Kiosk Mode lets you lock a supervised iPhone or iPad to a single app, so the device can be dedicated to one purpose, such as a point-of-sale screen, a check-in tablet, an assessment device, or a digital display. You can lock a device permanently, so only an admin can release it, or let an approved app lock and unlock itself for session-based tasks. This guide walks you through setting up both.
Prerequisites
The device must be supervised, meaning it's enrolled through Automated Device Enrollment (ADE) and linked to your organization's Apple Business Manager account.
The device must be marked as a Kiosk Device under device type when it's set up for enrollment.
For Persistent Single App, the target app must already be installed on the device.
Kiosk Mode is available under both Apple iOS Kiosk Policies and Apple iPadOS Kiosk Policies.
What this guide covers
Setting up Kiosk enrollment - marking a device as a Kiosk Device during Automated Device Enrollment.
Setting up the Kiosk policy - configuring Persistent or Autonomous Single App mode.
Setting up Kiosk enrollment
Go to Settings and open your Client's Apple device configuration.
Under Automated Device Enrollment, go to Map devices.
Find the device in the list and set its Device Type to Kiosk Device.
Select Mark as ready for enrollment. The device picks up the kiosk enrollment profile the next time it checks in.
The Map Devices table also shows the requester, enrollment status, and enrolled date and time for each device, so you can track enrollment as it happens.
Setting up the Kiosk policy
There are two ways to lock a Kiosk device to an app, and which one you use depends on the use case.
Persistent Single App locks the device to one app permanently. Only an admin can release it by removing or changing the policy. Use this for devices that are permanently dedicated to one purpose, like a point-of-sale screen, a check-in tablet, or digital signage.
Autonomous Single App lets the admin approve a set of apps that can lock and unlock the device. Assuming the app has that capability built in by its developer, the user can trigger an action from within the app that locks or unlocks it, without an admin stepping in each time. For example, an app like Slack could lock the device into a single dedicated channel view for a shift-based team, or a scheduling app could lock into check-in mode during business hours and release afterward.
Note : Autonomous Single App only works if the app itself has Apple's autonomous kiosk capability built in by its developer. Approving an app in SuperOps gives it permission to use this mode. It doesn't add the capability if the app doesn't already support it. Check with the app's own developer or documentation to confirm before relying on it for a live deployment.
Persistent Single App
Use this mode when you want the device permanently locked to one app, with only an admin able to release it.
Installing apps for kiosk use
Before you lock the device into an App, the App must already be installed on the device. To set this up, Navigate to Settings->Policy management-> Apple iOS or iPad Kiosk policies and select "App management ".
Apps for kiosk mode can come from the App Store or from your VPP-licensed catalog. Under App Management, you can also set:
A schedule for software installation: deploy on a recurring cadence (hourly, daily, weekly, or monthly), starting from a chosen date, ending never or on a set date.
Whether to install the public version of an app if a VPP license isn't found for a site.
Whether to install public apps even if Apps and Books isn't configured for a site.
Note: This step applies only to Persistent Single App. Since the device is locked to the app immediately after the configuration is saved, the app must already be installed on the device.
For Autonomous Single App, the device is locked only when the app initiates it, so the app does not need to be installed beforehand.
Setting up a Persistent Single App
Go to the device's policy and open Kiosk Mode.
Select Persistent Single App.
Choose the app to lock the device to.
Turn on any Interaction, Power, or Accessibility controls you want in place while the device is locked. See below for what each one does.
Select Save. The device locks to the selected app.
To change the locked app later, select Replace. You don't need to remove and reapply the policy.
What the controls do
Once you've chosen the app to lock the device to, you have control over a few more things that shape what the person using the kiosk can and can't do:
Interaction controls — what physical actions are allowed on the device, like touch, screen rotation, volume buttons, and the ringer switch
Power controls — how the device behaves around sleep and auto-lock while it's in kiosk mode
Accessibility controls — which accessibility features (VoiceOver, Zoom, AssistiveTouch, and others) are available, and whether the end user can toggle them themselves
Autonomous Single App
Use this mode for session-based tasks, like a timed assessment, where the app itself should control when it locks and unlocks, not an admin.
Go to the device's policy and open Kiosk Mode.
Select Autonomous Single App.
Select Add from Bundle/Software to open the software picker. Choose apps from Apps and Books or the Public App Store tab, then select Add.
Select Save. Approved apps can now enter and exit kiosk mode using their own in-app controls.
Alongside the software list, there's a separate App Bundle ID field on this screen. Use it to add an app directly by its bundle identifier, if it isn't in your software inventory yet.
Working with Kiosk devices
Similar to fully managed devices, you'll be able to manage the controls of Kiosk devices the same way. For more on that, see How to Manage iOS and iPadOS devices.
FAQs
Can I lock a device to more than one app at once? No. Both Persistent and Autonomous Single App lock to one app at a time.
What apps can I use for Persistent Single App? Any app already installed on the device, from the App Store or your VPP catalog. Alternatively, you can also choose an App from the App store.
Do I need to install the app before locking to it? For Persistent Single App, yes. Install the app under App Management first, then lock the device to it. Autonomous Single App doesn't have this requirement, since the app manages its own lock and unlock.
How do I unlock a device from Persistent Single App? Remove or disable the Kiosk Mode policy to unlock the device from the mode.
Can I change the locked app without removing the policy? Yes. Select Replace on the Persistent Single App screen. You don't need to remove and reapply the policy.
Who decides which apps can use Autonomous Single App? You can choose whichever app you want for Autonomous Single App, as long as it's in your inventory added through Apps and Books (or the Public App Store), and the app itself supports Apple's autonomous kiosk capability.
Does approving an app for Autonomous Single App guarantee it will work? No. Approving an app here only gives it permission to use Autonomous Single App. It doesn't check whether the app actually supports Apple's autonomous kiosk capability. That depends on the app's own developer having built it in, not on SuperOps.
What is the App Bundle ID field for? It lets you add an app directly by its bundle identifier, useful if it isn't already in your software inventory. Its on-screen description currently matches Persistent Single App wording, so check with product on exactly how an app added here behaves before relying on it.
Does Kiosk Mode work on both iPhone and iPad? Yes. It's available under both Apple iOS Kiosk Policies and Apple iPadOS Kiosk Policies. It isn't available on Mac.
How do I mark a device as a Kiosk device? This depends on your policy structure. On Basic hierarchy, you mark the device type as Kiosk. On Advanced hierarchy, you mark the device category as Kiosk instead. Either way, the correct kiosk policy applies based on that selection.
Can I schedule when kiosk apps get installed or updated? Yes. Under App Management, set a deployment cadence (hourly, daily, weekly, or monthly), a start date, and an end date, or leave it running with no end date.

