Last updated: July 24, 2026
When a Kiosk-provisioned device loses contact with the MDM server, Kiosk mode can't be revoked from the console and must be removed manually. For iOS devices originally enrolled via Apple Configurator, connect the device to the trusted Mac, then remove and delete the MDM profile; devices with connection-restricting profiles must instead be reset via Recovery Mode. Android devices can be managed using the Kiosk profile's pause/resume options.
Kiosk mode is an advanced security feature which lets the IT Administrator lock down managed devices to run a specific app or a set of preselected apps. Kiosk mode ensures users cannot modify device settings, access other features or apps present in the device, besides the one(s) allowed by the IT Administrator. Kiosk mode can be beneficial for single purpose devices such as self check-in kiosks at airports; point-of-sale (POS) terminals at self service restaurants or supermarkets; digital signage used for advertising, etc. In each of these cases, the administration would not want users to exit the designated app(s). To learn more about provisioning managed devices in Kiosk mode, refer the following documents.
At times, it becomes an issue when devices provisioned in Kiosk mode loses contact with the MDM server. This can happen because of various reasons such as faulty internet connections, incorrect wifi configurations, and much more. Since there is no contact with the MDM server, Kiosk mode cannot be revoked from the devices using the server. However, there are OS specific methods on how to get devices out of Kiosk Mode manually.
Follow the steps given below to remove an iOS device from Kiosk mode:
NOTE: This method can be used only if the device was enrolled using Apple Configurator, since the device has already enabled trust for that machine.
Once the profile is removed, the device will be unmanaged while retaining the data present in it. You can re-enroll the device using either self enrollment or invites to manage the device with supervision.
NOTE: In case you have applied profiles on the device that restrict it from connecting to other devices, the above mentioned method cannot be used to revoke Kiosk mode. The device must be reset by putting it in Recovery Mode.
For Managing Kiosk Profile including Pausing and Resuming kiosk mode on managed devices, refer to our Manage Kiosk Profile guide for detailed information.
If further assistance is required, you can contact mdm-support@manageengine.com for MDM On-premises and mdmcloud-support@manageengine.com for MDM Cloud.
If the device was originally enrolled using Apple Configurator, connect it to the trusted Mac via USB, open Apple Configurator, Control-click the device, hover over Remove, select Profiles, and delete the MDM profile - this unmanages the device while keeping its data, so it can be re-enrolled afterward.
In that case, the Apple Configurator removal method won't work, and the device must instead be reset by putting it into Recovery Mode.
Use the pause and resume options in the Manage Kiosk Profile section of the console to control Kiosk mode on managed Android devices, rather than removing the device from management.
Contact mdm-support@manageengine.com for MDM On-Premises devices, or mdmcloud-support@manageengine.com for MDM Cloud devices, for further assistance.