# Choose single-app mode by who must be able to exit it

> Should an iPad kiosk rely on an app-controlled exit or an administrator-controlled lock?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:59+00:00
- Modified: 2026-09-10T01:20:46+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Access Control, IT
- Reading time: 2 minutes

## What you need to know

Should an iPad kiosk rely on an app-controlled exit or an administrator-controlled lock?

## Potentially affected

Use this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.

## DSE recommendation

Write down the required exit authority before choosing the kiosk setting.

## Article

## Source facts

Microsoft distinguishes Autonomous Single App Mode from App Lock. An app used with ASAM must support that mode, and only the app can leave it. App Lock can target any app, with administrators able to exit the lock. The deployment guide lists separate configuration options for these iOS and iPadOS experiences. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/fundamentals/deploy-configuration-step-4).

## Applicability

Use this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.

## DSE recommendation

Write down the required exit authority before choosing the kiosk setting. Ask the application owner whether the workflow must control its own exit and obtain evidence of ASAM support if that is the proposed design. Alternatively, specify the authorized administrator’s procedure for an App Lock deployment. Keep the everyday operator’s actions and the maintenance operator’s actions distinct in the runbook. Do not discover the intended escape path for the first time during an unattended deployment.

## Verification

On an approved spare device, run the actual application under the proposed mode and test both the expected restricted workflow and the authorized exit. Have the relevant app or device administrator demonstrate the maintenance path. Record any unsupported application behavior before expanding the assignment. If the required exit authority differs from the selected mode’s documented model, revise the design rather than teaching users an unreviewed workaround.

## Official references

[Microsoft Learn: Configure security, email, VPN, and Wi-Fi device configuration profiles](https://learn.microsoft.com/en-us/intune/fundamentals/deploy-configuration-step-4).

## Primary reference

- Name: Configure security, email, VPN, and Wi-Fi device configuration profiles - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/fundamentals/deploy-configuration-step-4
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose single-app mode by who must be able to exit it,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-237-choose-single-app-mode-by-who-must-be-able-to-exit-it/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
