Academy
Technical · Course T5

Lesson 4 of 5

Kiosk mode end to end

7 min read
In this lesson you'll learn to
  • Build a kiosk policy in the right order — apps before lockdown
  • Choose between single-app and multi-app kiosk and configure each
  • Set the unlock password and recover a device when it's lost

Kiosk mode is where UEM gets physical: point-of-sale terminals, digital signage, warehouse scanners, shared floor tablets. WeGuard replaces the Android home screen with its own launcher showing only what you allow — and everything about it is policy.

Order of operations

Kiosk setup rewards doing things in sequence:

  1. Start from a Kiosk policy — clone one via Create Policy. Kiosk-only sections (Single App Kiosk, Layouts, Safe Drive) exist only on this type.
  2. Add apps first in App Management: managed Play Store apps, private APK uploads, or system apps like Camera and Calculator. The kiosk can only show what the policy delivers.
  3. Enable the kiosk screen — the toggle lives in the General section. Once on, kiosk-specific options light up across the editor.
  4. Pick the mode. For multi-app, you're done: every policy app appears on the kiosk launcher. For single-app, open the Single App Kiosk section and select the one app to pin — the device boots straight into it with no way out for the user.
  5. Set the unlock password in Security. This is the step people regret skipping: it's how a technician exits kiosk mode in the field. Optionally require a password to interact with the kiosk screen itself.

Lost the password? It's policy data, not device data — update it in the editor, save, force-sync the device, and use the new one. No factory reset required.

Making it look intentional

The difference between a lockdown and a product experience is the customization pass, mostly in General:

  • Custom status bar — show a WeGuard-drawn status bar with only the icons you choose (Wi-Fi, battery, time…), or hide the bar entirely for signage.
  • Always Screen On — mandatory for unattended displays.
  • Home button off — keeps single-app devices in the app.
  • Disable the default Wi-Fi screen — closes the classic kiosk escape hatch.

Then Layouts arranges the launcher grid per screen size — rows, columns, and app placement — so a 5-inch scanner and a 13-inch showroom tablet each look deliberate. Branding adds wallpaper and boot logo; Admin Lock customizes the screen users see when an admin locks the device remotely.

Variants worth knowing

Samsung, LG, and Huawei kiosk variants expose OEM extras on the same flow, and Windows has its own Kiosk policy type for single-purpose PCs. The pitch is identical everywhere: the device stops being a general-purpose computer and becomes an appliance your customer's brand lives on.

After save and assign, the device syncs and the launcher takes over within minutes. If it doesn't: confirm the policy type is actually Kiosk, the kiosk screen toggle is on, and force-sync from the device's Ops tab — a stubborn device sometimes wants one reboot.

Knowledge check
1. What should you configure before enabling the kiosk screen toggle?
2. A technician is locked out of a kiosk device and the unlock password is lost. What's the recovery?
3. Single-app kiosk vs multi-app kiosk — what's the difference?