We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Intune
  2. Kiosk and shared devices
Kiosk and shared devices, UAE

Intune supports one kiosk profile per device. Design the device around its job, not the other way round.

Signage, ordering terminals, inventory handsets, ticket printers and shared floor devices all need locking to their purpose. Windows, Android and iOS each have a kiosk path, they behave differently, and the Android route requires a factory reset that has to be planned before devices are distributed.

Book a shared device reviewSee the platform options
Kiosk and shared device management for UAE organisations
  • One profilePer device, unless you use custom settings
  • Single or multi appThe Windows kiosk modes
  • Factory resetRequired for Android dedicated enrolment
  • Unattended supportAvailable on Android dedicated devices
The sequencing that decides the cost

Decide the device role before the devices arrive.

Shared and single-purpose devices are the population where a late decision is most expensive, because the correct enrolment path frequently requires wiping the device.

  • Android Enterprise dedicated device enrolment requires a factory reset. Devices already distributed and in use have to be wiped to reach the right management state, which is straightforward for a stockroom of new handsets and awkward for two hundred terminals already running in stores.
  • Intune supports one kiosk profile per device, so a device does the job you configured it for. Where a single device genuinely needs to behave differently in different contexts, that is a custom settings conversation rather than a second kiosk profile.
  • On Windows, the single app and multi app modes are meaningfully different experiences, and Microsoft currently documents Intune multi-app kiosk configuration for Windows 10, pointing at separate documentation for Windows 11. With Windows 10 out of support since October 2025, that needs verifying against your estate rather than assumed.
  • The reward for getting this right early is disproportionate. A properly dedicated device cannot be used for anything else, cannot wander off its purpose, needs no user account management, and on Android can be supported remotely without anybody present to accept a connection.
Ask us to scope the device roles before you buy
How it works

Eight things about kiosk and shared devices that shape the design.

Microsoft describes running a Windows device as a kiosk, sometimes known as a dedicated device, able to run one application or many, with a customisable start menu, added applications including Win32 applications, and a specified browser home page. Microsoft frames the scenario as common for frontline workers.

Single app kiosk, which is genuinely locked

The device runs as a single user account and is locked to a single web browser or application, so a specific application starts when the user signs in, and the mode restricts users from opening new applications or changing the running one. Microsoft gives the example of running Edge showing only one site. This is the mode for signage, a wayfinding screen or a single-purpose terminal.

Multi app kiosk, for a role rather than a task

The device runs multiple Store applications, Win32 applications, web browsers or built-in Windows applications, with only the applications you add being available. Microsoft describes the benefit as an easy to understand experience where users access only the applications they need and the ones they do not need are removed from view, which is exactly right for a shift-based role.

The Windows 11 multi-app caveat, which affects planning

Microsoft states that currently you can use Intune to configure a multi-app kiosk on Windows 10 devices, directing readers to separate documentation for Windows 11 multi-app kiosk support. Given Windows 10 reached end of support on 14 October 2025, any multi-app kiosk plan on Windows needs that checked against your current position rather than assumed.

One kiosk profile per device

Microsoft states Intune supports one kiosk profile per device, and that if you need multiple kiosk profiles on a single device you can use custom settings instead. That constraint is usually fine and it does mean a device cannot be two things, which occasionally surfaces where somebody wants the same tablet to behave differently in different areas of a building.

Android dedicated devices, and what they are for

Microsoft describes enrolling corporate-owned single use or kiosk devices for things like digital signage, ticket printing and inventory management, limiting the applications and web links available and preventing people using the device outside its intended scope. In this market that covers a large share of retail, hospitality, logistics and facilities equipment.

The Android factory reset, which has to be planned

Android Enterprise dedicated device enrolment requires a factory reset, per Microsoft published table. That is fine for devices still in boxes and a real problem for devices already deployed and in use. It is the single planning fact that most often determines whether an Android kiosk project is straightforward or painful, and it belongs at procurement.

Unattended remote support, on exactly this population

Remote Help allows helpers to connect to Android devices without the user accepting the connection each time, and Microsoft states this requires the device to be enrolled as an Android Enterprise dedicated device. That is not a coincidence: these are precisely the devices with nobody sitting in front of them to accept anything, and it turns a site visit into a remote fix.

Devices with no Google services have their own route

For corporate-owned devices built from the Android Open Source Project without Google Mobile Services, there is a userless enrolment option with no associated user, which Microsoft describes as intended to be shared, like in a library or lab. Rugged and purpose-built hardware frequently falls here, and it is a different enrolment path rather than a variation of the same one.

How we approach it

Four things that make a dedicated device actually dedicated.

These devices are the least glamorous part of an estate and frequently the most exposed, because they sit in public areas doing a job nobody reviews.

We define the device role before choosing a platform or a mode

One application or several, a signed-in person or nobody, which web links are permitted, and whether the device ever needs to be something else. Those answers determine single app against multi app, dedicated against fully managed, and whether the standard route or a custom configuration is needed. Choosing the mode first and fitting the job to it is how these deployments end up compromised.

We raise the factory reset before devices are ordered

Android Enterprise dedicated enrolment requires a wipe, which is trivial for devices in boxes and painful for devices already running in stores, sites or clinics. Raising it at procurement is a five minute conversation. Raising it after distribution is a project with a rollout window and somebody explaining why the terminals will be down.

We build the support path for a device with nobody at it

Signage in a corridor, a terminal in a stockroom, a handset on a charging rack. Nobody is present to accept a remote session, and nobody complains when it stops working. Unattended remote access on Android dedicated devices, plus monitoring for devices that stop checking in, is what makes these supportable without a vehicle.

We keep the configuration narrow deliberately

The value of a dedicated device is that it cannot be used for anything else, which means every application added and every web link permitted reduces it. Microsoft frames the multi app benefit as removing the applications users do not need from view, and the discipline is to keep that list as short as the job genuinely requires.

Where this matters most

Six UAE situations where dedicated devices are the right answer.

Microsoft names digital signage, ticket printing and inventory management directly, and in this market those categories are unusually large.

Retail and hospitality terminals

Ordering screens, queue management, ticket printing, customer-facing displays and stock lookup devices. Microsoft names ticket printing and digital signage as dedicated device use cases specifically, and locking the applications and web links available is what stops a customer-facing tablet becoming a general browser.

Warehouse and logistics handsets

Inventory management is another use case Microsoft names, and it describes a large part of the device estate in this market. These are frequently rugged devices without Google Mobile Services, which puts them on the Android Open Source Project route rather than the standard Android Enterprise path.

Reception, wayfinding and meeting room displays

Screens in public areas showing one thing, which anybody can reach and nobody supervises. Single app kiosk mode locks the device to one browser showing one site with no way to open anything else, which is both the correct configuration and considerably safer than a general device that happens to be showing a page.

Shop floor and site terminals used across shifts

Where a role rather than a person needs a device, and different people use it through the day. Multi app kiosk gives them exactly the applications the job requires and removes everything else from view, which reduces both support load and the surface area for anything going wrong.

Shared devices in education and training

Laboratory machines, library terminals, training room devices and shared tablets. Microsoft describes the Android Open Source Project userless option as intended for shared devices like those in a library or lab, and the absence of an associated user is the property that makes them manageable at all.

A regulated environment with public-facing devices

Branch terminals, queue systems, self-service kiosks. Here the requirement is provable restriction rather than convention, because a device in a public area running general software is a finding waiting to be made. A kiosk profile that prevents opening anything else is evidence rather than an assurance.

Three positions

How single-purpose devices are actually managed here.

The right column is very common: a tablet or terminal doing a job, in general-purpose configuration, that anybody can walk up to and use for something else entirely.
Only the intended applications available
Properly dedicatedYes
Locked by conventionNo
A general device doing a jobNo
Users cannot open anything else
Properly dedicatedYes
Locked by conventionNo
A general device doing a jobNo
No personal account signed in
Properly dedicatedYes
Locked by conventionSometimes
A general device doing a jobOften there is one
Device enrolled in the right management state
Properly dedicatedYes
Locked by conventionPartly
A general device doing a jobRarely
Web browsing restricted to permitted links
Properly dedicatedYes
Locked by conventionNo
A general device doing a jobNo
Remote support without anybody present
Properly dedicatedOn Android dedicated
Locked by conventionNo
A general device doing a jobNo
Updates reach the device reliably
Properly dedicatedYes
Locked by conventionSometimes
A general device doing a jobRarely
Somebody notices when it stops reporting
Properly dedicatedYes
Locked by conventionNo
A general device doing a jobNo
Usable for something it was not intended for
Properly dedicatedNo
Locked by conventionYes
A general device doing a jobYes
Frequency in the UAE market
Properly dedicatedUncommon
Locked by conventionCommon
A general device doing a jobVery common
Feature
Properly dedicated
Locked by convention
A general device doing a job
Only the intended applications available
YesNoNo
Users cannot open anything else
YesNoNo
No personal account signed in
YesSometimesOften there is one
Device enrolled in the right management state
YesPartlyRarely
Web browsing restricted to permitted links
YesNoNo
Remote support without anybody present
On Android dedicatedNoNo
Updates reach the device reliably
YesSometimesRarely
Somebody notices when it stops reporting
YesNoNo
Usable for something it was not intended for
NoYesYes
Frequency in the UAE market
UncommonCommonVery common
By platform

Where each kiosk path lives, and what it suits.

Microsoft provides kiosk configuration across Windows, Windows Holographic for Business, Android in both device administrator and Android Enterprise forms, and iOS or iPadOS. They are separate configurations with different capabilities.
PlatformWhat is available
Windows, single appSingle user account locked to one browser or application, no other applications openable
Windows, multi appA defined set of Store, Win32, browser and built-in applications, and nothing else
Windows Holographic for BusinessIts own kiosk settings, for mixed reality devices
Android Enterprise dedicatedSingle use and kiosk devices, applications and web links limited, factory reset required
Android Enterprise, device experienceKiosk configuration through the Android Enterprise device restriction settings
Android Open Source Project, userlessShared devices with no Google services and no associated user
iOS and iPadOSKiosk configuration through the Apple device restriction settings
Multiple kiosk profiles on one deviceNot supported directly. Custom settings are the documented route.
How a deployment runs

Five steps, and the first one happens before procurement.

Typically two to four weeks for a defined population. The configuration is quick. The enrolment path and the physical logistics are what take the time.
  1. 1

    Define the device role and the permitted set

    One application or several, whether anybody is signed in, exactly which applications and web links are permitted, and whether the device ever needs to do anything else. Everything after this follows from those answers, including which platform and enrolment method is correct.

  2. 2

    Choose the enrolment path, before the devices arrive

    Android Enterprise dedicated, the Android Open Source Project userless route for devices without Google services, or a Windows kiosk profile. Android dedicated enrolment requires a factory reset, so this decision has to precede distribution or the project acquires a wipe exercise it did not plan for.

  3. 3

    Build and test the kiosk configuration

    Single app or multi app on Windows, or the equivalent restrictions on Android or iOS, tested on a real device doing the real job. Kiosk configurations fail in specific and visible ways, usually a missing application or a web link the workflow needs, and those surface in ten minutes of real use.

  4. 4

    Set up support for a device with nobody at it

    Unattended remote access where Android Enterprise dedicated enrolment makes it available, and monitoring for devices that stop checking in, because nobody raises a ticket about a screen in a corridor that has gone blank. This is the step that determines whether the estate stays working after month three.

  5. 5

    Deploy, and keep the permitted list short

    Rolled out by location or by role, with the configuration reviewed periodically to make sure the permitted application and link list has not quietly grown. The whole value of a dedicated device is what it cannot do, and that erodes one reasonable-sounding addition at a time.

Straight answers

What organisations ask about kiosk and shared devices.

Single app runs the device as a single user account locked to one web browser or application, so a specific application starts at sign-in and users cannot open new applications or change the running one. Multi app runs a defined set of Store applications, Win32 applications, browsers or built-in Windows applications, with only the applications you add available. One is for a screen doing a job, the other for a person doing a role.

Not directly. Microsoft states that Intune supports one kiosk profile per device, and that if you need multiple kiosk profiles on a single device you can use custom settings. In practice this means a device does the job you configured it for, which is usually the correct outcome and occasionally surfaces where somebody wants the same tablet to behave differently in different areas.

Microsoft documents kiosk configuration for Windows and Windows Holographic for Business through a kiosk template, and points to separate kiosk configuration for Android device administrator, for Android Enterprise through device experience settings, and for iOS and iPadOS through the Apple device restriction settings. They are separate configurations with different capabilities rather than one feature applied four ways.

Yes. Android Enterprise dedicated device enrolment requires a factory reset, per Microsoft published table. That is straightforward for devices still in boxes and genuinely disruptive for devices already deployed and running, which is why this decision belongs at procurement rather than after distribution. It is the most common avoidable problem in these projects.

Then the Android Open Source Project route applies. Microsoft describes corporate-owned userless devices as built from AOSP and absent of Google Mobile Services, with no user associated with them, intended to be shared like in a library or lab. Rugged handsets, purpose-built terminals and much industrial hardware falls here, and it is a different enrolment path rather than a variant.

Unattended remote access, where the platform allows it. Remote Help lets helpers connect to Android devices without the user accepting the connection each time, and Microsoft states this requires the device to be enrolled as an Android Enterprise dedicated device. That requirement is not incidental: these are exactly the devices with nobody present to accept anything.

Worth checking against your own estate rather than assuming. Microsoft states that currently you can use Intune to configure a multi-app kiosk on Windows 10 devices, and directs readers to separate documentation for setting up a multi-app kiosk on Windows 11. Given Windows 10 reached end of support on 14 October 2025, any multi-app kiosk plan needs this confirmed as part of the design.

Yes, and Microsoft gives it as the example for single app kiosk mode: running Microsoft Edge and showing only one site. That is the standard configuration for signage, wayfinding screens, queue displays and customer-facing information terminals, and it prevents opening any other application or navigating away, which a general device showing a page does not.

Microsoft names the use cases directly for Android dedicated devices: digital signage, ticket printing and inventory management, describing them as corporate-owned single use or kiosk devices. It also frames Windows kiosk mode as common for frontline workers. In this market that covers a great deal of retail, hospitality, logistics, healthcare and facilities equipment.

That is the entire point of the configuration. On Android dedicated devices you limit the applications and web links available and prevent people using the device outside its intended scope. On Windows multi app kiosk, only the applications you add are available, and Microsoft describes the benefit as removing from view the applications users do not need. Everything else is unreachable rather than discouraged.

It needs designing rather than assuming, and it is the most common way these estates fall behind. A device with no user has nobody to accept anything, which is precisely why unattended update mechanisms matter here. On Android specifically, delivering firmware updates over the air without user action is an Intune advanced capability aimed at exactly this population.

A standard non-administrator account is limited to fifteen devices, while a device enrolment manager account can enrol up to a thousand. For a kiosk deployment this matters, because these devices are usually prepared centrally in batches by one person. Discovering the limit at device sixteen, halfway through preparing a shipment, is a specific and avoidable frustration.

Yes, and it is worth stating because a locked configuration on an unsecured device is half a control. These devices sit in public areas, corridors, shop floors and receptions by definition. Mounting, cabling and physical restraint are part of the deployment rather than a separate concern, and the management configuration is what limits the damage if one is taken.

You need to decide that, because nobody will tell you. A screen in a corridor that has gone blank generates no ticket, and a handset on a charging rack that stopped checking in generates none either. Monitoring for devices that have not reported, with a named owner, is what separates a managed kiosk estate from a collection of devices somebody discovers are broken during an inspection.

We scope per organisation, driven by how many device roles are in scope, which platforms are involved, and whether devices are already deployed, since that determines whether a factory reset is a plan or a problem. What we will tell you free in the first conversation is which enrolment path each device population should be on, because that decision has the largest cost consequence.
Before deploying

Fifteen questions worth answering first.

The first group defines the device role. The second is the enrolment path, which is where the factory reset decision sits. The third is the operational reality of a device nobody owns.

The device role

  • Does this device do one thing or several?
    Single app and multi app are different modes.
  • Is anybody signed in as a person?
    Some of these devices have no user at all.
  • Which applications and web links are permitted?
    Everything else should be unreachable.
  • Does the device need to behave differently by location?
    One kiosk profile per device applies.
  • Is this a frontline worker scenario?
    Microsoft frames kiosk mode around exactly that.

The enrolment path

  • Which platform, and which enrolment method?
    They differ substantially in what they allow.
  • Are the devices already deployed?
    Android dedicated enrolment requires a factory reset.
  • Do the Android devices have Google services?
    If not, the AOSP userless route applies.
  • Are you on Windows 10 or Windows 11?
    Relevant to multi-app kiosk configuration.
  • Who will enrol them, and how many?
    Standard accounts are capped at fifteen devices.

Running them

  • How do you support a device with nobody at it?
    Unattended remote access covers Android dedicated devices.
  • How do updates reach a device nobody logs into?
    Worth designing rather than hoping.
  • What happens if one is stolen or moved?
    These devices are physically exposed by nature.
  • Who notices when one stops checking in?
    Nobody complains about a screen in a corridor.
  • Is the device physically secured?
    A locked configuration on an unlocked device is half a control.
Related reading

The pages around this one.

Android Enterprise management

The enrolment methods in detail, including the factory reset table and the zero-touch route for bulk deployment.

Learn more

Intune Remote Help

Unattended remote access, which is available specifically on Android Enterprise dedicated devices.

Learn more

Microsoft Intune

The platform these configurations live in, alongside compliance, application deployment and reporting.

Learn more
Next step

Decide the enrolment path before the devices are distributed.

Android dedicated enrolment requires a factory reset, which is trivial for devices in boxes and a real project for devices already running in stores or on sites. Half an hour on this at procurement is the cheapest part of the whole deployment.

Book a shared device reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Android Enterprise

Choose the enrolment method before you buy the phones

Learn more

Intune Remote Help

Remote support scoped by role, with both parties authenticated

Learn more

Microsoft Intune

Device management and endpoint security

Learn more

MDM Solutions Dubai

Device management across Windows, Apple and Android

Learn more

Intune Suite

Eight advanced capabilities, and one trial each per tenant

Learn more

Intune Compliance Policies

The default that lets unassessed devices through Conditional Access

Learn more

Endpoint Security

Defender for Endpoint and Intune managed

Learn more

IT Support Dubai

24/7 on-site and remote IT support

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy