Article
Intune iPad Kiosk Mode: Lock to One App, No Extra MDM
Set up Intune iPad kiosk mode entirely inside Microsoft 365 — no third-party MDM, no extra license. Follow the exact admin-center clickpath, step by step.
By InstaCheckin Team Updated August 12, 2026

If your company runs Microsoft 365, you already pay for Microsoft Intune. Setting up Intune iPad kiosk mode for a visitor sign-in desk doesn’t require a separate MDM subscription, a Jamf license, or anything beyond what’s already in your M365 plan — the configuration lives inside the same admin center you use for Windows device management.
The goal is simple: the iPad locks to one app, the Home bar and app switcher disappear, and no on-device action can return a visitor to the home screen. Some offices also pair a sign-in kiosk with an AI receptionist for overflow and after-hours calls so the front desk stays covered even when no one’s sitting at it.
This guide walks the exact clickpath from a default Intune tenant to a locked reception iPad. If you’re still weighing which kiosk method to use — Guided Access vs. Single App Mode vs. Intune vs. Jamf — read our iPad kiosk mode guide first. That post maps every option with honest tradeoffs before you commit.
How Intune iPad Kiosk Mode Works Under the Hood
Intune’s iOS/iPadOS device configuration templates include a profile type called “Kiosk.” It exposes three locking modes:
- Single App, Managed App — locks the iPad to one app from your Intune app catalog
- Single App, Built-In App — locks to a pre-installed Apple app such as Safari or Maps
- Multi-App — shows a custom home screen grid limited to a defined set of apps
For a visitor sign-in desk, you want Single App, Managed App.
What Intune labels “Kiosk” is Apple’s Single App Mode AppLock payload — the same protocol command every other MDM uses to lock an iPad to one app. Intune sends that command to the supervised iPad; iOS enforces it at the operating-system level. The restriction re-engages every time the iPad reboots and checks back in, which is why this method survives power cycles where Guided Access doesn’t.
Worth clarifying early: this is not Guided Access. Guided Access is free, requires no MDM, and takes two minutes to configure — but it exits with a triple-click and won’t re-lock after a reboot. For a single staffed reception desk, Guided Access may be sufficient. For an unattended kiosk, multiple devices, or any deployment where you can’t rely on staff to re-lock the iPad each morning, Intune Single App Mode is the right call.
Which Microsoft 365 License Includes Intune?
Kiosk mode isn’t an upsell. It’s a core Intune device-configuration feature, and base Intune — Plan 1 — ships inside the Microsoft 365 bundles most offices already run: Microsoft 365 E3, E5, F1, F3, Business Premium, and the standalone Enterprise Mobility + Security (EMS) E3/E5 plans. If you manage Windows laptops or M365 accounts through one of those, you can build the iPad kiosk profile in the same admin center today. No Jamf seat, no separate MDM contract.
Microsoft is folding more into those base plans, not less. The 2026 Microsoft 365 packaging FAQ names the additions: Intune Remote Help, Intune Advanced Analytics, Intune Plan 2, Intune Privilege Management, Microsoft Cloud PKI, and Intune Application Management, landing in eligible EMS E3, Microsoft 365 E3, and E5 tenants. Microsoft scheduled that rollout to start in CY26 Q3 and complete by August 1, 2026, with 30 days’ Message Center notice per tenant. A reception kiosk needs none of it — base Intune handles Single App Mode by itself. Worth knowing the licensing direction anyway, before you sign for a third-party tool you may already own the equivalent of. The one line item Intune doesn’t cover is the sign-in app itself, which is priced separately by whoever supplies it — InstaCheckin’s plans are published.
One requirement to check first: the iPad has to be on a current OS. Intune’s supported-platforms reference lists iOS/iPadOS 17.x and later as supported, and — for devices enrolled without user affinity, which is what a reception kiosk is — 15.x and later as allowed to enroll. The distinction matters. Supported means the three most recent OS versions, where every applicable Intune feature works. Allowed means the device enrolls and eligible features may work, with no guarantee. Don’t run a lobby kiosk on “allowed.” Any iPad you’d buy new for a front desk clears the supported bar easily; a drawer iPad from 2018 might not.
Prerequisites Before You Open the Admin Center
Three things need to be in place before the kiosk profile does anything useful.
1. A supervised iPad
Single App Mode requires iPad supervision — a device state where iOS grants the MDM full device-level control. Apple puts App Lock squarely in the supervised-only restrictions list, available on iPadOS 13.1 and later, alongside the rest of the restrictions an unsupervised device simply won’t honor. Without supervision, Intune sends the AppLock command and the iPad silently ignores it. The Intune console may show the profile status as “Succeeded” while the iPad remains unlocked. This silent failure is the most common source of confusion for first-time Intune kiosk deployments.
Supervision happens two ways:
- Apple Business Manager — iPads purchased through an authorized reseller or added to ABM can be supervised and enrolled over the air during initial setup. Right path for any fleet larger than one or two devices.
- Apple Configurator 2 — supervises an iPad over USB from a Mac. Free. Works for one or two kiosks, but requires physical access to each device.
2. The iPad enrolled in Intune
The iPad must appear as a managed device in your Intune tenant. For ABM-enrolled devices, enrollment happens automatically when you link ABM to Intune and assign an enrollment profile. For Configurator-supervised devices, enrollment completes when the user steps through initial setup and the Company Portal app registers the device.
3. The sign-in app deployed to the device
The kiosk profile locks the iPad to one app — that app must already be installed and assigned to the device before the kiosk profile applies. Add it as a managed app first: Apps → iOS/iPadOS → Add, assign it to the device group you’ll target. A kiosk profile that references an uninstalled app will show an error in the device configuration view.
Templates or Settings Catalog? Where the Kiosk Profile Lives Today
Open Intune’s configuration blade today and you’re offered two ways to build a policy: Settings catalog and Templates. Microsoft’s own guidance nudges you toward the first. Its Apple settings-catalog reference states it plainly — “it’s recommended to create all new policies using the settings catalog where possible” — and warns that several older Apple templates are frozen: Device features, Device restrictions, Endpoint protection, and Extensions are no longer being updated, will be migrated into the settings catalog, and will eventually lose the ability to create new instances.
So should you build your kiosk in the Settings catalog?
Not yet. Kiosk isn’t on that frozen list, and Single App Mode for iOS/iPadOS is still configured through Templates → Kiosk. The clickpath below is the current one. Two practical implications for a reception iPad:
- Don’t go hunting for AppLock in the settings catalog. You’ll burn twenty minutes. The kiosk settings aren’t surfaced there today, and Microsoft’s own catalog reference documents DDM configurations — passcode, software update, Safari extensions, disk management — not the kiosk payload.
- Expect a migration eventually. When Kiosk does move, it’ll be a policy-type change, not a behavior change. iOS enforces the same Apple AppLock payload either way. Your iPad won’t unlock itself because Microsoft reorganized a menu.
The broader direction is worth tracking if you manage Apple devices beyond the front desk. Declarative device management is where Apple and Intune are both heading — Apple has already deprecated MDM-command-based software update management in favor of declarative software updates. Kiosk isn’t part of that shift yet.
Create the Kiosk Configuration Profile
Open the Intune admin center and go to:
Devices → Configuration → Create → New policy
Set Platform to iOS/iPadOS and Profile type to Templates → Kiosk. Click Create.
Basics tab — name the profile something recognizable: Reception iPad — Single App Kiosk is easy to find when troubleshooting.
Configuration settings tab — three Kiosk Mode options appear. Select Single App, Managed App, then configure:
- App to run in kiosk mode: Click Select a managed app and choose the visitor sign-in app you deployed. If it doesn’t appear, confirm the app is assigned as a managed app first, then try again.
- Touch — leave enabled. Visitors need to interact with the sign-in screen.
- Screen rotation — match your kiosk stand orientation. Most reception desks use a fixed portrait or landscape mount.
- Volume buttons — disable if the iPad is wall-mounted and you don’t want visitors adjusting volume.
- Sleep/wake button — disable to prevent the screen going dark between visitors.
- Auto lock — set to Never for a permanent kiosk. Otherwise the screen locks between visitors and requires a tap to wake before they can sign in.
Assignments tab — scope the profile to the device group containing your reception iPads only. Don’t assign it to all iOS devices. An accidental kiosk policy on a senior employee’s personal iPad is not an easy incident to explain.
Click Review + create, verify the summary, and save.
Assign the Profile and Confirm the Lock
After you save and publish the profile, Intune pushes it on the iPad’s next scheduled check-in. To apply it immediately:
- Go to Devices → All devices and select the reception iPad.
- Click Sync in the top action bar.
- After 30–60 seconds, refresh the device view and open the Device configuration tab.
- The kiosk profile should show Succeeded.
On the iPad: when the profile applies, the current app closes, the Home bar disappears, and the sign-in app launches automatically. Visitors can’t reach the home screen or switch apps through any on-device control — no triple-click exit, no Settings access, no app switcher.
Locking the iPad to More Than One App
Most reception desks want exactly one app on screen. But if your front desk also runs, say, a room-booking app or a building directory next to sign-in, Intune’s Multi-App kiosk mode shows a controlled home screen with only the apps you pick — everything else stays hidden. You set it up in the same Kiosk profile: choose Multi-App instead of Single App, Managed App, then add each app and lay out the grid.
Two things to weigh before going multi-app:
- Single App Mode is the stronger lock. One app, no Home bar, nothing for a visitor to wander into. Multi-app puts a home screen back on the device — fine for a staff-facing kiosk, riskier for an unattended lobby.
- The Kiosk profile can lock to three app sources. A managed app you previously added to Intune, a built-in app entered by bundle ID, or a Store app entered as an App Store URL, per Apple device restriction settings in Intune. For a visitor sign-in desk, a single managed app is almost always the right answer.
One caveat that catches people: a device locked in Single App Mode can’t switch to an authenticator app to finish a multi-factor prompt. If your sign-in app expects per-device MFA, plan to handle that login on the backend or at the host level — the locked iPad can’t satisfy a second-factor challenge that lives in another app.
How to Remove Intune Kiosk Mode from an iPad
Every kiosk gets unlocked eventually. You’re swapping the sign-in app, repurposing the iPad for a conference room, or shipping it back to the leasing company. There’s no button on the device — the whole point of MDM-enforced Single App Mode is that no on-device action ends it. The unlock happens in the admin center.
The clean path:
- Devices → Configuration, open your kiosk profile.
- Assignments tab — remove the device group containing that iPad. If the profile only ever served this one kiosk, deleting the profile outright works too.
- Devices → All devices, select the iPad, click Sync.
- On the next check-in, iOS drops the AppLock restriction. The Home bar comes back and the app switcher works again.
Give it 30–60 seconds and confirm in the device’s Device configuration tab that the kiosk profile no longer appears. A profile stuck in “Pending” usually means the iPad hasn’t checked in — plug it in, make sure it’s on Wi-Fi, and sync again.
Two mistakes to avoid. Don’t uninstall the app first. Pull the app while the kiosk profile is still assigned and you get an iPad locked to something that isn’t there — a black screen and a support ticket. Profile first, app second. And removing supervision isn’t the answer either. Wiping supervision means a full device erase and re-enrollment for what should be a two-click assignment change.
If you want staff to break out of kiosk mode routinely — say, to run a fire-drill roster off the same iPad — the assignment dance is the wrong tool. Ask your sign-in vendor about Autonomous Single App Mode (ASAM), where the app locks and unlocks itself behind a passcode while the MDM still controls the authorization. That’s a per-shift workflow. Removing the profile is a decommissioning workflow.
When the iPad Won’t Lock: Common Issues
Profile shows “Succeeded” but the iPad isn’t locked
The device isn’t supervised. On the iPad, check Settings → General → VPN & Device Management. If you see an enrollment profile but no supervision indicator, the device enrolled without supervision — the AppLock command arrives and iOS ignores it silently. Fix: re-enroll through ABM or Configurator with supervision enabled. Our iPad Single App Mode guide covers the supervision process for both paths.
The app isn’t locking — home screen is still accessible
The sign-in app isn’t installed on the device — or it landed after the profile did. Confirm it shows Installed in the device’s App Inventory inside Intune. The kiosk profile references the app’s Bundle ID; if the app isn’t present when the profile applies, iOS can’t lock to it. One detail Microsoft calls out and most people miss: “if the iOS/iPadOS app you enter is installed after you assign the profile, the device doesn’t enter kiosk mode until the device is restarted.” So reboot the device after confirming the install — a plain Sync won’t trigger the lock on its own.
Profile status shows “Conflict”
Two configuration profiles are sending competing restrictions to the same device. Open the device’s profile list and look for duplicate Kiosk assignments. Remove whichever one shouldn’t be there.
The wrong app is showing in kiosk mode
Double-check the Bundle ID in the kiosk profile. One character off causes the wrong app to run — or a silent failure where no lock applies at all. Verify against the app developer’s IT documentation or Apple Configurator 2’s Get Info view on the installed app.
FAQ
Does Intune kiosk mode survive an iPad reboot?
Yes. This is the main advantage over Guided Access. When the iPad reboots and reconnects to Intune, the MDM re-sends the AppLock restriction and the device comes back up locked to the same app. No staff action required.
Do I need Apple Business Manager, or will Apple Configurator 2 work?
Both work. Apple Configurator 2 supervises over USB from a Mac — it’s free and fine for one or two kiosks. Apple Business Manager is the right path for larger fleets: ABM-enrolled iPads are supervised over the air during initial device setup, so no USB cable or physical access is needed per device.
Can staff exit kiosk mode without involving IT?
Not with MDM-managed Single App Mode. The only exits are a Disable Single App Mode command from the Intune console or removing the configuration profile. If staff need to occasionally break out of kiosk mode without an IT ticket, ask your visitor sign-in app vendor whether they support Autonomous Single App Mode (ASAM) — that lets the app self-lock and self-unlock via an in-app passcode, while the MDM controls the overall authorization.
Does the iPad need to stay connected to the internet to remain locked?
No. Once Intune applies the AppLock profile, iOS enforces the restriction locally. The iPad stays locked even offline. It does need to reach Intune periodically to receive policy updates or the command to disable Single App Mode.
Which Microsoft 365 license do I need for Intune iPad kiosk mode?
Base Intune — Plan 1 — which is included in Microsoft 365 E3, E5, F1, F3, Business Premium, and the standalone EMS E3/E5 plans. Kiosk mode is a core device-configuration feature in Plan 1, so there’s no add-on to buy. If you already manage Windows devices or Microsoft 365 accounts through one of those bundles, you can build the iPad kiosk profile in the same admin center today.
Can a kiosk iPad locked to one app still use multi-factor authentication?
Not easily. A device in Single App Mode can’t switch to an authenticator app to complete a second factor, so per-app MFA prompts tend to break under the lock. For a reception kiosk, handle authentication on the app’s own backend or at the host level rather than relying on a device-side MFA challenge the locked iPad can’t satisfy.
What iPadOS version does Intune kiosk mode require?
Intune lists iOS/iPadOS 17.x and later as supported — meaning the three most recent releases, where every applicable feature works. For devices enrolled without user affinity, which is how a reception kiosk enrolls, 15.x and later are allowed to enroll, but Microsoft makes no guarantee they behave correctly. Any iPad you’d buy new for a front desk clears the supported bar comfortably. Keep it on a current iPadOS release so the kiosk profile and policy check-ins stay reliable.
Should I build the kiosk profile in the Settings catalog instead of Templates?
Not today. Microsoft’s guidance is to create new Intune policies in the Settings catalog where possible, and it has stopped updating several older Apple templates — Device features, Device restrictions, Endpoint protection, and Extensions — ahead of migrating them. Kiosk isn’t on that frozen list, and the Kiosk profile type is still where you configure iOS/iPadOS Single App Mode. Build it under Templates → Kiosk, and expect the settings to reappear in the Settings catalog at some point.
How do I take an iPad out of Intune kiosk mode?
Two options. Remove the kiosk profile’s assignment from the device group (Devices → Configuration → your profile → Assignments), then Sync the iPad — iOS drops the AppLock restriction on the next check-in and the Home bar returns. Or delete the profile entirely if no other kiosk uses it. Removing the app instead of the profile doesn’t work: the iPad stays locked to a missing app. Pull the profile first, then the app.
Where do I find the Bundle ID for the InstaCheckin iPad app?
It’s listed in the InstaCheckin admin portal under Settings → Device Setup. You can also find it in Apple Configurator 2 by selecting the installed app and choosing Get Info, or in the IT setup documentation InstaCheckin provides when you start a trial.
Set Up InstaCheckin on Your Kiosk iPad
InstaCheckin’s iPad app is built for MDM-managed kiosk deployments. Lock it to Single App Mode through Intune, and visitors see only the sign-in flow — photo capture, NDA or waiver signature if required, and a host notification by email or SMS the moment they check in. The InstaCheckin admin portal gives your IT team the app’s Bundle ID and enrollment steps without hunting through third-party documentation. If you’re standing up reception for a corporate office, the office visitor management system page covers the full front-desk workflow, and our comparison of the best visitor sign-in apps shows how the iPad options stack up before you commit. Plans are listed on the pricing page. Start a free trial and pair it with your existing Intune setup.
Frequently asked questions
Does Intune kiosk mode survive an iPad reboot?
Do I need Apple Business Manager, or will Apple Configurator 2 work?
Can staff exit kiosk mode without involving IT?
Does the iPad need to stay connected to the internet to remain locked?
Which Microsoft 365 license do I need for Intune iPad kiosk mode?
Can a kiosk iPad locked to one app still use multi-factor authentication?
What iPadOS version does Intune kiosk mode require?
Should I build the kiosk profile in the Settings catalog instead of Templates?
How do I take an iPad out of Intune kiosk mode?
Where do I find the Bundle ID for the InstaCheckin iPad app?
Related reading
iPad Guided Access Setup Guide for Visitor Sign-In
Lock your iPad to one sign-in app with Guided Access — no MDM, no subscription. Full setup walkthrough, passcode tips, and the reboot caveat Apple omits.
How to Put an iPad in Kiosk Mode (2026 Step-by-Step Guide)
Learn how to put an iPad in kiosk mode using Guided Access, Single App Mode, or MDM. Step-by-step instructions for locking any iPad to a single app — no MDM required for the quick setup.
iPad Single App Mode: Lock an iPad to One App
Single App Mode (SAM) is the MDM-enforced way to lock an iPad to one app — it survives reboots, resists triple-click exits, and scales across a fleet.