Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / Windows 11 Enterprise Kiosk Mode Deep Dive
Transcript
- Lucas: There's a shift happening in enterprise Windows that isn't getting much attention, and it's around what Microsoft calls 'dedicated-purpose devices' — essentially, machines that are locked down to run one app, one function, and nothing else. Luna: You mean kiosks, right? Like the check-in tablets at a doctor's office or the self-order screens at a fast-food place. Lucas: Exactly. And Windows has had a kiosk mode for years — it used to be called 'Assigned Access' — but with Windows 11 and the 2025 feature update, Microsoft quietly rewrote the underlying architecture. The new mode is built on a minimal shell that runs directly on top of the Windows kernel, without the full explorer.exe desktop process. Luna: So no taskbar, no start menu, no notifications — just the app? Lucas: Right. The device boots straight into a single Microsoft Edge window in full-screen. No way to break out, no Alt-Tab to other apps. And it's enforced through Intune policies, which means IT can provision these at scale without touching each machine manually. Luna: That sounds like a huge reduction in attack surface. If there's no desktop, there's no way to launch a rogue executable or mess with system settings. Lucas: Exactly. And that's the main selling point Microsoft is pushing. But the interesting thing is how specific the new requirements are. For a device to qualify for this locked-down mode, it needs at least 4 gigs of RAM, a 64-bit processor, and TPM 2.0 — the same baseline as Windows 11 itself. Luna: So no more repurposing old hardware as kiosks? I've seen a lot of organizations use decade-old desktops for signage or check-in. Lucas: Right, that era is ending. But the trade-off is that the new kiosk mode is significantly more secure and easier to manage. I spoke with an IT director at a midsize healthcare chain — they deployed five hundred check-in kiosks across their clinics using this setup. Their previous solution was a custom Windows 10 image with a locked-down shell, which took about 45 minutes per device to configure. Luna: And with the new approach? Lucas: They used a provisioning package through Intune — scanned a QR code on each new device, and the kiosk was configured in about 8 minutes. That's a 5x reduction in setup time per unit. Over 500 devices, that's over 300 hours saved. Luna: Wow. And the security side — any incidents since the rollout? Lucas: They told me that in the first six months, they had zero successful attempts to break out of the kiosk. With the old system, they'd had three incidents where patients or visitors managed to get to the desktop — one person even tried to browse the web on a device that was supposed to be appointment-only. Luna: So the new mode isn't just about convenience — it's actually preventing real-world misuse. Lucas: Exactly. And Microsoft is betting that this will drive more enterprise adoption of Windows 11 in verticals like retail, healthcare, and education. But there's a catch: the new kiosk mode is only available in the Enterprise and Education editions — not Pro. So if a small business is used to buying Windows 11 Pro for their kiosk machines, they're now forced into a higher licensing tier. Luna: That's a significant cost increase. Windows 11 Pro is included in the device price for most new PCs, but Enterprise requires a volume licensing agreement or a subscription like Microsoft 365 E3. Lucas: Right. For a large organization, that might be manageable. But for a small retail chain with fifty kiosks, the licensing cost could easily double. Some IT admins I've talked to are looking at alternatives — like using Windows 11 Pro with a third-party kiosk lock-down tool — but those often lack the deep integration with Intune and the security guarantees. Luna: It feels like Microsoft is making a bet: lock down the OS so tightly that the only way to manage it is through their cloud. And that drives subscription revenue. Lucas: It's a pattern we've seen before. And it's not just kiosk mode. The same update also introduced a new 'kiosk browser' policy that forces Edge into a single-site mode with no address bar, no menus, no settings. That's ideal for a catalog or booking system. Luna: So if you need to display a web app, you don't even need a full kiosk — you can just lock down the browser? That seems more flexible. Lucas: It is. And you can combine that with the new 'device lockdown' policy that disables the power button, volume keys, and even the ability to sign out. The device becomes a pure appliance. Luna: That's powerful — but also a little dystopian. What about workers who need to use that machine for non-kiosk tasks occasionally? Or maintenance? Lucas: That's the tension. Microsoft does provide a way to temporarily exit the kiosk — a special admin gesture, like pressing ctrl alt delete five times — but it's clunky. And if the device is truly locked down, you need remote management tools to update the app or troubleshoot. That means the device must always be online and connected to Intune. Luna: Which is fine for most enterprise environments, but not for disconnected scenarios — like a kiosk in a factory basement with spotty Wi-Fi. Lucas: Right. So there are still gaps. But the direction is clear: Microsoft wants Windows 11 to be the platform of choice for dedicated devices, competing with ChromeOS and even some Linux-based kiosk solutions. And they're using the security argument as the wedge. Luna: It's a smart strategy, but it also means IT teams need to rethink their hardware lifecycle. Older devices that don't meet Windows 11 requirements will need to be replaced. Lucas: And that's where the cost-benefit analysis gets interesting. The healthcare IT director I mentioned — they calculated that the time savings from faster deployment alone paid for the hardware refresh in about 18 months. Plus they eliminated a part-time contractor who used to handle kiosk configurations. Luna: So for them, the total cost of ownership went down, even with the licensing upgrade. Lucas: Exactly. And that's the story Microsoft wants to tell. But it requires a level of planning and centralized management that some organizations don't have. If you're a small business with one IT person who's also the owner, the new kiosk mode might feel like overkill. Luna: If today's conversation gave you something useful for planning or just a clearer picture of where Windows is headed, that's exactly why we do this show — and listener support is what keeps it ad-free. If you'd like to help, you can find us at buy me a coffee dot com slash fexingo. Lucas: Yeah, it's a small gesture that makes a real difference. Now, back to the kiosk mode — one more thing I want to highlight. Luna: Please. Lucas: There's a new reporting feature in Intune that shows you the last time each kiosk device was used, and whether any unauthorized app was detected trying to run. That's a game-changer for compliance audits — you can prove that your kiosks are locked down as configured. Luna: So the new kiosk mode isn't just a configuration — it's a whole management ecosystem. Lucas: Exactly. And for organizations that need to demonstrate PCI DSS or HIPAA compliance, that level of auditability is huge. The old kiosk mode didn't log that information. Luna: Alright, so the takeaway: if you're evaluating Windows 11 for kiosks, the new capabilities are worth a hard look, but factor in the licensing cost and the need for constant connectivity. Lucas: Right. And if you're already on Windows 11 Enterprise, you might be able to enable kiosk mode tomorrow with a single Intune policy. The configuration is surprisingly simple — Microsoft even provides a template. But the real work is in deciding which devices should be locked down and how to handle exceptions. Luna: Thanks, Lucas. And thanks to our listeners for tuning in. We'll be back next week with another deep dive into enterprise Windows.