GuideInformationAccess ControlIT

Choose single-app mode by who must be able to exit it

Should an iPad kiosk rely on an app-controlled exit or an administrator-controlled lock?

Integrated video surveillance and controlled entry at a modern commercial facility.
DSE visual intelligencePhysical securityGuide · 2 min read
Executive summary

What you need to know

Should an iPad kiosk rely on an app-controlled exit or an administrator-controlled lock?

Potentially affected

Use this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.

DSE recommendation

Write down the required exit authority before choosing the kiosk setting.

Source facts

Microsoft distinguishes Autonomous Single App Mode from App Lock. An app used with ASAM must support that mode, and only the app can leave it. App Lock can target any app, with administrators able to exit the lock. The deployment guide lists separate configuration options for these iOS and iPadOS experiences. Microsoft Learn.

Applicability

Use this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.

DSE recommendation

Write down the required exit authority before choosing the kiosk setting. Ask the application owner whether the workflow must control its own exit and obtain evidence of ASAM support if that is the proposed design. Alternatively, specify the authorized administrator’s procedure for an App Lock deployment. Keep the everyday operator’s actions and the maintenance operator’s actions distinct in the runbook. Do not discover the intended escape path for the first time during an unattended deployment.

Verification

On an approved spare device, run the actual application under the proposed mode and test both the expected restricted workflow and the authorized exit. Have the relevant app or device administrator demonstrate the maintenance path. Record any unsupported application behavior before expanding the assignment. If the required exit authority differs from the selected mode’s documented model, revise the design rather than teaching users an unreviewed workaround.

Official references

Microsoft Learn: Configure security, email, VPN, and Wi-Fi device configuration profiles.

Primary reference

Review the official source

Configure security, email, VPN, and Wi-Fi device configuration profiles - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE