# Kiosk With POS devices finding an exponential level of usage, the need to convert mobile devices to single-purpose devices is on the rise. But locking the devices to a single app is an arduous task for admins, as they need to configure these devices to ensure no other apps are installed and users do not navigate away from the locked app. Furthermore, it is difficult to manually manage and restrict the settings on each of these devices. POS devices are usually at critical points in an organization and any user modifications to the settings may lead to device downtime and loss of productivity. With MDM's Kiosk, locking down the devices to a **single app** and **pre-configuring the settings** over-the-air becomes a breeze. Another advantage is that ManageEngine MDM Kiosk Mode allows you to provision **multiple apps under Kiosk**. Once configured, you can ensure these settings cannot be modified by the users. Additionally, you can let the users configure basic settings through Custom Settings app. Kiosk is supported for all devices. However, **Non-Samsung devices running 5.0 or above should be provisioned as [Device Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Device_Owner).** **Note:** 1. You need to enable Usage Access Permission when prompted on the device to enable or disable some of the Kiosk features like status bar, task manager or custom settings app. 2. The advantage of Kiosk is that all types of notification services such as the edge notification window, available in Samsung devices, get restricted by default, ensuring users cannot navigate away from the app(s) provisioned under Kiosk. 3. It is better to have only one Kiosk profile associated per device/group. When you associate two Kiosk profiles to the same device/group, the profile that is applied at last gets associated. To avoid confusion, it is recommended not to associate a new Kiosk profile when there is a Kiosk profile already associated. If you want to make modifications, remove the existing profile and associate a new profile or modify the existing profile. Similarly, do not combine other profiles with Kiosk since every time the other profiles are modified and updated, the Kiosk profile will be re-applied to the devices. ## Provisioning app(s) under Kiosk - You can provision apps already present in any one of the managed devices or [added to the App Repository](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_creating_app_repository.html). This can include pre-installed apps, store apps and enterprise apps. - In case the app provisioned under Kiosk is not available on the device, **the app gets automatically distributed and installed on the device**. The app distribution status is shown when viewing the device individually or in a group, in the **Device Mgmt** view. - In case of Store apps, these apps can be manually updated by the device user in case App Store is provisioned as an app in Kiosk. Otherwise, you need to [update the app via MDM](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_app_management.html#Automating_App_Updates). - In case of enterprise apps, you need to [update the latest version of the source file (.apk) to the App Repository](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_multi_app_version_management.html#updating_android_enterprise_apps) and then update the app on the devices. - If silent installation isn't supported, the apps get distributed to the App Catalog, from where the user needs to install it. - If a [profile is updated and then re-distributed](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_creating_profiles.html#modify_profile), the version of the enterprise app initially used during profile creation is the one that gets distributed even if there's an updated version available in the App Repository. In case of Store apps, the latest version is distributed. The updated enterprise app needs to be separately distributed as [explained here](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_app_management.html#app_update_dist). - ME MDM app requires data access permission for the Kiosk to perform certain functionalities like enabling status bar and notification bar, task manager/recent buttons, launching a specific app after idle time and enabling mobile data, bluetooth etc. in custom settings. - Apps pinned to the Home screen cannot be uninstalled by users, ensuring that essential business apps remain on the device. ## Choosing the Launcher For devices in Multi-app Kiosk, the launcher to be used on the devices can be configured. Choosing **MDM launcher** permits the **Custom Settings app** and **Device restrictions** to be configured. Along with that, the **Default app** can be configured under **Advanced settings**. The Default app will be automatically launched on the device, if inactive for the specified time duration. Configuring these settings ensures **granular control** over the device, which cannot be achieved using Device launcher. The Device launcher does not support advanced Kiosk settings. ## Custom Settings App In case of Kiosk provisioned devices, users in general cannot view/modify basic settings such as Brightness, Wi-Fi etc., as the screen gets locked to provisioned apps. Custom Settings app, as the name suggests, if configured allows the users to modify these basic settings on Multi-app as well as on Single-app Kiosk. **The advantage of this app is that you can configure basic settings irrespective of the status bar restriction.** You can also configure [Custom Settings for Single-app Kiosk](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-basic-settings-kiosk-enterprise-app.html). ## Home Screen Layout Customization Home Screen Layout Customization lets you organize apps on the Home screen in multi-app Kiosk provisioned devices. You can add frequently used apps to the Dock and pin these apps to the Home screen even when the user swipes across various pages. Apps pinned to the Home screen cannot be uninstalled by the users, ensuring that the business requisite apps are always present on the device. You can add pages and folders to the Home screen, modify font color of texts displayed on the Home screen, thus improving user experience on the device. - You can set up a custom kiosk wallpaper by configuring [Wallpaper](https://www.manageengine.com/mobile-device-management/help/profile_management/android/android_wallpaper.html) profile along with the same kiosk profile. - To display device details such as Username, Serial Number etc., on the device lock screen for easy identification, you can use [Asset Tagging](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_asset_tagging.html). In case you've configured wallpaper in the Asset Tag profile, it takes precedence over the wallpaper profile. - Only web shortcuts added in the Kiosk profile can be customized to the desired position. Web shortcuts added from other profiles will be listed after the ones configured in the Kiosk profile. - If a web shortcut is added in Home screen layout, it will directly be displayed in the kiosk; else if it is added in kiosk without a screen layout, it will be displayed inside a folder. Watch this [short video](https://www.youtube.com/watch?v=675QflMIC_E) to learn how you can customize your Android Kiosk device's home screen. ## Profile Description **Only devices running Android 5.0 or above can be provisioned as [Device Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Device_Owner).** *(The detailed feature compatibility tables for Knox-enabled Samsung, Legacy, Profile Owner, and Device Owner modes — including Device Restrictions, Custom Settings App options, Advanced Settings, and Edit Screen Layout — are available in the original documentation and should be referred to for complete platform-specific support details.)* ## Enabling Phone Calls in Kiosk Mode To enable phone calls in kiosk mode, add the following system applications to your kiosk profile's allowed apps or Hidden app list: ### For Android devices The required apps can be added from **com.android.server.telecom** and **com.android.dialer**. However, the actual package name of the dialer app may vary depending on the device manufacturer. If the exact package name is not known, it can be identified from the MDM console by navigating to **Inventory > Apps > Devices**, selecting the specific device, and searching for the dialer app by name. The console will display the exact bundle identifier (package name) of the dialer app for that device. **Note:** Excluding the Dialer and Contacts applications from the kiosk profile does not completely prevent access to them. The Dialer may still open through Android intents — for instance, when a website or app contains a phone number in the `tel:` format, tapping it can launch the Dialer, which may in turn expose Contacts. This behavior is governed by the Android framework's intent handling and cannot be restricted by the MDM application. ### For Samsung devices Add the following packages: - `com.android.server.telecom` - `com.samsung.android.incallui` - `com.samsung.android.dialer` ## How to Add an Apps to the Kiosk Profile? To configure apps in the Kiosk profile: 1. Open the profile and select the required apps from the **Allowed Apps** and **Hidden Apps** dropdown menus. 2. If the desired app is not listed: - **If you have the APK file:** Upload it to the [App Repository](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_creating_app_repository.html#android_enterprise_apps). Once uploaded, the app will automatically appear in the **Allowed Apps** list within the Kiosk profile. - **If you do not have the APK file but know the package name:** Navigate to **Inventory > Apps > Add New App**, select **Android** as the platform, and enter the **bundle identifier (package name)** along with the app name. After adding, the app will be available in both the **Allowed Apps** and **Background Apps** lists in the Kiosk profile. **Note:** To find the App Name and Bundle Identifier of an existing application on a managed device, navigate to **Inventory > Apps > Devices**, select the device, and fetch the App Name & Bundle Identifier. ## Managing Kiosk Profile: Pause and Resume While managing devices under Kiosk, there might be a need to pause Kiosk temporarily for troubleshooting or maintenance. ![An Android device deployed using MDM under Kiosk mode](https://www.manageengine.com/mobile-device-management/help/images/top_screen.png) ![Using password to pause or temporarily exit out of MDM Kiosk mode on Android](https://www.manageengine.com/mobile-device-management/help/images/revoke_admin_passwordprompt.jpg) ### 1. Pause Kiosk Mode #### Method 1: Using Inventory Action (MDM console) 1. Navigate to the **Inventory** tab and select the device. 2. Click on **Actions** and choose **Pause Kiosk**. 3. Provide a reason. 4. Choose how to resume: - Only when initiated from the server. - Set a time frame for automatic resume. 5. Click OK. #### Method 2: Using Pause Kiosk Passcode (On-Device) Use the passcode configured under **Pause Kiosk Password** in the Kiosk profile. If no passcode is configured, generate a **time-bound passcode**: 1. Navigate to **MDM Console > Inventory > Device Details > Device Access Recovery Key**. 2. Click **Generate Now** and choose **Pause Kiosk**. 3. A randomly generated time-bound passcode will be displayed. **Entering the passcode:** - If ME MDM app is not allowed: - Press the **Home** button 4 times consecutively. - If ME MDM app is allowed: - Open **ME MDM app > Settings > Exit Kiosk**. - If ME MDM app is not allowed and Home button is restricted: - Long-press **Volume Up + Volume Down** keys 5 times consecutively. - Launch ME MDM app and navigate to **Settings > Exit Kiosk**. #### Method 3: Using Remote Chat Commands You can use [Remote Troubleshoot](https://www.manageengine.com/mobile-device-management/help/asset_management/mdm_remote_troubleshoot_android.html) and send chat commands: - `/EXIT-KIOSK` — to pause Kiosk - `/ENTER-KIOSK` — to resume Kiosk More details: [Chat commands in Remote Troubleshooting guide](https://www.manageengine.com/mobile-device-management/help/asset_management/mdm_remote_troubleshoot_android.html#remote_commands). ### 2. Resume Kiosk Mode - **From MDM Console:** Inventory > Device Details > Actions > Resume Kiosk. - **From Notification:** Tap the notification displayed on the device. - **From ME MDM App:** Open ME MDM app > Settings > Resume Kiosk Mode. ## Troubleshooting Tips 1. **Missing app or settings prompts in kiosk mode** - Ensure the Settings app is allowed. - Identify package names using tools like [Current Activity](https://play.google.com/store/apps/details?id=io.github.ratul.topactivity&pli=1). 2. **Buttons not working (Home, Power, etc.)** - Remove passcode via [Inventory Actions](https://www.manageengine.com/mobile-device-management/help/security_management/mdm_security_management.html#passcode) or restrict "Unlock device without passcode". 3. **Device loses internet connectivity** - Recover as [explained here](https://www.manageengine.com/mobile-device-management/how-to/mdm-recover-device-from-kiosk-mode.html). 4. **Time-bound passcode not working** - Ensure device time matches server time. 5. **Physical keyboard configuration** - Enable on-screen keyboard from **Custom Settings > Keyboard Settings**. 6. **Allow Play Store in Multi-App Kiosk** - Remove Kiosk profile. - Set "Users can install only approved apps" to No. - Add Play Store and redistribute profile. 7. **Auto-launch specific app** - Use Single App Kiosk, or - Configure Default App in Multi-App Kiosk with inactivity timeout. 8. **Automatic launch after QR enrollment** - Associate Kiosk profile to device group. - Configure QR enrollment with auto-assignment. 9. **App relaunch after restart** - Expected behavior due to re-application of kiosk configuration. ## FAQs ### 1. How do I exit kiosk mode on a managed Android device? - **Remote:** Device Mgmt > Groups & Devices > Actions > Pause Kiosk. - **On-site:** Use configured exit password or device inventory password retrieval. ### 2. Why does the screen go black when exiting kiosk mode? This may occur due to launcher handoff delay and is device dependent. ### 3. Why is the Kiosk exit password rejected on new Zebra devices after MDM upgrade? Generate a new device-specific key from **Inventory > Device Details > Access Recovery Key**. **Note:** The generated key is device-specific and must be used accordingly.