mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-16 19:03:46 +00:00
final updates, hopefully
This commit is contained in:
@ -2,7 +2,7 @@
|
|||||||
title: Guidelines for choosing an app for assigned access (Windows 10/11)
|
title: Guidelines for choosing an app for assigned access (Windows 10/11)
|
||||||
description: The following guidelines may help you choose an appropriate Windows app for your assigned access experience.
|
description: The following guidelines may help you choose an appropriate Windows app for your assigned access experience.
|
||||||
keywords: ["kiosk", "lockdown", "assigned access"]
|
keywords: ["kiosk", "lockdown", "assigned access"]
|
||||||
ms.prod: w10
|
ms.prod: w10, w11
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
author: greg-lindsay
|
author: greg-lindsay
|
||||||
@ -56,7 +56,7 @@ In Windows client, you can install the **Kiosk Browser** app from Microsoft to u
|
|||||||
>Kiosk Browser cannot access intranet websites.
|
>Kiosk Browser cannot access intranet websites.
|
||||||
|
|
||||||
|
|
||||||
**Kiosk Browser** must be downloaded for offline licensing using Microsoft Store For Business. You can deploy **Kiosk Browser** to devices running Windows 10, version 1803 (Pro, Business, Enterprise, and Education) / Windows 11.
|
**Kiosk Browser** must be downloaded for offline licensing using Microsoft Store For Business. You can deploy **Kiosk Browser** to devices running Windows 10, version 1803 (Pro, Business, Enterprise, and Education) and Windows 11.
|
||||||
|
|
||||||
1. [Get **Kiosk Browser** in Microsoft Store for Business with offline license type.](/microsoft-store/acquire-apps-microsoft-store-for-business#acquire-apps)
|
1. [Get **Kiosk Browser** in Microsoft Store for Business with offline license type.](/microsoft-store/acquire-apps-microsoft-store-for-business#acquire-apps)
|
||||||
2. [Deploy **Kiosk Browser** to kiosk devices.](/microsoft-store/distribute-offline-apps)
|
2. [Deploy **Kiosk Browser** to kiosk devices.](/microsoft-store/distribute-offline-apps)
|
||||||
|
@ -0,0 +1,12 @@
|
|||||||
|
---
|
||||||
|
author: MandiOhlinger
|
||||||
|
ms.author: mandia
|
||||||
|
ms.date: 09/21/2021
|
||||||
|
ms.reviewer:
|
||||||
|
audience: itpro
|
||||||
|
manager: dansimp
|
||||||
|
ms.prod: w10
|
||||||
|
ms.topic: include
|
||||||
|
---
|
||||||
|
|
||||||
|
Currently, multi-app kiosk is only supported on Windows 10. It's not supported on Windows 11.
|
@ -6,7 +6,7 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
ms.author: greglin
|
ms.author: greglin
|
||||||
keywords: ["assigned access", "kiosk", "lockdown", "digital sign", "digital signage"]
|
keywords: ["assigned access", "kiosk", "lockdown", "digital sign", "digital signage"]
|
||||||
ms.prod: w10
|
ms.prod: w10, w11
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
author: greg-lindsay
|
author: greg-lindsay
|
||||||
@ -32,7 +32,7 @@ Topic | Description
|
|||||||
[Guidelines for choosing an app for assigned access (kiosk mode)](guidelines-for-assigned-access-app.md) | These guidelines will help you choose an appropriate Windows app for your assigned access experience.
|
[Guidelines for choosing an app for assigned access (kiosk mode)](guidelines-for-assigned-access-app.md) | These guidelines will help you choose an appropriate Windows app for your assigned access experience.
|
||||||
[Policies enforced on kiosk devices](kiosk-policies.md) | Learn about the policies enforced on a device when you configure it as a kiosk.
|
[Policies enforced on kiosk devices](kiosk-policies.md) | Learn about the policies enforced on a device when you configure it as a kiosk.
|
||||||
[Assigned access XML reference](kiosk-xml.md) | The XML and XSD for kiosk device configuration.
|
[Assigned access XML reference](kiosk-xml.md) | The XML and XSD for kiosk device configuration.
|
||||||
[Use AppLocker to create a Windows client kiosk](lock-down-windows-10-applocker.md) | Learn how to use AppLocker to configure a kiosk device running Windows 10 Enterprise or Windows 10 Education, version 1703 and earlier, so that users can only run a few specific apps.
|
[Use AppLocker to create a Windows client kiosk](lock-down-windows-10-applocker.md) | Learn how to use AppLocker to configure a Windows client kiosk device running Enterprise or Education so that users can only run a few specific apps.
|
||||||
[Use Shell Launcher to create a Windows client kiosk](kiosk-shelllauncher.md) | Using Shell Launcher, you can configure a kiosk device that runs a Windows application as the user interface.
|
[Use Shell Launcher to create a Windows client kiosk](kiosk-shelllauncher.md) | Using Shell Launcher, you can configure a kiosk device that runs a Windows application as the user interface.
|
||||||
[Use MDM Bridge WMI Provider to create a Windows client kiosk](kiosk-mdm-bridge.md) | Environments that use Windows Management Instrumentation (WMI) can use the MDM Bridge WMI Provider to configure the MDM_AssignedAccess class.
|
[Use MDM Bridge WMI Provider to create a Windows client kiosk](kiosk-mdm-bridge.md) | Environments that use Windows Management Instrumentation (WMI) can use the MDM Bridge WMI Provider to configure the MDM_AssignedAccess class.
|
||||||
[Troubleshoot kiosk mode issues](kiosk-troubleshoot.md) | Tips for troubleshooting multi-app kiosk configuration.
|
[Troubleshoot kiosk mode issues](kiosk-troubleshoot.md) | Tips for troubleshooting multi-app kiosk configuration.
|
||||||
|
@ -1,10 +1,10 @@
|
|||||||
---
|
---
|
||||||
title: Configure kiosks and digital signs on Windows desktop editions (Windows 10/11)
|
title: Configure kiosks and digital signs on Windows 10/11 desktop editions
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
ms.author: greglin
|
ms.author: greglin
|
||||||
description: In this article, learn about the methods for configuring kiosks and digital signs on Windows 10 or Windows 11 desktop editions.
|
description: In this article, learn about the methods for configuring kiosks and digital signs on Windows 10 or Windows 11 desktop editions.
|
||||||
ms.prod: w10
|
ms.prod: w10, w11
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -34,7 +34,7 @@ Some desktop devices in an enterprise serve a special purpose. For example, a PC
|
|||||||
- **A multi-app kiosk**: Runs one or more apps from the desktop. People using the kiosk see a customized Start that shows only the tiles for the apps that are allowed. With this approach, you can configure a locked-down experience for different account types.
|
- **A multi-app kiosk**: Runs one or more apps from the desktop. People using the kiosk see a customized Start that shows only the tiles for the apps that are allowed. With this approach, you can configure a locked-down experience for different account types.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Currently, multi-app kiosk is only supported on Windows 10. It's not supported on Windows 11.
|
> [!INCLUDE [Multi-app kiosk mode not supported on Windows 11](./includes/multi-app-kiosk-support-windows11.md)]
|
||||||
|
|
||||||
A multi-app kiosk is appropriate for devices that are shared by multiple people. When you configure a multi-app kiosk, [specific policies are enforced](kiosk-policies.md) that will affect **all** non-administrator users on the device.
|
A multi-app kiosk is appropriate for devices that are shared by multiple people. When you configure a multi-app kiosk, [specific policies are enforced](kiosk-policies.md) that will affect **all** non-administrator users on the device.
|
||||||
|
|
||||||
@ -72,8 +72,6 @@ There are several kiosk configuration methods that you can choose from, dependin
|
|||||||
>[!IMPORTANT]
|
>[!IMPORTANT]
|
||||||
>Single-app kiosk mode isn't supported over a remote desktop connection. Your kiosk users must sign in on the physical device that is set up as a kiosk.
|
>Single-app kiosk mode isn't supported over a remote desktop connection. Your kiosk users must sign in on the physical device that is set up as a kiosk.
|
||||||
|
|
||||||
<span id="uwp" />
|
|
||||||
|
|
||||||
## Methods for a single-app kiosk running a UWP app
|
## Methods for a single-app kiosk running a UWP app
|
||||||
|
|
||||||
You can use this method | For this edition | For this kiosk account type
|
You can use this method | For this edition | For this kiosk account type
|
||||||
@ -108,13 +106,13 @@ You can use this method | For this edition | For this kiosk account type
|
|||||||
|
|
||||||
Method | App type | Account type | Single-app kiosk | Multi-app kiosk
|
Method | App type | Account type | Single-app kiosk | Multi-app kiosk
|
||||||
--- | --- | --- | :---: | :---:
|
--- | --- | --- | :---: | :---:
|
||||||
[Assigned access in Settings](kiosk-single-app.md#local) | UWP | Local account | X |
|
[Assigned access in Settings](kiosk-single-app.md#local) | UWP | Local account | ✔️ |
|
||||||
[Assigned access cmdlets](kiosk-single-app.md#powershell) | UWP | Local account | X |
|
[Assigned access cmdlets](kiosk-single-app.md#powershell) | UWP | Local account | ✔️ |
|
||||||
[The kiosk wizard in Windows Configuration Designer](kiosk-single-app.md#wizard) | UWP, Windows desktop app | Local standard user, Active Directory, Azure AD | X |
|
[The kiosk wizard in Windows Configuration Designer](kiosk-single-app.md#wizard) | UWP, Windows desktop app | Local standard user, Active Directory, Azure AD | ✔️ |
|
||||||
[XML in a provisioning package](lock-down-windows-10-to-specific-apps.md) | UWP, Windows desktop app | Local standard user, Active Directory, Azure AD | X | X
|
[XML in a provisioning package](lock-down-windows-10-to-specific-apps.md) | UWP, Windows desktop app | Local standard user, Active Directory, Azure AD | ✔️ | ✔️
|
||||||
Microsoft Intune or other MDM [for full-screen single-app kiosk](kiosk-single-app.md#mdm) or [for multi-app kiosk with desktop](lock-down-windows-10-to-specific-apps.md) | UWP, Windows desktop app | Local standard user, Azure AD | X | X
|
Microsoft Intune or other MDM [for full-screen single-app kiosk](kiosk-single-app.md#mdm) or [for multi-app kiosk with desktop](lock-down-windows-10-to-specific-apps.md) | UWP, Windows desktop app | Local standard user, Azure AD | ✔️ | ✔️
|
||||||
[Shell Launcher](kiosk-shelllauncher.md) |Windows desktop app | Local standard user, Active Directory, Azure AD | X |
|
[Shell Launcher](kiosk-shelllauncher.md) |Windows desktop app | Local standard user, Active Directory, Azure AD | ✔️ |
|
||||||
[MDM Bridge WMI Provider](kiosk-mdm-bridge.md) | UWP, Windows desktop app | Local standard user, Active Directory, Azure AD | | X
|
[MDM Bridge WMI Provider](kiosk-mdm-bridge.md) | UWP, Windows desktop app | Local standard user, Active Directory, Azure AD | | ✔️
|
||||||
|
|
||||||
|
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
|
@ -1,12 +1,12 @@
|
|||||||
---
|
---
|
||||||
title: Prepare a device for kiosk configuration (Windows 10/11) | Microsoft Docs
|
title: Prepare a device for kiosk configuration on Windows 10/11 | Microsoft Docs
|
||||||
description: Learn how to prepare a device for kiosk configuration. Also, learn about the recommended kiosk configuration changes.
|
description: Learn how to prepare a device for kiosk configuration. Also, learn about the recommended kiosk configuration changes.
|
||||||
ms.assetid: 428680AE-A05F-43ED-BD59-088024D1BFCC
|
ms.assetid: 428680AE-A05F-43ED-BD59-088024D1BFCC
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
ms.author: greglin
|
ms.author: greglin
|
||||||
keywords: ["assigned access", "kiosk", "lockdown", "digital sign", "digital signage"]
|
keywords: ["assigned access", "kiosk", "lockdown", "digital sign", "digital signage"]
|
||||||
ms.prod: w10
|
ms.prod: w10, w11
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
author: greg-lindsay
|
author: greg-lindsay
|
||||||
|
@ -6,7 +6,7 @@ ms.reviewer:
|
|||||||
manager: dansimp
|
manager: dansimp
|
||||||
ms.author: greglin
|
ms.author: greglin
|
||||||
keywords: ["assigned access", "kiosk", "lockdown", "digital sign", "digital signage"]
|
keywords: ["assigned access", "kiosk", "lockdown", "digital sign", "digital signage"]
|
||||||
ms.prod: w10
|
ms.prod: w10, w11
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
author: greg-lindsay
|
author: greg-lindsay
|
||||||
@ -31,7 +31,7 @@ Using Shell Launcher, you can configure a device that runs an application as the
|
|||||||
>- [AppLocker](/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview) - Application control policies
|
>- [AppLocker](/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview) - Application control policies
|
||||||
>- [Mobile Device Management](/windows/client-management/mdm) - Enterprise management of device security policies
|
>- [Mobile Device Management](/windows/client-management/mdm) - Enterprise management of device security policies
|
||||||
|
|
||||||
You can apply a custom shell through Shell Launcher [by using PowerShell](#configure-a-custom-shell-using-powershell). In Windows 10 version 1803+ / Windows 11, you can also [use mobile device management (MDM)](#configure-a-custom-shell-in-mdm) to apply a custom shell through Shell Launcher.
|
You can apply a custom shell through Shell Launcher [by using PowerShell](#configure-a-custom-shell-using-powershell). Starting with Windows 10 version 1803+, you can also [use mobile device management (MDM)](#configure-a-custom-shell-in-mdm) to apply a custom shell through Shell Launcher.
|
||||||
|
|
||||||
|
|
||||||
## Differences between Shell Launcher v1 and Shell Launcher v2
|
## Differences between Shell Launcher v1 and Shell Launcher v2
|
||||||
|
@ -1,21 +1,21 @@
|
|||||||
---
|
---
|
||||||
title: Set up a single-app kiosk (Windows 10/11)
|
title: Set up a single-app kiosk on Windows 10/11
|
||||||
description: A single-use device is easy to set up in Windows 10 for desktop editions (Pro, Enterprise, and Education).
|
description: A single-use device is easy to set up in Windows 10 and Windows 11 for desktop editions (Pro, Enterprise, and Education).
|
||||||
ms.assetid: 428680AE-A05F-43ED-BD59-088024D1BFCC
|
ms.assetid: 428680AE-A05F-43ED-BD59-088024D1BFCC
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
ms.author: greglin
|
ms.author: greglin
|
||||||
keywords: ["assigned access", "kiosk", "lockdown", "digital sign", "digital signage"]
|
keywords: ["assigned access", "kiosk", "lockdown", "digital sign", "digital signage"]
|
||||||
ms.prod: w10
|
ms.prod: w10, w11
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
author: greg-lindsay
|
author: greg-lindsay
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
ms.date: 09/20/2021
|
ms.date: 09/21/2021
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
---
|
---
|
||||||
|
|
||||||
# Set up a single-app kiosk
|
# Set up a single-app kiosk on Windows 10/11
|
||||||
|
|
||||||
|
|
||||||
**Applies to**
|
**Applies to**
|
||||||
@ -34,12 +34,12 @@ A single-app kiosk uses the Assigned Access feature to run a single app above th
|
|||||||
|
|
||||||
You have several options for configuring your single-app kiosk.
|
You have several options for configuring your single-app kiosk.
|
||||||
|
|
||||||
| Method | Description |
|
| Option | Description |
|
||||||
| --- | --- |
|
| --- | --- |
|
||||||
| [Locally, in Settings](#local) | The **Set up a kiosk** (previously named **Set up assigned access**) option in **Settings** is a quick and easy method to set up a single device as a kiosk for a local standard user account. <br><br>This method is supported on Windows client Pro, Enterprise, and Education. |
|
| [Locally, in Settings](#local) | The **Set up a kiosk** (previously named **Set up assigned access**) option in **Settings** is a quick and easy method to set up a single device as a kiosk for a local standard user account. <br><br>This option is supported on: <br>- Windows 10 Pro, Enterprise, and Education<br>- Windows 11 |
|
||||||
| [PowerShell](#powershell) | You can use Windows PowerShell cmdlets to set up a single-app kiosk. First, you need to [create the user account](https://support.microsoft.com/help/4026923/windows-create-a-local-user-or-administrator-account-in-windows-10) on the device and install the kiosk app for that account.<br><br>This method is supported on Windows client Pro, Enterprise, and Education. |
|
| [PowerShell](#powershell) | You can use Windows PowerShell cmdlets to set up a single-app kiosk. First, you need to [create the user account](https://support.microsoft.com/help/4026923/windows-create-a-local-user-or-administrator-account-in-windows-10) on the device and install the kiosk app for that account.<br><br>This option is supported on: <br>- Windows 10 Pro, Enterprise, and Education<br>- Windows 11 |
|
||||||
| [The kiosk wizard in Windows Configuration Designer](#wizard) | Windows Configuration Designer is a tool that produces a *provisioning package*. A provisioning package includes configuration settings that can be applied to one or more devices during the first-run experience (OOBE), or after OOBE is done (runtime). Using the kiosk wizard, you can also create the kiosk user account, install the kiosk app, and configure more useful settings.<br><br>This method is supported on Windows 10 Pro version 1709+, Enterprise, and Education. |
|
| [The kiosk wizard in Windows Configuration Designer](#wizard) | Windows Configuration Designer is a tool that produces a *provisioning package*. A provisioning package includes configuration settings that can be applied to one or more devices during the first-run experience (OOBE), or after OOBE is done (runtime). Using the kiosk wizard, you can also create the kiosk user account, install the kiosk app, and configure more useful settings.<br><br>This option is supported on: <br>- Windows 10 Pro version 1709+, Enterprise, and Education<br>- Windows 11 |
|
||||||
| [Microsoft Intune or other mobile device management (MDM) provider](#mdm) | For managed devices, you can use MDM to set up a kiosk configuration.<br><br>This method is supported on Windows 10 Pro version 1709+, Enterprise, and Education / Windows 11. |
|
| [Microsoft Intune or other mobile device management (MDM) provider](#mdm) | For managed devices, you can use MDM to set up a kiosk configuration.<br><br>This option is supported on: <br>- Windows 10 Pro version 1709+, Enterprise, and Education<br>- Windows 11 |
|
||||||
|
|
||||||
>[!TIP]
|
>[!TIP]
|
||||||
>You can also configure a kiosk account and app for single-app kiosk within [XML in a provisioning package](lock-down-windows-10-to-specific-apps.md) by using a [kiosk profile](lock-down-windows-10-to-specific-apps.md#profile).
|
>You can also configure a kiosk account and app for single-app kiosk within [XML in a provisioning package](lock-down-windows-10-to-specific-apps.md) by using a [kiosk profile](lock-down-windows-10-to-specific-apps.md#profile).
|
||||||
@ -55,8 +55,9 @@ You have several options for configuring your single-app kiosk.
|
|||||||
>App type:
|
>App type:
|
||||||
> - UWP
|
> - UWP
|
||||||
>
|
>
|
||||||
>OS edition:
|
>OS:
|
||||||
> - Windows client Pro, Ent, Edu
|
> - Windows 10 Pro, Ent, Edu
|
||||||
|
> - Windows 11
|
||||||
>
|
>
|
||||||
>Account type:
|
>Account type:
|
||||||
> - Local standard user
|
> - Local standard user
|
||||||
@ -71,7 +72,7 @@ When your kiosk is a local device that isn't managed by Active Directory or Azur
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
### Windows 10 version 1809 / Windows 11
|
### Windows 10 version 1809+ / Windows 11
|
||||||
|
|
||||||
When you set up a kiosk (also known as *assigned access*) in **Settings** for Windows client, you create the kiosk user account at the same time. To set up assigned access in PC settings:
|
When you set up a kiosk (also known as *assigned access*) in **Settings** for Windows client, you create the kiosk user account at the same time. To set up assigned access in PC settings:
|
||||||
|
|
||||||
@ -123,8 +124,9 @@ To remove assigned access, choose **Turn off assigned access and sign out of the
|
|||||||
>App type:
|
>App type:
|
||||||
> - UWP
|
> - UWP
|
||||||
>
|
>
|
||||||
>OS edition:
|
>OS:
|
||||||
> - Windows client Pro, Ent, Edu
|
> - Windows 10 Pro, Ent, Edu
|
||||||
|
> - Windows 11
|
||||||
>
|
>
|
||||||
>Account type:
|
>Account type:
|
||||||
> - Local standard user
|
> - Local standard user
|
||||||
@ -170,8 +172,10 @@ Clear-AssignedAccess
|
|||||||
> - UWP
|
> - UWP
|
||||||
> - Windows desktop application
|
> - Windows desktop application
|
||||||
>
|
>
|
||||||
>OS edition:
|
>OS:
|
||||||
> - Windows 10 Pro version 1709+ for UWP only; Ent, Edu for both app types
|
> - Windows 10 Pro version 1709+ for UWP only
|
||||||
|
> - Windows 10 Ent, Edu for UWP and Windows desktop applications
|
||||||
|
> - Windows 11
|
||||||
>
|
>
|
||||||
>Account type:
|
>Account type:
|
||||||
> - Local standard user
|
> - Local standard user
|
||||||
|
@ -5,7 +5,7 @@ ms.assetid: 14DDDC96-88C7-4181-8415-B371F25726C8
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
keywords: ["lockdown", "app restrictions"]
|
keywords: ["lockdown", "app restrictions"]
|
||||||
ms.prod: w10
|
ms.prod: w10, w11
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: edu, security
|
ms.pagetype: edu, security
|
||||||
@ -39,6 +39,9 @@ Check the Event Viewer logs for auto logon issues under **Applications and Servi
|
|||||||
|
|
||||||
## Multi-app kiosk issues
|
## Multi-app kiosk issues
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> [!INCLUDE [Multi-app kiosk mode not supported on Windows 11](./includes/multi-app-kiosk-support-windows11.md)]
|
||||||
|
|
||||||
### Unexpected results
|
### Unexpected results
|
||||||
|
|
||||||
For example:
|
For example:
|
||||||
|
@ -5,7 +5,7 @@ ms.assetid: 14DDDC96-88C7-4181-8415-B371F25726C8
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
keywords: ["lockdown", "app restrictions", "applocker"]
|
keywords: ["lockdown", "app restrictions", "applocker"]
|
||||||
ms.prod: w10
|
ms.prod: w10, w11
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: edu, security
|
ms.pagetype: edu, security
|
||||||
@ -256,7 +256,13 @@ This sample demonstrates that both UWP and Win32 apps can be configured to autom
|
|||||||
```
|
```
|
||||||
|
|
||||||
## Global Profile Sample XML
|
## Global Profile Sample XML
|
||||||
Global Profile is currently supported in Windows 10 version 2004 / Windows 11. Global Profile is designed for scenarios where a user does not have a designated profile, yet IT Admin still wants the user to run in lockdown mode, or used as mitigation when a profile cannot be determined for a user.
|
|
||||||
|
Global Profile is supported on:
|
||||||
|
|
||||||
|
- Windows 10 version 2004+
|
||||||
|
- Windows 11
|
||||||
|
|
||||||
|
Global Profile is designed for scenarios where a user does not have a designated profile, yet IT Admin still wants the user to run in lockdown mode, or used as mitigation when a profile cannot be determined for a user.
|
||||||
|
|
||||||
This sample demonstrates that only a global profile is used, no active user configured. Global profile will be applied when every non-admin account logs in.
|
This sample demonstrates that only a global profile is used, no active user configured. Global profile will be applied when every non-admin account logs in.
|
||||||
|
|
||||||
@ -894,7 +900,9 @@ The following XML is the schema for Windows 10 version 1909+:
|
|||||||
</xs:schema>
|
</xs:schema>
|
||||||
```
|
```
|
||||||
|
|
||||||
To authorize a compatible configuration XML that includes elements and attributes from Windows 10 version 1809 or newer / Windows 11, always include the namespace of these add-on schemas, and decorate the attributes and elements accordingly with the namespace alias. For example, to configure the autolaunch feature that was added in Windows 10 version 1809 / Windows 11, use the following sample. Notice an alias r1809 is given to the 201810 namespace for Windows 10 version 1809 / Windows 11, and the alias is tagged on AutoLaunch and AutoLaunchArguments inline.
|
To authorize a compatible configuration XML that includes elements and attributes from Windows 10 version 1809 or newer / Windows 11, always include the namespace of these add-on schemas, and decorate the attributes and elements accordingly with the namespace alias.
|
||||||
|
|
||||||
|
For example, to configure the autolaunch feature that was added in Windows 10 version 1809 / Windows 11, use the following sample. Notice an alias r1809 is given to the 201810 namespace for Windows 10 version 1809 / Windows 11, and the alias is tagged on AutoLaunch and AutoLaunchArguments inline.
|
||||||
|
|
||||||
```xml
|
```xml
|
||||||
<AssignedAccessConfiguration
|
<AssignedAccessConfiguration
|
||||||
|
@ -1,5 +1,5 @@
|
|||||||
---
|
---
|
||||||
title: Set up a multi-app kiosk (Windows 10) | Microsoft Docs
|
title: Set up a multi-app kiosk on Windows 10 | Microsoft Docs
|
||||||
description: Learn how to configure a kiosk device running Windows 10 so that users can only run a few specific apps.
|
description: Learn how to configure a kiosk device running Windows 10 so that users can only run a few specific apps.
|
||||||
ms.assetid: 14DDDC96-88C7-4181-8415-B371F25726C8
|
ms.assetid: 14DDDC96-88C7-4181-8415-B371F25726C8
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
@ -11,19 +11,18 @@ ms.sitesec: library
|
|||||||
ms.pagetype: edu, security
|
ms.pagetype: edu, security
|
||||||
author: greg-lindsay
|
author: greg-lindsay
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
ms.date: 09/20/2021
|
|
||||||
ms.author: greglin
|
ms.author: greglin
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
---
|
---
|
||||||
|
|
||||||
# Set up a multi-app kiosk
|
# Set up a multi-app kiosk on Windows 10 devices
|
||||||
|
|
||||||
**Applies to**
|
**Applies to**
|
||||||
|
|
||||||
- Windows 10 Pro, Enterprise, and Education
|
- Windows 10 Pro, Enterprise, and Education
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Currently, multi-app kiosk is only supported on Windows 10. It's not supported on Windows 11.
|
> [!INCLUDE [Multi-app kiosk mode not supported on Windows 11](./includes/multi-app-kiosk-support-windows11.md)]
|
||||||
|
|
||||||
A [kiosk device](./kiosk-single-app.md) typically runs a single app, and users are prevented from accessing any features or functions on the device outside of the kiosk app. In Windows 10, version 1709, the [AssignedAccess configuration service provider (CSP)](/windows/client-management/mdm/assignedaccess-csp) was expanded to make it easy for administrators to create kiosks that run more than one app. The benefit of a kiosk that runs only one or more specified apps is to provide an easy-to-understand experience for individuals by putting in front of them only the things they need to use, and removing from their view the things they don’t need to access.
|
A [kiosk device](./kiosk-single-app.md) typically runs a single app, and users are prevented from accessing any features or functions on the device outside of the kiosk app. In Windows 10, version 1709, the [AssignedAccess configuration service provider (CSP)](/windows/client-management/mdm/assignedaccess-csp) was expanded to make it easy for administrators to create kiosks that run more than one app. The benefit of a kiosk that runs only one or more specified apps is to provide an easy-to-understand experience for individuals by putting in front of them only the things they need to use, and removing from their view the things they don’t need to access.
|
||||||
|
|
||||||
@ -46,7 +45,10 @@ You can configure multi-app kiosks using [Microsoft Intune](#intune) or a [provi
|
|||||||
|
|
||||||
## Configure a kiosk in Microsoft Intune
|
## Configure a kiosk in Microsoft Intune
|
||||||
|
|
||||||
To configure a kiosk in Microsoft Intune, see [Windows client and Windows Holographic for Business device settings to run as a dedicated kiosk using Intune](/intune/kiosk-settings). For explanations of the specific settings, see [Windows client device settings to run as a kiosk in Intune](/intune/kiosk-settings-windows).
|
To configure a kiosk in Microsoft Intune, see:
|
||||||
|
|
||||||
|
- [Windows client and Windows Holographic for Business device settings to run as a dedicated kiosk using Intune](/intune/kiosk-settings)
|
||||||
|
- [Windows client device settings to run as a kiosk in Intune](/intune/kiosk-settings-windows)
|
||||||
|
|
||||||
<span id="provision" />
|
<span id="provision" />
|
||||||
|
|
||||||
@ -117,7 +119,7 @@ You can start your file by pasting the following XML (or any other examples in t
|
|||||||
There are two types of profiles that you can specify in the XML:
|
There are two types of profiles that you can specify in the XML:
|
||||||
|
|
||||||
- **Lockdown profile**: Users assigned a lockdown profile will see the desktop in tablet mode with the specific apps on the Start screen.
|
- **Lockdown profile**: Users assigned a lockdown profile will see the desktop in tablet mode with the specific apps on the Start screen.
|
||||||
- **Kiosk profile**: New in Windows 10, version 1803, this profile replaces the KioskModeApp node of the [AssignedAccess CSP](/windows/client-management/mdm/assignedaccess-csp). Users assigned a kiosk profile will not see the desktop, but only the kiosk app running in full-screen mode.
|
- **Kiosk profile**: Starting with Windows 10 version 1803, this profile replaces the KioskModeApp node of the [AssignedAccess CSP](/windows/client-management/mdm/assignedaccess-csp). Users assigned a kiosk profile will not see the desktop, but only the kiosk app running in full-screen mode.
|
||||||
|
|
||||||
A lockdown profile section in the XML has the following entries:
|
A lockdown profile section in the XML has the following entries:
|
||||||
|
|
||||||
@ -149,7 +151,7 @@ The profile **Id** is a GUID attribute to uniquely identify the profile. You can
|
|||||||
|
|
||||||
##### AllowedApps
|
##### AllowedApps
|
||||||
|
|
||||||
**AllowedApps** is a list of applications that are allowed to run. Apps can be Universal Windows Platform (UWP) apps or Windows desktop applications. In Windows 10, version 1809, you can configure a single app in the **AllowedApps** list to run automatically when the assigned access user account signs in.
|
**AllowedApps** is a list of applications that are allowed to run. Apps can be Universal Windows Platform (UWP) apps or Windows desktop applications. Starting with Windows 10 version 1809, you can configure a single app in the **AllowedApps** list to run automatically when the assigned access user account signs in.
|
||||||
|
|
||||||
- For UWP apps, you need to provide the App User Model ID (AUMID). [Learn how to get the AUMID](./find-the-application-user-model-id-of-an-installed-app.md), or [get the AUMID from the Start Layout XML](#startlayout).
|
- For UWP apps, you need to provide the App User Model ID (AUMID). [Learn how to get the AUMID](./find-the-application-user-model-id-of-an-installed-app.md), or [get the AUMID from the Start Layout XML](#startlayout).
|
||||||
- For desktop apps, you need to specify the full path of the executable, which can contain one or more system environment variables in the form of %variableName% (i.e. %systemroot%, %windir%).
|
- For desktop apps, you need to specify the full path of the executable, which can contain one or more system environment variables in the form of %variableName% (i.e. %systemroot%, %windir%).
|
||||||
@ -192,7 +194,7 @@ The following example allows Groove Music, Movies & TV, Photos, Weather, Calcula
|
|||||||
|
|
||||||
##### FileExplorerNamespaceRestrictions
|
##### FileExplorerNamespaceRestrictions
|
||||||
|
|
||||||
Starting in Windows 10, version 1809, you can explicitly allow some known folders to be accessed when the user tries to open the file dialog box in multi-app assigned access by including **FileExplorerNamespaceRestrictions** in your XML file. Currently, **Downloads** is the only folder supported. This can also be set using Microsoft Intune.
|
Starting in Windows 10 version 1809, you can explicitly allow some known folders to be accessed when the user tries to open the file dialog box in multi-app assigned access by including **FileExplorerNamespaceRestrictions** in your XML file. Currently, **Downloads** is the only folder supported. This can also be set using Microsoft Intune.
|
||||||
|
|
||||||
The following example shows how to allow user access to the Downloads folder in the common file dialog box.
|
The following example shows how to allow user access to the Downloads folder in the common file dialog box.
|
||||||
|
|
||||||
@ -234,7 +236,7 @@ FileExplorerNamespaceRestriction has been extended in current Windows 10 Prerele
|
|||||||
|
|
||||||
After you define the list of allowed applications, you can customize the Start layout for your kiosk experience. You can choose to pin all the allowed apps on the Start screen or just a subset, depending on whether you want the end user to directly access them on the Start screen.
|
After you define the list of allowed applications, you can customize the Start layout for your kiosk experience. You can choose to pin all the allowed apps on the Start screen or just a subset, depending on whether you want the end user to directly access them on the Start screen.
|
||||||
|
|
||||||
The easiest way to create a customized Start layout to apply to other Windows 10 devices is to set up the Start screen on a test device and then export the layout. For detailed steps, see [Customize and export Start layout](customize-and-export-start-layout.md).
|
The easiest way to create a customized Start layout to apply to other Windows client devices is to set up the Start screen on a test device and then export the layout. For detailed steps, see [Customize and export Start layout](customize-and-export-start-layout.md).
|
||||||
|
|
||||||
A few things to note here:
|
A few things to note here:
|
||||||
|
|
||||||
@ -272,7 +274,7 @@ This example pins Groove Music, Movies & TV, Photos, Weather, Calculator, Paint,
|
|||||||
```
|
```
|
||||||
|
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
>If an app is not installed for the user but is included in the Start layout XML, the app will not be shown on the Start screen.
|
>If an app isn't installed for the user, but is included in the Start layout XML, the app isn't shown on the Start screen.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@ -336,7 +338,7 @@ The following example shows how to specify an account to sign in automatically.
|
|||||||
</Configs>
|
</Configs>
|
||||||
```
|
```
|
||||||
|
|
||||||
In Windows 10, version 1809, you can configure the display name that will be shown when the user signs in. The following example shows how to create an AutoLogon Account that shows the name "Hello World".
|
Starting with Windows 10 version 1809, you can configure the display name that will be shown when the user signs in. The following example shows how to create an AutoLogon Account that shows the name "Hello World".
|
||||||
|
|
||||||
```xml
|
```xml
|
||||||
<Configs>
|
<Configs>
|
||||||
@ -414,7 +416,7 @@ Group accounts are specified using `<UserGroup>`. Nested groups are not supporte
|
|||||||
<span id="add-xml" />
|
<span id="add-xml" />
|
||||||
|
|
||||||
#### [Preview] Global Profile
|
#### [Preview] Global Profile
|
||||||
Global profile is added in current Windows 10 Prerelease. There are times when IT Admin wants to everyone who logging into a specific devices are assigned access users, even there is no dedicated profile for that user, or there are times that Assigned Access could not identify a profile for the user and a fallback profile is wished to use. Global Profile is designed for these scenarios.
|
Global profile is added in Windows 10. There are times when IT Admin wants to everyone who logging into a specific devices are assigned access users, even there is no dedicated profile for that user, or there are times that Assigned Access could not identify a profile for the user and a fallback profile is wished to use. Global Profile is designed for these scenarios.
|
||||||
|
|
||||||
Usage is demonstrated below, by using the new xml namespace and specify GlobalProfile from that namespace. When GlobalProfile is configured, a non-admin account logs in, if this user does not have designated profile in Assigned Access, or Assigned Access fails to determine a profile for current user, global profile will be applied for the user.
|
Usage is demonstrated below, by using the new xml namespace and specify GlobalProfile from that namespace. When GlobalProfile is configured, a non-admin account logs in, if this user does not have designated profile in Assigned Access, or Assigned Access fails to determine a profile for current user, global profile will be applied for the user.
|
||||||
|
|
||||||
@ -575,7 +577,6 @@ Provisioning packages can be applied to a device during the first-run experience
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
<span id="alternate-methods" />
|
|
||||||
### Use MDM to deploy the multi-app configuration
|
### Use MDM to deploy the multi-app configuration
|
||||||
|
|
||||||
Multi-app kiosk mode is enabled by the [AssignedAccess configuration service provider (CSP)](/windows/client-management/mdm/assignedaccess-csp). Your MDM policy can contain the assigned access configuration XML.
|
Multi-app kiosk mode is enabled by the [AssignedAccess configuration service provider (CSP)](/windows/client-management/mdm/assignedaccess-csp). Your MDM policy can contain the assigned access configuration XML.
|
||||||
|
@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: Set up a shared or guest PC with Windows 10/11 (Windows 10/11)
|
title: Set up a shared or guest PC with Windows 10/11
|
||||||
description: Windows 10, version 1607, introduces *shared PC mode*, which optimizes Windows client for shared use scenarios.
|
description: Windows 10 and Windows has shared PC mode, which optimizes Windows client for shared use scenarios.
|
||||||
keywords: ["shared pc mode"]
|
keywords: ["shared pc mode"]
|
||||||
ms.prod: w10
|
ms.prod: w10, w11
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
author: greg-lindsay
|
author: greg-lindsay
|
||||||
@ -113,7 +113,7 @@ You can configure Windows to be in shared PC mode in a couple different ways:
|
|||||||
|
|
||||||
11. From this point on, you can configure any additional settings you’d like to be part of this policy, and then follow the rest of the set-up flow to its completion by selecting **Create** after **Step 6**.
|
11. From this point on, you can configure any additional settings you’d like to be part of this policy, and then follow the rest of the set-up flow to its completion by selecting **Create** after **Step 6**.
|
||||||
|
|
||||||
- A provisioning package created with the Windows Configuration Designer: You can apply a provisioning package when you initially set up the PC (also known as the out-of-box-experience or OOBE), or you can apply the provisioning package to a Windows 10 PC that is already in use. The provisioning package is created in Windows Configuration Designer. Shared PC mode is enabled by the [SharedPC configuration service provider (CSP)](/windows/client-management/mdm/sharedpc-csp), exposed in Windows Configuration Designer as **SharedPC**.
|
- A provisioning package created with the Windows Configuration Designer: You can apply a provisioning package when you initially set up the PC (also known as the out-of-box-experience or OOBE), or you can apply the provisioning package to a Windows client that's already in use. The provisioning package is created in Windows Configuration Designer. Shared PC mode is enabled by the [SharedPC configuration service provider (CSP)](/windows/client-management/mdm/sharedpc-csp), exposed in Windows Configuration Designer as **SharedPC**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
@ -1,12 +1,12 @@
|
|||||||
---
|
---
|
||||||
title: Set up digital signs on Windows 10/11 (Windows 10/11)
|
title: Set up digital signs on Windows 10/11
|
||||||
description: A single-use device such as a digital sign is easy to set up in Windows 10 (Pro, Enterprise, and Education).
|
description: A single-use device such as a digital sign is easy to set up in Windows 10 and Windows 11 (Pro, Enterprise, and Education).
|
||||||
ms.assetid: 428680AE-A05F-43ED-BD59-088024D1BFCC
|
ms.assetid: 428680AE-A05F-43ED-BD59-088024D1BFCC
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: dansimp
|
manager: dansimp
|
||||||
ms.author: greglin
|
ms.author: greglin
|
||||||
keywords: ["assigned access", "kiosk", "lockdown", "digital sign", "digital signage", "kiosk browser", "browser"]
|
keywords: ["assigned access", "kiosk", "lockdown", "digital sign", "digital signage", "kiosk browser", "browser"]
|
||||||
ms.prod: w10
|
ms.prod: w10, w11
|
||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
author: greg-lindsay
|
author: greg-lindsay
|
||||||
|
Reference in New Issue
Block a user