I have a windows desktop that’s in a mental health ward that’s accessible to patients. The last time i did the setup was with Win 10 in guest mode. I’m looking to see if there is a better way of doing this in Win 11 in guest mode or multi-app kiosk mode. This can be domain or non-domain joined. Any experience or suggestions are welcome, thanks.
The requirements are:
single click (no password) user account
a non-persistent user and Edge browser profile (Allow clearing browsing data on exit)
restricted local access account (no add\remove applications or system settings)
a local usb printer
Edge Browser content restrictions (without using MS family)

3 Spice ups

Multi-app kiosk mode in Windows 11 is your best bet since it gives more control than guest mode and works fine on or off a domain. Set up a local kiosk account with auto sign-in, use Edge in kiosk mode with browsing data cleared on exit, and lock down system access using local policies or Applocker. You can also add a local USB printer manually and restrict web access using Edge’s site list or local GPO settings.

2 Spice ups

that’s almost exactly what i was thinking

2 Spice ups

GPO is a huge game-changer for us. We used to use restore-on-reboot tools like Deep Freeze and Reboot Restore but imo over time they were more of a hassle to maintain then their inherent worth. GPO takes time to set up, but it has everything you need to set up a kiosk.

1 Spice up

i’ve used those apps before but in this environment they aren’t approved apps and i’m also not going to fight the “senior” admin team for access to intune (i retire in 6 years and would like this completed before then). i’m using gpo’s to restrict user access to system settings and folders,

2 Spice ups

Totally fair, like I said GPO is the way to go, and it’s more admin friendly to tell them it’s using stuff you already have lol

1 Spice up

Scalefusion’s Kiosk Mode for Windows 11 might be worth checking out. It supports auto-login, non-persistent user sessions, restricts access to settings and apps, and allows you to manage Edge browser behavior remotely. Also works fine with local printers and doesn’t require domain join.

1 Spice up