# Android Kiosk **Last Updated On**: 15 Jun 2026 **53 minutes read** With POS devices finding an exponential level of usage, the need to convert mobile devices to single-purpose devices is on the rise. But locking the devices to a single app is an arduous task for admins, as they need to configure these devices to ensure no other apps are installed and users do not navigate away from the locked app. Furthermore, it is difficult to manually manage and restrict the settings on each of these devices. POS devices are usually at critical points in an organization and any user modifications to the settings may lead to device downtime and loss of productivity. With MDM's Kiosk, locking down the devices to a **single app** and **pre-configuring the settings** over-the-air becomes a breeze. Another advantage is that Endpoint Central MDM Kiosk Mode allows you to provision **multiple apps under Kiosk**. Once configured, you can ensure these settings cannot be modified by the users. Additionally, you can let the users configure basic settings through Custom Settings app. Kiosk is supported for all devices. However, **Non-Samsung devices running 5.0 or above should be provisioned as [Device Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Device_Owner).** You need to enable Usage Access Permission when prompted on the device to enable or disable some of the Kiosk features like status bar, task manager or custom settings app. The advantage of Kiosk is that all types of notification services such as the edge notification window, available in Samsung devices, get restricted by default, ensuring users cannot navigate away from the app(s) provisioned under Kiosk. > **Note** > It is better to have only one Kiosk profile associated per device/group. When you associate two Kiosk profiles to the same device/group, the profile that is applied at last gets associated. To avoid confusion, it is recommended not to associate a new Kiosk profile when there is a Kiosk profile already associated. If you want to make modifications, remove the existing profile and associate a new profile or modify the existing profile. Similarly do not combine other profiles with Kiosk since every time the other profiles are modified and updated, Kiosk profile will be re-applied to the devices. You need to enable Usage Access Permission when prompted on the device to enable or disable some of the Kiosk features like status bar, task manager or custom settings app. ## Provisioning app(s) under Kiosk - You can provision apps already present in any one of the managed devices or [added to the App Repository](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_creating_app_repository.html). This can include pre-installed apps, store apps and enterprise apps. - In case the app provisioned under Kiosk is not available on the device, **the app gets automatically distributed and installed on the device**. The app distribution status is shown when viewing the device individually or in a group, in the **Device Mgmt** view. - In case of Store apps, these apps can be manually updated by the device user in case App Store is provisioned as an app in Kiosk. Otherwise you need to [update the app via MDM](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_app_management.html#Automating_App_Updates). - In case of enterprise apps, you need to [update the latest version of the source file (.apk) to the App Repository](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_multi_app_version_management.html#updating_android_enterprise_apps) and then update the app on the devices. - If silent installation isn't supported, the apps get distributed to the App Catalog, from where the user needs to install it. - If a [profile is updated and then re-distributed](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_creating_profiles.html#modify_profile), the version of the enterprise app initially used during profile creation is one that gets distributed even if there's an updated version available in the App Repository. In case of Store apps, the latest version is distributed. The updated enterprise app needs to be separately distributed as [explained here](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_app_management.html#app_update_dist). - ME MDM app requires data access permission for the Kiosk to perform certain functionalities like enabling status bar and notification bar, task manager/recent buttons, launch a specific app after idle time and enabling mobile data, bluetooth etc in custom settings. - Apps pinned to the Home screen cannot be uninstalled by users, ensuring that essential business apps remain on the device. ## Choosing the Launcher For devices in Multi-app Kiosk, the launcher to be used on the devices can be configured. Choosing **MDM launcher**, permits the **Custom Settings app** and **Device restrictions** to be configured. Along with that, the **Default app** can be configured under **Advanced settings**. The Default app will be automatically launched on the device, if inactive for the specified time duration. Configuring these settings ensures **granular control** over the device which cannot be achieved using Device launcher. The Device launcher does not support advanced Kiosk settings. ## Custom Settings App In case of Kiosk provisioned devices, users in general cannot view/modify basic settings such as Brightness, Wi-Fi etc., as the screen gets locked to provisioned apps. Custom Settings app, as the name suggests, if configured allows the users to modify these basic settings on Multi-app as well as on Single-app Kiosk. **The advantage of this app is that you can configure basic settings irrespective of the status bar restriction.** You can also configure [Custom Settings for Single-app Kiosk](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-basic-settings-kiosk-enterprise-app.html). ## Home Screen Layout Customization Home Screen Layout Customization lets you organize apps on the Home screen in multi-app Kiosk provisioned devices. You can add frequently used apps to the Dock and pin these apps to the Home screen even when user swipes across various pages. Apps pinned to the Home screen cannot be uninstalled by the users ensuring that the business requisite apps are always present on the device. You can add pages and folders to the Home screen, modify font color of texts displayed on the Home screen, thus improving user experience on the device. - You can set up a custom kiosk wallpaper by configuring a [Wallpaper](https://www.manageengine.com/mobile-device-management/help/profile_management/android/android_wallpaper.html) profile along with the same kiosk profile. - To display device details such as Username, Serial Number etc., on the device lock screen for easy identification, you can use [Asset Tagging](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_asset_tagging.html). In case you've configured wallpaper in the Asset Tag profile, it takes precedence over the wallpaper profile. - Only web shortcuts added in the Kiosk profile can be customized to desired position. Web shortcuts added from other profiles will be listed after the ones configured in Kiosk profile. - If a web shortcut is added in home screen layout, it will directly be displayed in the kiosk else if it is added in kiosk without a screen layout it will be displayed inside a folder. Watch this [short video](https://www.youtube.com/watch?v=675QflMIC_E") to learn how you can customize your Android Kiosk device's home screen. ## Profile Description **Only devices running Android 5.0 or above can be provisioned as [Device Owner](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Device_Owner).** | FEATURE | DESCRIPTION | KNOX-ENABLED SAMSUNG | NON-SAMSUNG LEGACY | NON-SAMSUNG PROFILE OWNER | NON-SAMSUNG DEVICE OWNER | |---|---|---|---|---|---| | Configure | Single-app Kiosk type locks down the device to display only a single app. Multi-app Kiosk type locks down the device to display only a specific set of apps displayed on the Home screen. | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | | Launcher type (Multi-app only) | Choose the launcher for Kiosk. MDM launcher allows granular control not possible with Device launcher. | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ### DEVICE RESTRICTIONS | FEATURE | DESCRIPTION | KNOX-ENABLED SAMSUNG | NON-SAMSUNG LEGACY | NON-SAMSUNG PROFILE OWNER | NON-SAMSUNG DEVICE OWNER | |---|---|---|---|---|---| | Task Manager | Prevents access to Task Manager and exiting Kiosk. Recommended to restrict. | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | | Status Bar | Restricts viewing battery, notifications, network details. | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ![failured](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/failured.webp) | ![success](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/success.webp) | ## Enabling Phone Calls in Kiosk Mode To enable phone calls in kiosk mode, add the following system applications to your kiosk profile's allowed apps or Hidden app list: **For Android devices:** The required apps can be added from **com.android.server.telecom** and **com.android.dialer**. The actual package name of the dialer app may vary depending on the device manufacturer. It can be identified from the MDM console by navigating to **Inventory > Apps > Devices**, selecting the device, and searching for the dialer app. **For Samsung devices:** Add: - `com.android.server.telecom` - `com.samsung.android.incallui` - `com.samsung.android.dialer` ## How to Add an Apps to the Kiosk Profile? To configure apps in the Kiosk profile, open the profile and select the required apps from the **Allowed Apps** and **Hidden Apps** dropdown menus. If the desired app is not listed: **If you have the APK file:** Upload it to the [App Repository](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_creating_app_repository.html#android_enterprise_apps). Once uploaded, it will appear in the **Allowed Apps** list. **If you do not have the APK file but know the package name:** Navigate to **Inventory → Apps → Add New App**, select **Android**, and enter the **bundle identifier (package name)** and app name. The app will then be available in both **Allowed Apps** and **Background Apps** lists. > **Note** > To find any additional App Name and Bundle identifier of an existing application in the managed device, navigate to Inventory → Apps → Devices in the MDM Console. Select the device and fetch the App Name & bundle Identifier. ## Managing Kiosk Profile: Pause and Resume MDM lets you pause Kiosk in three different ways. ![An Android device deployed using MDM under Kiosk mode](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/top_screen.webp) ![Using password to pause or temporarily exit out of MDM Kiosk mode on Android](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/revoke_admin_passwordprompt.webp) ### 1. Pause Kiosk Mode **Method 1: Using Inventory Action (MDM console)** 1. Navigate to the **Inventory tab** and select the device. 2. Click **Actions** and choose **Pause Kiosk**. 3. Provide a reason. 4. Choose resume method: - Manual resume from server - Automatic resume after time frame 5. Click OK. **Method 2: Using Pause Kiosk Passcode (On-Device)** Exit kiosk mode using the configured **Pause Kiosk Password**. If no passcode is configured, generate a **time-bound passcode**: - Navigate to **MDM Console > Inventory > Device > Device Access Recovery Key > Generate Now** - Choose **Pause Kiosk** - Use generated passcode **Enter passcode on device:** - If ME MDM app not allowed: Press **Home button 4 times consecutively** - If ME MDM app allowed: Open **ME MDM > Settings > Exit Kiosk** - If Home button restricted: Long-press **Volume Up + Volume Down 5 times consecutively**, then exit via ME MDM app **Method 3: Using Remote Chat Commands** Use: - `/EXIT-KIOSK` - `/ENTER-KIOSK` Learn more in the [Remote Troubleshooting guide](https://www.manageengine.com/mobile-device-management/help/asset_management/mdm_remote_troubleshoot_android.html#remote_commands). ### 2. Resume Kiosk Mode **Method 1:** Inventory → Device → Actions → Resume Kiosk **Method 2:** Tap resume notification on device **Method 3:** ME MDM app → Settings → Resume Kiosk Mode ## Troubleshooting Tips 1. **Missing settings prompt?** Ensure Settings app is allowed in kiosk profile. 2. **Buttons not working?** If passcode exists and "Unlock device without passcode" is allowed, restart may fail. - Remove passcode via [Inventory Actions](https://www.manageengine.com/mobile-device-management/help/security_management/mdm_security_management.html#passcode) - Or restrict unlock without passcode 3. **Device loses internet?** Recover device as [explained here](https://www.manageengine.com/mobile-device-management/how-to/mdm-recover-device-from-kiosk-mode.html). 4. **Time-bound passcode not working?** Ensure device time matches server time. 5. **Physical keyboard issues?** Enable on-screen keyboard via Custom Settings → Keyboard Settings. 6. **Allow Play Store in Multi-App Kiosk?** - Remove existing Kiosk profile - Set "Users can install only approved apps" to **No** - Add Play Store to allowed apps - Redistribute profile ## FAQs ### 1. How do I exit kiosk mode on a managed Android device? **Method 1 — Remote:** Device Mgmt → Groups & Devices → Actions → Pause Kiosk **Method 2 — On-site:** Use exit kiosk password from profile or inventory. ### 2. Why does the screen go black with an error when exiting kiosk mode? Some devices apply launcher switch with delay, causing temporary black screen. > **Note** > This behavior is device dependent. ### 3. Why is the Kiosk exit password rejected on new Zebra devices after MDM upgrade? Older versions used revoke admin password. After upgrade, device-specific recovery workflow is used. Generate correct key via: **Inventory → Device → Access Recovery Key** > **Note** > Generated key is device-specific.