Kiosk · How-to

How to lock an Android tablet to one app, without an MDM

Screen pinning, kiosk apps and device owner mode compared — what each actually holds shut, and what none of them can.

3 min read UniKiosk

You have a tablet, you want it to show one thing, and you want a member of the public to be unable to reach anything else. There are three ways to do that on Android and they are not equivalent.

Option 1: screen pinning

Built into Android. Settings → Security → Screen pinning, then pin the app from recents.

What it does: stops casual app switching.

What it does not do: hide the system bars, survive a reboot, or resist anybody who knows that holding back and recents unpins it. On many builds it shows a toast explaining exactly how to escape.

Fine for handing your own phone to a child. Not a kiosk.

Option 2: a kiosk app

An app that takes over the display and holds the system out of the way. This covers most purpose-built signage and kiosk software, including ours.

What it does:

  • Hides the status and navigation bars, and re-hides them after a swipe — which requires the overlay permission, and is the single most common thing people forget to grant.
  • Swallows home, recents and back rather than merely ignoring them.
  • Keeps the screen awake, pins orientation, fixes brightness.
  • Starts on boot, so a power cut is not a site visit.
  • Provides a deliberate, obscure way back in — ours is five taps in the bottom-left corner, then a PIN.

What it does not do: stop somebody with physical access. See below.

Option 3: device owner provisioning

The real lockdown. The device is enrolled as device owner, usually via an MDM and usually from a factory-reset state, and the operating system itself enforces the restrictions.

What it does: everything above, plus blocking safe mode, factory reset, USB debugging and settings changes at the OS level.

What it costs: an MDM, a provisioning process, and a factory reset on every device. For an enterprise with a fleet, that is routine. For a café with two tablets, a school with a corridor screen, or a clinic with a waiting-room panel, it is why the screen never gets deployed at all.

What none of them stop

Be honest about the boundary, because a lockdown you overestimate is worse than one you understand:

  • The power button. Anyone can turn the device off. The answer is an enclosure, not software.
  • Safe mode. Booting to safe mode disables third-party apps. Only device owner mode prevents it.
  • adb over USB, if debugging is enabled and the port is reachable. Turn it off before deployment and cover the port.

Physical access beats software. Every time. Budget for the enclosure.

Choosing

  • One or two screens, no IT department: a kiosk app. It is the only option that gets deployed.
  • A regulated environment or a device that leaves the building: device owner via an MDM, no argument.
  • Both: MDM for provisioning, a kiosk app for the actual board. They compose fine.

The deployment checklist

Whatever you pick:

  • Overlay permission granted, or the bars come back on the first swipe.
  • A PIN set before the lockdown is enabled.
  • USB debugging off.
  • Mains power, not battery.
  • Auto-rotate off, orientation pinned in the app.
  • System updates scheduled for the middle of the night, not the middle of the day.
  • One reboot tested on site before you leave.

That last one catches more problems than the other six together.

There is a fuller version of this in our kiosk lockdown documentation, including the failure modes and what to leave taped inside the enclosure.

Free, and there is nothing to cancel.

One APK, no account, no per-screen fee.