{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/",
        "slug": "dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/"
        },
        "title": "Choose single-app mode by who must be able to exit it",
        "summary": "Should an iPad kiosk rely on an app-controlled exit or an administrator-controlled lock?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:27:59+00:00",
        "modified_at": "2026-09-10T01:20:46+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 254,
        "potentially_affected": "Use this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.",
        "dse_recommendation": "Write down the required exit authority before choosing the kiosk setting.",
        "primary_source": {
            "name": "Configure security, email, VPN, and Wi-Fi device configuration profiles - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/fundamentals/deploy-configuration-step-4",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft distinguishes Autonomous Single App Mode from App Lock. An app used with ASAM must support that mode, and only the app can leave it. App Lock can target any app, with administrators able to exit the lock. The deployment guide lists separate configuration options for these iOS and iPadOS experiences. <a href=\"https://learn.microsoft.com/en-us/intune/fundamentals/deploy-configuration-step-4\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.</p>\n<h2>DSE recommendation</h2>\n<p>Write down the required exit authority before choosing the kiosk setting. Ask the application owner whether the workflow must control its own exit and obtain evidence of ASAM support if that is the proposed design. Alternatively, specify the authorized administrator&#8217;s procedure for an App Lock deployment. Keep the everyday operator&#8217;s actions and the maintenance operator&#8217;s actions distinct in the runbook. Do not discover the intended escape path for the first time during an unattended deployment.</p>\n<h2>Verification</h2>\n<p>On an approved spare device, run the actual application under the proposed mode and test both the expected restricted workflow and the authorized exit. Have the relevant app or device administrator demonstrate the maintenance path. Record any unsupported application behavior before expanding the assignment. If the required exit authority differs from the selected mode&#8217;s documented model, revise the design rather than teaching users an unreviewed workaround.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/fundamentals/deploy-configuration-step-4\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure security, email, VPN, and Wi-Fi device configuration profiles</a>.</p>",
        "content_text": "Source facts\nMicrosoft distinguishes Autonomous Single App Mode from App Lock. An app used with ASAM must support that mode, and only the app can leave it. App Lock can target any app, with administrators able to exit the lock. The deployment guide lists separate configuration options for these iOS and iPadOS experiences. Microsoft Learn.\nApplicability\nUse this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.\nDSE recommendation\nWrite down the required exit authority before choosing the kiosk setting. Ask the application owner whether the workflow must control its own exit and obtain evidence of ASAM support if that is the proposed design. Alternatively, specify the authorized administrator’s procedure for an App Lock deployment. Keep the everyday operator’s actions and the maintenance operator’s actions distinct in the runbook. Do not discover the intended escape path for the first time during an unattended deployment.\nVerification\nOn an approved spare device, run the actual application under the proposed mode and test both the expected restricted workflow and the authorized exit. Have the relevant app or device administrator demonstrate the maintenance path. Record any unsupported application behavior before expanding the assignment. If the required exit authority differs from the selected mode’s documented model, revise the design rather than teaching users an unreviewed workaround.\nOfficial references\nMicrosoft Learn: Configure security, email, VPN, and Wi-Fi device configuration profiles.",
        "content_markdown": "## Source facts\n\nMicrosoft distinguishes Autonomous Single App Mode from App Lock. An app used with ASAM must support that mode, and only the app can leave it. App Lock can target any app, with administrators able to exit the lock. The deployment guide lists separate configuration options for these iOS and iPadOS experiences. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/fundamentals/deploy-configuration-step-4).\n\n## Applicability\n\nUse this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.\n\n## DSE recommendation\n\nWrite down the required exit authority before choosing the kiosk setting. Ask the application owner whether the workflow must control its own exit and obtain evidence of ASAM support if that is the proposed design. Alternatively, specify the authorized administrator’s procedure for an App Lock deployment. Keep the everyday operator’s actions and the maintenance operator’s actions distinct in the runbook. Do not discover the intended escape path for the first time during an unattended deployment.\n\n## Verification\n\nOn an approved spare device, run the actual application under the proposed mode and test both the expected restricted workflow and the authorized exit. Have the relevant app or device administrator demonstrate the maintenance path. Record any unsupported application behavior before expanding the assignment. If the required exit authority differs from the selected mode’s documented model, revise the design rather than teaching users an unreviewed workaround.\n\n## Official references\n\n[Microsoft Learn: Configure security, email, VPN, and Wi-Fi device configuration profiles](https://learn.microsoft.com/en-us/intune/fundamentals/deploy-configuration-step-4)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Choose single-app mode by who must be able to exit it",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/",
                "headline": "Choose single-app mode by who must be able to exit it",
                "description": "Should an iPad kiosk rely on an app-controlled exit or an administrator-controlled lock?",
                "abstract": "Should an iPad kiosk rely on an app-controlled exit or an administrator-controlled lock?",
                "articleBody": "Source facts\nMicrosoft distinguishes Autonomous Single App Mode from App Lock. An app used with ASAM must support that mode, and only the app can leave it. App Lock can target any app, with administrators able to exit the lock. The deployment guide lists separate configuration options for these iOS and iPadOS experiences. Microsoft Learn.\nApplicability\nUse this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.\nDSE recommendation\nWrite down the required exit authority before choosing the kiosk setting. Ask the application owner whether the workflow must control its own exit and obtain evidence of ASAM support if that is the proposed design. Alternatively, specify the authorized administrator’s procedure for an App Lock deployment. Keep the everyday operator’s actions and the maintenance operator’s actions distinct in the runbook. Do not discover the intended escape path for the first time during an unattended deployment.\nVerification\nOn an approved spare device, run the actual application under the proposed mode and test both the expected restricted workflow and the authorized exit. Have the relevant app or device administrator demonstrate the maintenance path. Record any unsupported application behavior before expanding the assignment. If the required exit authority differs from the selected mode’s documented model, revise the design rather than teaching users an unreviewed workaround.\nOfficial references\nMicrosoft Learn: Configure security, email, VPN, and Wi-Fi device configuration profiles.",
                "datePublished": "2026-09-10T00:27:59+00:00",
                "dateModified": "2026-09-10T01:20:46+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Choose single-app mode by who must be able to exit it"
                },
                "articleSection": [
                    "Access Control",
                    "IT"
                ],
                "keywords": [
                    "Access Control",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 254,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure security, email, VPN, and Wi-Fi device configuration profiles - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/fundamentals/deploy-configuration-step-4"
                }
            }
        ]
    }
}