What you need to know
Should an iPad kiosk rely on an app-controlled exit or an administrator-controlled lock?
Potentially affected
Use this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.
DSE recommendation
Write down the required exit authority before choosing the kiosk setting.
Source facts
Microsoft distinguishes Autonomous Single App Mode from App Lock. An app used with ASAM must support that mode, and only the app can leave it. App Lock can target any app, with administrators able to exit the lock. The deployment guide lists separate configuration options for these iOS and iPadOS experiences. Microsoft Learn.
Applicability
Use this design check for an Intune-managed iOS or iPadOS single-app device. Confirm the actual application, platform requirements and supported configuration before selecting a mode. Do not infer app support merely because the same app can run normally on the device.
DSE recommendation
Write down the required exit authority before choosing the kiosk setting. Ask the application owner whether the workflow must control its own exit and obtain evidence of ASAM support if that is the proposed design. Alternatively, specify the authorized administrator’s procedure for an App Lock deployment. Keep the everyday operator’s actions and the maintenance operator’s actions distinct in the runbook. Do not discover the intended escape path for the first time during an unattended deployment.
Verification
On an approved spare device, run the actual application under the proposed mode and test both the expected restricted workflow and the authorized exit. Have the relevant app or device administrator demonstrate the maintenance path. Record any unsupported application behavior before expanding the assignment. If the required exit authority differs from the selected mode’s documented model, revise the design rather than teaching users an unreviewed workaround.
Official references
Microsoft Learn: Configure security, email, VPN, and Wi-Fi device configuration profiles.
Review the official source
Configure security, email, VPN, and Wi-Fi device configuration profiles - Microsoft Intune | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE