Flamingo Raises $4.5M Seed Round

Skip to content

A kiosk is a device that does one job, like a check-in iPad at a front desk or a menu board in a lobby. Apple, Google and Microsoft each draw the lock in a different place, so the right control depends on the platform. This guide starts with iPad kiosk mode, then covers Chrome kiosk mode and Windows Assigned Access, so you can match the lock to the device.

Guided Access vs Single App Mode

Two features get called iPad kiosk mode, and they are not the same lock. Guided Access is an accessibility setting. Apple describes it as a way to "temporarily restrict your device to a single app", with a passcode, optional Face ID or Touch ID to end the session, and controls for hardware buttons, keyboard, touch areas and a time limit.

Single App Mode is the managed version. It works only on supervised iPads, and an MDM server turns it on through the App Lock payload. The app stays in the foreground with no exit, and only an MDM command or a changed profile ends it. SimpleMDM's guide (updated May 2025) covers the same ground, and our Apple MDM comparison covers which tools can push it.

The practical difference is who holds the exit. With Guided Access, anyone who knows the passcode can end the session at the device. With Single App Mode, the exit lives on the server.

Setting Up Guided Access on an iPad

Guided Access suits one or two iPads, a demo unit or a trade show stand. Per Apple's support page, the setup is short:

  1. Open Settings, tap Accessibility, then tap Guided Access and turn it on.
  2. Set a Guided Access passcode, and choose whether Face ID or Touch ID can also end a session.
  3. Open the app you want to lock, then triple-click the top button on an iPad (the Home button on older models).
  4. Circle any screen areas that should ignore touch, open Session Settings to block buttons, motion, keyboard or set a time limit, then tap Start.

Locking an iPad to one website is the common request. One r/ipad thread, "PSA: How to lock an iPad to a single website or app (kiosk mode) without buying expensive extra hardware", covers the do-it-yourself route.

The limit is scale. Each iPad is configured by hand, and nothing stops a staff member who knows the passcode from ending the session. That is fine for a demo table and a poor fit for forty iPads across three sites.

Single App Mode Through MDM

For a fleet, supervise the iPads and push the lock from the MDM. The video below shows the device side of Single App Mode.

The flow is the same in every MDM: enroll the iPad as supervised, assign the app, then push the App Lock payload. A second option is Autonomous Single App Mode, where an approved app locks the device itself, which suits point-of-sale and exam apps that need to unlock between sessions.

Plan the exit before you deploy. Because the MDM owns it, every maintenance task, from a new app version to a Wi-Fi change, becomes a managed step instead of a quick fix at the device.

Where Kiosk iPads Break

The lock that keeps users out also keeps updates out. SimpleMDM notes that apps cannot be updated while a device is in Single App Mode, so you have to release the lock temporarily to apply pending updates.

OS updates behave the same way. In an r/Intune thread from August 2026, an admin with roughly 30 kiosk iPads reported that they ignored a declarative device management update policy. Replies split: one admin said kiosk iPads running Guided Access would not update until Guided Access was turned off, another got "Enforce latest" working against a web app in kiosk mode, and a third suggested pinning a Targeted Version instead.

Connectivity is the other failure. In a September 2026 r/Intune thread, an admin with seven iPads in kiosk mode through Intune reported that they dropped off Wi-Fi after about three weeks, even with MAC randomization disabled in the Wi-Fi profile, and each one needed a USB-C Ethernet adapter to get back online. Kiosks sit untouched, so a slow failure like that can run for weeks before anyone notices.

The takeaway is to test one iPad before the update window, not to expect one answer. Build a monthly maintenance slot where kiosks leave the lock, update and return to it, and write that slot into the client's runbook.

Chrome Kiosk Mode

On a laptop or mini PC, Chrome kiosk mode is a launch flag. Starting Chrome with --kiosk opens it in full screen, and the Chromium switch list notes that this is not Chrome OS kiosk mode. The flag changes the window, not the machine, so it works as a tidy front end and not as a lock.

A Chrome kiosk still needs a surrounding policy. Keyboard shortcuts, other apps and the desktop sit behind the browser unless the operating system blocks them. A related switch, --kiosk-printing, presses the print button in print preview automatically, which suits receipt and label kiosks.

For Chromebooks and Android tablets, the lock comes from the management console and not from a flag. The Android side is covered in our Android MDM guide.

Windows Assigned Access

Assigned Access is the built-in Windows kiosk, and Microsoft's own examples are public browsing and interactive digital signage. Microsoft Learn (updated 15 July 2026) says a single-app kiosk runs one Universal Windows Platform app or Microsoft Edge in full screen above the lock screen, and if the app closes, it restarts. A restricted user experience is the multi-app option, with a defined app list, a tailored Start menu and taskbar, and AppLocker rules.

Assigned Access applies to Windows 11 and Windows 10 Pro, Enterprise, Enterprise LTSC, Education and IoT Enterprise. Home is not on the list, so a Home-edition mini PC needs an upgrade or a different approach.

Kiosks also lose their lock quietly. A screen that sleeps or locks defeats the point of a menu board, and the fix is a power setting, not a new tool. Our guide to screen timeout settings covers the dashboard and kiosk case.

If you run kiosks for clients, OpenFrame can run a script across a client's devices and collect the output, which makes a quick audit of kiosk settings a single job.

Choosing the Right Lockdown

Start from the device, then ask who needs the exit. One iPad that a staff member sets up and watches fits Guided Access. A supervised fleet with an MDM fits Single App Mode. A Windows machine fits Assigned Access, and a Chrome flag is a front end that sits on top of one of those, not a replacement.

Mixed fleets raise the same question at scale, which our MDM solutions comparison answers by platform.

Aliaska Varieva

Aliaska Varieva

Head of Platform

Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. Guided Access is built into iPadOS and needs no MDM or supervision. Turn it on in Settings, Accessibility, set a passcode, then triple-click the top button inside the app you want to lock. It works for one or two iPads, but anyone who knows the passcode can end the session.
SimpleMDM notes that apps cannot be updated while a device is in Single App Mode, so you need to release the lock temporarily to apply pending updates. Admins in an August 2026 r/Intune thread also reported OS update policies being ignored on kiosk iPads. Schedule a maintenance window and test on one device first.
Start Chrome with the --kiosk command-line switch to open it in full screen. The Chromium switch list notes this is not Chrome OS kiosk mode, and the flag only changes the browser window. Pair it with an operating system lock such as Windows Assigned Access if users must not leave the page.
Microsoft Learn (updated 15 July 2026) lists Assigned Access as supported on Windows 10 and 11 Pro, Enterprise, Enterprise LTSC, Education and IoT Enterprise editions. Home is not on that list, so a Home-edition kiosk PC needs an edition upgrade or a different approach.