ipad
How to Put an iPad in Kiosk Mode (2026 Step-by-Step Guide)
Learn how to put an iPad in kiosk mode using Guided Access, Single App Mode, or MDM. Step-by-step instructions for locking any iPad to a single app — no MDM required for the quick setup.
By InstaCheckin Team Updated August 5, 2026

iPad kiosk mode locks a device to a single app — visitors can sign in, place an order, or interact with your content, but they can’t exit the app, open Safari, change settings, or see anything you haven’t put in front of them.
This guide explains exactly how to put an iPad in kiosk mode using three methods, starting with the fastest (30 seconds, no tools required) and working up to the managed approach used for multi-site fleet deployments. Pick the method that matches your situation, follow the steps, and your iPad will be locked down before you finish your coffee.
How to put an iPad in kiosk mode: choose your method
There are three ways to put an iPad in kiosk mode. The right one depends on how many iPads you’re locking down and whether the kiosk needs to recover from reboots without anyone touching it.
| Method | Requires supervision? | Survives reboot? | Cost | Best for |
|---|---|---|---|---|
| Guided Access | No | No | Free | 1–2 iPads, on-site staff |
| Single App Mode (Apple Configurator) | Yes | Yes | Free (need a Mac) | Up to ~20 iPads |
| Single App Mode (MDM) | Yes | Yes | Varies by vendor | Fleets, multi-site |
Start with Guided Access if you’re trying things out or running a single front-desk iPad. Jump straight to MDM-based Single App Mode if you have multiple locations or unattended iPads that need to recover on their own.
Method 1: How to enable Guided Access on iPad (free, no MDM needed)
Guided Access is built into every iPad. It takes about 30 seconds to set up and works without a Mac, MDM, or Apple Business Manager account. Apple documents it as an accessibility feature — “Guided Access helps you stay focused on a task by temporarily restricting iPad to a single app” — but it’s the same lock a kiosk needs.
One-time setup
- Open Settings on the iPad.
- Tap Accessibility, then scroll down and tap Guided Access.
- Toggle Guided Access on.
- Tap Passcode Settings → Set Guided Access Passcode. Enter and confirm a 6-digit code. This passcode ends sessions — keep it separate from the device unlock passcode.
- (Optional but recommended) Enable Face ID or Touch ID so authorized staff can end the session with biometrics instead of typing a code in front of visitors.
Starting a kiosk session
- Open the app you want to lock the iPad to (for example, InstaCheckin’s visitor sign-in screen).
- Triple-click the side button (or the Home button on older iPads).
- The Guided Access setup screen appears. Tap Options in the bottom-left to configure the session:
- Disable the Sleep/Wake and Volume buttons so visitors can’t power off or mute the device.
- Disable Motion to prevent screen rotation.
- Draw circles over any screen areas you want to make touch-dead (useful for blocking a back button).
- Set a Time Limit if you want sessions to auto-end after a fixed duration.
- Tap Start in the top-right corner.
The iPad is now in kiosk mode. The Home Screen is unreachable, swipes from the bottom are blocked, and Control Center is disabled. The visitor sees only the app.
Ending a Guided Access session
Triple-click the side or Home button, enter the passcode (or use Face ID/Touch ID), and tap End in the top-left corner.
The one limitation to know
Guided Access does not survive a reboot. If the battery drains, an update installs overnight, or someone force-restarts the device, the iPad boots back to the Home Screen. For a single lobby iPad with staff on site each morning, that’s manageable — someone re-engages Guided Access when they arrive. For an unattended kiosk in a remote office or warehouse, it’s a problem. That’s what Single App Mode solves.
Method 2: Single App Mode via Apple Configurator (persistent, free)
Single App Mode is the production-grade version of iPad kiosk mode. The iPad boots directly into the locked app after every restart, OS update, or battery drain — with no staff intervention. It requires the iPad to be supervised, which means erasing it and re-preparing it through Apple Configurator 2 (a free Mac app). Apple gates the lock behind supervision on purpose: Single App Mode (listed as “App Lock”) is one of the restrictions Apple reserves for supervised devices, along with disabling screenshots and AirDrop.
Step 1: Supervise the iPad
- Download Apple Configurator 2 from the Mac App Store (free).
- Connect the iPad to your Mac via USB.
- Click Prepare in Apple Configurator, check Supervise devices, and complete the wizard. This factory-resets the iPad — back up anything on it first.
- Reinstall your kiosk app after preparation is complete.
Step 2: Enable Single App Mode
With the supervised iPad still connected via USB:
- In Apple Configurator, click the iPad.
- Choose Actions → Advanced → Start Single App Mode (Apple’s current steps).
- Select the app to lock to (it must already be installed).
- Click Select.
The iPad immediately relaunches into the chosen app, locked. Home button, app switcher, Control Center, Notification Center — all disabled. Every reboot returns to the same app automatically.
Step 3: Tighten the kiosk profile (recommended)
Push a Restrictions configuration profile to disable features that Single App Mode doesn’t cover on its own: screenshots, AirDrop, AirPrint, Siri, Bluetooth pairing changes, and iPadOS update prompts. These take five minutes in Apple Configurator and meaningfully reduce the attack surface of a public-facing kiosk.
Exiting Single App Mode
Connect the iPad back to the same Mac, open Apple Configurator, and choose Actions → Advanced → Stop Single App Mode. There is no on-device way out.
Method 3: MDM kiosk mode — Jamf, Intune, Mosyle, ManageEngine, Kandji
For any deployment larger than about 20 iPads, or any deployment where you can’t periodically connect iPads to a Mac, an MDM (mobile device management) platform pushes Single App Mode over the air. You configure the lock once in a web dashboard, scope it to a device group, and every iPad in that group locks within minutes — no USB cable, no per-device touch.
The core configuration is identical across MDMs: create a Single App Mode payload, enter the kiosk app’s bundle ID, and scope to your supervised iPads.
Microsoft Intune: Devices → Configuration → Create profile → iOS/iPadOS → Templates → Device features → App Single App Mode → enter bundle ID (e.g. io.instacheckin.app) → assign to group.
Jamf Pro: Configuration Profiles → New → Single App Mode payload → bundle ID → scope to a smart group filtered on Supervised = Yes.
Mosyle: Profiles → iOS/iPadOS → Single App Mode → choose app → assign.
ManageEngine MDM: Profiles → Apple → iOS Profile → Restrictions → Single App Mode → bundle ID.
Kandji: Library → Single App Mode → choose app → assign to the kiosk Blueprint.
Production tips that apply to all MDMs:
- Pair the Single App Mode profile with a Restrictions payload — block screenshots, AirDrop, AirPrint, Siri, and the App Store.
- Add a Web Content Filter if your kiosk app uses an embedded browser for redirect flows; allowlist only the domains it needs.
- Use deferred software updates so iPadOS updates apply only after you’ve validated the kiosk app works on the new version.
- Enable lost mode so stolen or misplaced kiosk iPads can be remote-wiped.
Zero-touch enrollment: deploying iPad kiosks at scale with Apple Business Manager
The three methods above assume you’re setting up iPads in person. For a single front-desk iPad, that’s a five-minute task. For a 15-location organization shipping iPads to remote facilities, physically connecting each device to a Mac or manually enrolling each one in an MDM becomes a real logistics problem.
Apple Business Manager (ABM) eliminates the per-device setup step. It’s a free Apple portal for organizations that connects your iPad purchases to your MDM before the devices even ship. Every iPad you buy through ABM or an ABM-enrolled reseller arrives already supervised, already in your MDM’s queue, and ready for your Single App Mode configuration — the kiosk profile installs automatically on first Wi-Fi connection.
How to set up zero-touch iPad kiosk enrollment
- Create an Apple Business Manager account at business.apple.com. Apple verifies your organization using a DUNS number or equivalent business ID — plan for a few business days.
- Connect your MDM. In ABM, go to Settings → MDM Servers → Add MDM Server. Generate and upload the token from your MDM console (Jamf, Intune, Mosyle, and Kandji all support this). Any device assigned to your ABM reports to this MDM on first power-on.
- Purchase iPads through an ABM-enrolled reseller. Apple Authorized Resellers and Apple.com direct orders can be tagged to your ABM account at checkout. Already own iPads that weren’t purchased through ABM? Apple Configurator 2 has an “Add to Apple Business Manager” flow that reassigns existing devices without erasing them.
- Configure your MDM enrollment profile. Set it to apply supervision, push your kiosk app silently, and deploy the Single App Mode profile — all scoped to a device group.
When the iPad arrives at your location, a staff member connects it to power and Wi-Fi. Setup Assistant runs, Apple’s activation servers recognize the ABM assignment, the MDM profile installs automatically, and the device locks to Single App Mode — in under ten minutes, with no Mac and no IT on-site.
ABM vs. Apple Configurator: which path fits your situation
| Apple Configurator 2 | Apple Business Manager | |
|---|---|---|
| Setup method | USB + Mac | Over the air |
| Works on | Any iPad you own | Devices purchased through or added to ABM |
| Cost | Free | Free |
| MDM required | Optional | Yes |
| Best for | Existing iPads, up to ~20 devices | New purchases at any scale |
For a step-by-step MDM configuration walkthrough, see the Jamf iPad kiosk mode guide or the Microsoft Intune iPad kiosk mode guide.
Picking the right iPad, mount, and power for a kiosk
The software side of kiosk mode is the easy part. The hardware decisions are what people get wrong — they buy too much iPad, forget the iPad sleeps, or mount it somewhere a visitor can walk off with it. Tablet kiosks are a fast-growing slice of a market that Grand View Research valued at $34.79 billion in 2024 and projects to reach $52.74 billion by 2030, a 7.2% compound annual growth rate — with North America holding more than 42% of that spend. The hardware ecosystem around iPad kiosks is deep, so you have real choices. Here’s how to make them.
Which iPad model. The base iPad is almost always enough. A kiosk runs one app, not a game engine, so you’re not paying for an iPad Pro’s chip. Buy for longevity instead: pick a model still receiving iPadOS updates, since a kiosk you bolt to a wall should stay supported for years. That’s a concrete threshold, not a vibe. iPadOS 27 supports iPad (9th generation) and later, iPad Air (4th generation) and later, iPad mini (6th generation), and iPad Pro 11-inch (2nd generation) / 12.9-inch (4th generation) and later — so a refurbished iPad 9th generation is the oldest unit worth buying for a new kiosk today. Wi-Fi-only is fine for most lobbies; add cellular only if the kiosk lives somewhere your network doesn’t reach.
Power and the sleep problem. An iPad isn’t a digital-signage display — it will dim and lock unless you stop it. In Settings → Display & Brightness, set Auto-Lock to Never, and keep the iPad on a charger. A wall-mount with a pass-through power cable is the standard setup; for a freestanding floor kiosk, run power up through the stand. Guided Access and Single App Mode both keep the screen awake while engaged, but only if the device has power.
Mount and anti-theft. A public-facing iPad needs a locking enclosure, not a desk stand a visitor can pocket. Commercial kiosk enclosures bolt to a wall, counter, or floor stand and cover the charging port and buttons. If you’re printing badges, the badge printer is the other piece of hardware to plan for — see how to find your Brother label printer’s IP address when you wire one into the kiosk.
iPadOS 26 and kiosk mode: what the redesign changed
iPadOS 26 shipped on September 15, 2025, and it’s the biggest visual overhaul the iPad has had in years. Apple replaced the flat look with a translucent material called Liquid Glass, added a Mac-style windowing system, and kept the year-based name it adopted that summer. If you run kiosks, the headline question is simple: does any of this break the lockdown? No. But two things are worth knowing.
The kiosk APIs didn’t change. Guided Access, Single App Mode, and Autonomous Single App Mode work on iPadOS 26 exactly as they did on iPadOS 16, 17, and 18. The triple-click is the same. The Apple Configurator menu path is the same. The MDM payload keys are the same. Single App Mode still pins the device to one app, and the new windowing system never engages while that lock is active — the app lock sits below the multitasking layer, so visitors can’t float, tile, or resize their way out of your sign-in screen.
Liquid Glass changes how some controls read. The translucent chrome shifts contrast on buttons and text fields. On a kiosk that visitors approach at arm’s length, a control that looked fine on iPadOS 18 might wash out against a bright lobby. After you update, walk up to the kiosk and check that your sign-in buttons still read clearly from a step or two back. It’s a two-minute check that catches a legibility regression before a visitor does.
The real work on any major iPadOS jump is app compatibility, not the lock itself. Test your kiosk app on the new build before you let it reach production devices — then use your MDM’s deferred software updates to hold the rollout until you’ve confirmed it. The lock APIs are stable; your app on a brand-new OS is the variable.
iPadOS 27 ships this fall: three things to settle before it lands
Apple previewed iPadOS 27 on June 8, 2026 at WWDC. Developer betas went out the same day, the public beta followed a month later, and the general release is “this fall” — which in practice means September. Guided Access, Single App Mode, and ASAM are all untouched again. But three things do land on a kiosk operator’s desk.
Some of your iPads are at the end of the line. iPadOS 27 runs on iPad (9th generation) and later, iPad Air (4th generation) and later, iPad mini (6th generation), iPad Pro 11-inch (2nd generation) and later, and iPad Pro 12.9-inch (4th generation) and later. If a lobby of yours is running an iPad 8, an iPad Air 3, an iPad mini 5, or a 2018 iPad Pro, this is where it stops getting new iPadOS releases. Nothing breaks the morning after. The kiosk keeps running on iPadOS 26, Single App Mode keeps holding, and your visitors notice nothing. What changes is the clock: you’re now on a device that won’t pick up new OS features, so put a replacement in next year’s budget rather than discovering the problem when a vendor drops support for the older build.
Siri is the headline, and on a kiosk that’s a liability, not a feature. iPadOS 27’s marquee change is an overhauled, far more capable Siri. On a device bolted to a lobby wall, a voice assistant that answers questions and opens things is another surface a stranger can poke at. If you’re on MDM, Siri is one of the restrictions Apple exposes for supervised devices — confirm that toggle is still off in your Restrictions payload after the upgrade, not before. Major releases have a habit of reintroducing defaults.
Your test window is now, not September. The public beta is already out. Install it on one spare iPad, run your kiosk app through a full sign-in — badge print, signature capture, host notification — and only then set your MDM’s deferred-update window. Testing one device in August costs an hour. Discovering a broken badge print across twelve lobbies in September costs a week.
Apple iPad kiosk mode for visitor sign-in
One of the most common real-world deployments of Apple iPad kiosk mode is the front-desk visitor sign-in station. A wall-mounted or stand-mounted iPad running a visitor management app greets guests at the lobby, collects their name and host, captures a photo or signature if required, and notifies the host via SMS — all without a receptionist needing to be present.
For offices where the front desk can’t always be staffed, pairing the sign-in kiosk with an AI receptionist for overflow and after-hours calls means visitors and callers are covered around the clock.
The iPad kiosk mode setup for visitor sign-in follows the same steps above, with one addition: most purpose-built visitor sign-in apps — InstaCheckin included — support Autonomous Single App Mode (ASAM). The app locks itself between visitor sessions and unlocks briefly for staff (for admin settings or overrides) without anyone touching Settings or entering a passcode. This means the iPad stays locked in kiosk mode automatically across the entire business day.
For a single office, Guided Access is enough to get running in under five minutes. For a multi-site organization where lobby iPads sit unattended overnight, the right setup is Single App Mode via MDM, a Restrictions profile blocking screenshots and AirDrop, and deferred updates managed from the MDM console.
InstaCheckin’s visitor check-in app is built for iPad kiosk mode deployments in offices, schools, manufacturing facilities, and events. It runs in Guided Access out of the box and supports ASAM for MDM-managed fleets. Start a free trial to see it running in kiosk mode on your own iPad.
How to exit iPad kiosk mode
The exit procedure depends on which method you used:
- Guided Access: Triple-click the side (or Home) button → enter the Guided Access passcode → tap End. If Face ID or Touch ID was enabled, double-click and authenticate.
- Forgotten Guided Access passcode: Force-restart the iPad. On Face ID iPads: press and release Volume Up, press and release Volume Down, hold the top button until the Apple logo appears. On Home button iPads: hold Home and the top button together. The reboot ends the session.
- Single App Mode (Apple Configurator): Connect the iPad to the Mac via USB → Apple Configurator → Actions → Advanced → Stop Single App Mode.
- Single App Mode (MDM): Remove the Single App Mode configuration profile from the device’s scope in your MDM console, or push an updated profile with Single App Mode disabled. The iPad relaunches to the Home Screen within minutes.
- Autonomous Single App Mode: The app’s own admin flow exits ASAM programmatically. Removing the
com.apple.app.lockallowlist profile from the MDM also disables it.
Kiosk mode won’t engage: five failures, in the order you’ll hit them
Most “iPad kiosk mode isn’t working” tickets are one of five things. None of them require a support call.
The triple-click does nothing, or Guided Access is greyed out. Check the toggle first: Settings → Accessibility → Guided Access has to be on before the shortcut does anything. If it’s on and the triple-click still misfires, you’ve almost certainly assigned more than one feature to the Accessibility Shortcut — with two or more selected, a triple-click opens a picker menu instead of starting a session. Settings → Accessibility → Accessibility Shortcut, uncheck everything except Guided Access. Apple’s Guided Access instructions cover the setup path but not this conflict, which is why it eats so much time.
The MDM says the Single App Mode profile installed, but the iPad ignores it. Supervision. Single App Mode is a supervised-device-only restriction, and an unsupervised iPad accepts the payload and silently does nothing with it. Look at the device record in your MDM console and confirm Supervised = Yes before you debug a single other thing. If it says No, the device has to go back through Apple Configurator or be reassigned in Apple Business Manager.
The lock applies to the wrong app, or to nothing. Bundle ID. It’s case-sensitive, it’s reverse-DNS (io.instacheckin.app), and it is not the app’s App Store display name. Pull the exact string from your MDM’s app inventory rather than typing it from memory.
The kiosk is back on the Home Screen every Monday morning. That’s Guided Access doing exactly what it’s designed to do. It doesn’t survive a reboot, and a weekend of battery drain or an overnight iPadOS update counts as a reboot. Either move that device to Single App Mode or keep it permanently on power — those are the only two fixes.
A permission dialog traps the visitor. This one’s sneaky. If your kiosk app hasn’t yet been granted camera, Bluetooth, or notification access, iPadOS raises the request the first time the app needs it — and inside a locked session with touch regions disabled, a visitor can end up staring at a modal they can’t dismiss. Grant every permission the app needs while the iPad is unlocked, run one complete visitor flow end to end, and only then start the kiosk session.
Common questions about putting an iPad in kiosk mode
Does iPad kiosk mode work with Bluetooth printers?
Yes. Bluetooth printer pairing is unaffected by Guided Access or Single App Mode as long as the kiosk app has Bluetooth permission. Pair the printer first in Settings → Bluetooth, then start kiosk mode. For supervised deployments, an MDM Restrictions payload can prevent users from disconnecting or re-pairing devices.
Can I lock the iPad to a specific website?
Yes. Open the URL in Safari (or a dedicated kiosk browser), then start Guided Access. For a managed deployment, combine a Web Content Filter payload (allowlisting the target URL) with Single App Mode locked to Safari or the kiosk browser.
Will an iPadOS update break my kiosk?
Single App Mode and Guided Access both survive iPadOS updates. The two ways an update can break a kiosk are: (1) the kiosk app becomes incompatible with the new iPadOS version, or (2) a new system UI element appears that the user can now reach. Mitigate both by deferring iPadOS updates in your MDM until you’ve validated the new version.
Can visitors take screenshots while the iPad is in kiosk mode?
By default, yes — Guided Access does not block screenshots. Push a Restrictions configuration profile via Apple Configurator or your MDM to disable screenshot capture if your kiosk displays content that shouldn’t be captured.
Is iPad kiosk mode the same as iPhone kiosk mode?
Functionally yes. Guided Access and Single App Mode work identically on iPhone (iOS) and iPad (iPadOS), and the MDM payloads use the same keys. Most kiosk deployments use iPad rather than iPhone because the larger screen is better suited to sign-in forms, ordering flows, and self-service interactions.