Android dedicated devices, plus monitoring for devices that stop checking in, is what makes these supportable without a vehicle.
We keep the configuration narrow deliberately
The value of a dedicated device is that it cannot be used for anything else, which means every application added and every web link permitted reduces it. Microsoft frames the multi app benefit as removing the applications users do not need from view, and the discipline is to keep that list as short as the job genuinely requires.
Six UAE situations where dedicated devices are the right answer.
Retail and hospitality terminals
Ordering screens, queue management, ticket printing, customer-facing displays and stock lookup devices. Microsoft names ticket printing and digital signage as dedicated device use cases specifically, and locking the applications and web links available is what stops a customer-facing tablet becoming a general browser.
Warehouse and logistics handsets
Inventory management is another use case Microsoft names, and it describes a large part of the device estate in this market. These are frequently rugged devices without Google Mobile Services, which puts them on the Android Open Source Project route rather than the standard Android Enterprise path.
Reception, wayfinding and meeting room displays
Screens in public areas showing one thing, which anybody can reach and nobody supervises. Single app kiosk mode locks the device to one browser showing one site with no way to open anything else, which is both the correct configuration and considerably safer than a general device that happens to be showing a page.
Shop floor and site terminals used across shifts
Where a role rather than a person needs a device, and different people use it through the day. Multi app kiosk gives them exactly the applications the job requires and removes everything else from view, which reduces both support load and the surface area for anything going wrong.
Shared devices in education and training
Laboratory machines, library terminals, training room devices and shared tablets. Microsoft describes the Android Open Source Project userless option as intended for shared devices like those in a library or lab, and the absence of an associated user is the property that makes them manageable at all.
A regulated environment with public-facing devices
Branch terminals, queue systems, self-service kiosks. Here the requirement is provable restriction rather than convention, because a device in a public area running general software is a finding waiting to be made. A kiosk profile that prevents opening anything else is evidence rather than an assurance.
How single-purpose devices are actually managed here.
| Feature | Properly dedicated | Locked by convention | A general device doing a job |
|---|---|---|---|
Only the intended applications available | Yes | No | No |
Users cannot open anything else | Yes | No | No |
No personal account signed in | Yes | Sometimes | Often there is one |
Device enrolled in the right management state | Yes | Partly | Rarely |
Web browsing restricted to permitted links | Yes | No | No |
Remote support without anybody present | On Android dedicated | No | No |
Updates reach the device reliably | Yes | Sometimes | Rarely |
Somebody notices when it stops reporting | Yes | No | No |
Usable for something it was not intended for | No | Yes | Yes |
Frequency in the UAE market | Uncommon | Common | Very common |
Where each kiosk path lives, and what it suits.
| Platform | What is available | |
|---|---|---|
| Windows, single app | Single user account locked to one browser or application, no other applications openable | |
| Windows, multi app | A defined set of Store, Win32, browser and built-in applications, and nothing else | |
| Windows Holographic for Business | Its own kiosk settings, for mixed reality devices | |
| Android Enterprise dedicated | Single use and kiosk devices, applications and web links limited, factory reset required | |
| Android Enterprise, device experience | Kiosk configuration through the Android Enterprise device restriction settings | |
| Android Open Source Project, userless | Shared devices with no Google services and no associated user | |
| iOS and iPadOS | Kiosk configuration through the Apple device restriction settings | |
| Multiple kiosk profiles on one device | Not supported directly. Custom settings are the documented route. |
Five steps, and the first one happens before procurement.
- 1
Define the device role and the permitted set
One application or several, whether anybody is signed in, exactly which applications and web links are permitted, and whether the device ever needs to do anything else. Everything after this follows from those answers, including which platform and enrolment method is correct.
- 2
Choose the enrolment path, before the devices arrive
Android Enterprise dedicated, the Android Open Source Project userless route for devices without Google services, or a Windows kiosk profile. Android dedicated enrolment requires a factory reset, so this decision has to precede distribution or the project acquires a wipe exercise it did not plan for.
- 3
Build and test the kiosk configuration
Single app or multi app on Windows, or the equivalent restrictions on Android or iOS, tested on a real device doing the real job. Kiosk configurations fail in specific and visible ways, usually a missing application or a web link the workflow needs, and those surface in ten minutes of real use.
- 4
Set up support for a device with nobody at it
Unattended remote access where Android Enterprise dedicated enrolment makes it available, and monitoring for devices that stop checking in, because nobody raises a ticket about a screen in a corridor that has gone blank. This is the step that determines whether the estate stays working after month three.
- 5
Deploy, and keep the permitted list short
Rolled out by location or by role, with the configuration reviewed periodically to make sure the permitted application and link list has not quietly grown. The whole value of a dedicated device is what it cannot do, and that erodes one reasonable-sounding addition at a time.
What organisations ask about kiosk and shared devices.
Fifteen questions worth answering first.
The device role
- Does this device do one thing or several?Single app and multi app are different modes.
- Is anybody signed in as a person?Some of these devices have no user at all.
- Which applications and web links are permitted?Everything else should be unreachable.
- Does the device need to behave differently by location?One kiosk profile per device applies.
- Is this a frontline worker scenario?Microsoft frames kiosk mode around exactly that.
The enrolment path
- Which platform, and which enrolment method?They differ substantially in what they allow.
- Are the devices already deployed?Android dedicated enrolment requires a factory reset.
- Do the Android devices have Google services?If not, the AOSP userless route applies.
- Are you on Windows 10 or Windows 11?Relevant to multi-app kiosk configuration.
- Who will enrol them, and how many?Standard accounts are capped at fifteen devices.
Running them
- How do you support a device with nobody at it?Unattended remote access covers Android dedicated devices.
- How do updates reach a device nobody logs into?Worth designing rather than hoping.
- What happens if one is stolen or moved?These devices are physically exposed by nature.
- Who notices when one stops checking in?Nobody complains about a screen in a corridor.
- Is the device physically secured?A locked configuration on an unlocked device is half a control.
The pages around this one.
Android Enterprise management
The enrolment methods in detail, including the factory reset table and the zero-touch route for bulk deployment.
Intune Remote Help
Unattended remote access, which is available specifically on Android Enterprise dedicated devices.
Microsoft Intune
The platform these configurations live in, alongside compliance, application deployment and reporting.
Decide the enrolment path before the devices are distributed.
Android dedicated enrolment requires a factory reset, which is trivial for devices in boxes and a real project for devices already running in stores or on sites. Half an hour on this at procurement is the cheapest part of the whole deployment.
Related Services
Explore more solutions that work great with this service
Android Enterprise
Choose the enrolment method before you buy the phones
Intune Remote Help
Remote support scoped by role, with both parties authenticated
Microsoft Intune
Device management and endpoint security
MDM Solutions Dubai
Device management across Windows, Apple and Android
Intune Suite
Eight advanced capabilities, and one trial each per tenant
Intune Compliance Policies
The default that lets unassessed devices through Conditional Access
Endpoint Security
Defender for Endpoint and Intune managed
IT Support Dubai
24/7 on-site and remote IT support