Test a Windows Assigned Access Kiosk From the Actual Console
A visitor-facing kiosk needs more than a full-screen window. Establish which application the visitor may use, what information it can reveal and how an authorised operator will return to maintenance. Rehearse these paths before the device is left unattended.
Windows Assigned Access supports a single-app kiosk using a UWP application or Microsoft Edge. Microsoft lists Pro, Enterprise, Education and IoT Enterprise editions; UAC must be enabled. The kiosk experience requires a console sign-in and is not supported over Remote Desktop.
Configure a deliberate visitor account
For a simple local setup, an administrator can use Settings, Accounts, Other Users, Set up a kiosk. Create or choose a local standard account, then select the kiosk application. Microsoft recommends a least-privileged local account for a public kiosk, rather than an account with access to organisational resources.
With Edge, choose the intended digital-sign or public-browser experience, starting URL and applicable inactivity behaviour. Use harmless test content while establishing the setup. Keep the operator’s administrative account separate.
Review automatic sign-in before deployment. Microsoft documents that the Settings route configures it automatically when the device is not joined to an Active Directory domain or Microsoft Entra ID. Decide whether that matches the intended restart behaviour.
Validate on the actual hardware
Sign out and sign in as the kiosk account at the device. If the configuration was applied while that account was already signed in, the next sign-in is needed for validation. Testing an ordinary administrator desktop does not verify the visitor experience.
Complete the visitor’s whole task. Inspect every link, download or account prompt the app exposes. For a touch workflow, tap a text field on the physical device; Microsoft notes that mouse clicks and VM testing do not demonstrate the kiosk touch keyboard’s automatic appearance.
Practise the operator exit. Ctrl+Alt+Del is the default breakout sequence, although managed configurations can change it. Confirm that the operator can reach the intended maintenance account and then restore the visitor session.
Finally restart during the rehearsal and observe which account and application return. Keep the tested configuration and maintenance procedure with the device, including any remaining limitations that prevent unattended use.
Sources: Microsoft Assigned Access requirements; Microsoft single-app kiosk configuration; Microsoft kiosk recommendations.