You can allow only one website in Windows 10 by using browser kiosk mode, Assigned Access, web filtering, firewall rules, or an MDM solution. For businesses, schools, and public-use devices, MDM-based restriction to a single approved URL is a more reliable approach. For centrally managed kiosk fleets, MDM can help IT configure a dedicated browser experience, apply supported website restrictions, and maintain kiosk policies remotely across enrolled Windows devices.
Key Takeaways
Allowing only one website on Windows 10 transforms standard devices into focused, purpose-built kiosks for self-service, learning, digital signage, and frontline workflows.
- Create Purpose-Built Experiences: Restricting a Windows device to a single website helps create a controlled and focused environment for public or frontline use.
- Deploy via Centralized MDM: For organizations managing multiple or distributed kiosk devices, MDM provides a centralized way to deploy, update, and maintain kiosk configurations without managing each endpoint individually.
- Account for Website Dependencies: When allowlisting a single URL, IT admins must also allow essential dependencies like login domains, APIs, and CDNs for the site to function properly.
- Choose Between Two Kiosk Modes: IT admins can configure devices into a single-app kiosk running only the browser in full screen, or a multi-app kiosk running a restricted set of approved applications.
Note: Windows 10 version 22H2 reached end of support on October 14, 2025. Organizations using ESU or Windows 10 LTSC/LTSB editions should check the lifecycle that applies to their specific release before maintaining or deploying Windows 10 kiosks.
Why restrict Windows devices to one website?
Limiting a Windows 10 device to a single web application supports various business goals:
- Enhanced focus: Helps prevent users from accessing distracting or irrelevant websites when configured correctly.
- Data security: Limits users to the configured app experience and applies web restrictions, reducing unnecessary access to other apps, sites, and Windows surfaces.
- Ease of use: Provides a simplified, self-serve interface for customers and non-technical staff.
- Cost management: Helps reduce unauthorized data consumption on cellularly connected fleet devices.
Methods comparison: Choosing the right approach
Before locking down your devices, review the common methods used to restrict web access:
| Method | Best for | Strength | Limitation |
|---|---|---|---|
| Windows Assigned Access/Edge kiosk mode | Individual or small locally administered deployments | Runs Microsoft Edge or a selected app in a restricted kiosk experience | Requires careful URL, account, and kiosk policy configuration |
| MDM kiosk policy | Centrally managed or distributed fleets | Central deployment, remote updates, monitoring, and policy enforcement | Requires device enrollment and admin setup |
| Browser URL allow/block policies | Managed browser environments | Can allow one URL and block other URLs in supported browsers | Must account for login domains, CDNs, redirects, and embedded resources |
| DNS or web filtering | Network-level support control | Blocks unwanted domains outside the device policy | Less precise for one-web-app kiosk flows and may affect other apps |
| Hosts file or browser extension | Testing or personal use | Simple to try on one device | Easy to bypass, hard to scale, and unreliable for business kiosks |
When using the Windows Assigned Access/Edge kiosk mode method to deploy a single-website environment, you leverage Microsoft’s native lockdown capabilities. As outlined in Microsoft’s Assigned Access overview, these configurations restrict a Windows device as a kiosk. Specifically, configuring a single-app kiosk allows you to force a browser like Microsoft Edge to run full screen, hiding the desktop and Start Menu entirely.
If you want to configure a restricted web experience alongside access to a few select native apps (like a calculator or camera), a multi-app kiosk is the right choice. For managed deployments, Microsoft documents that its own kiosk settings and equivalent MDM platforms like Scalefusion allow IT admins to cleanly configure the Edge Kiosk URL and push allowed-website policies directly to a multi-app Start Menu.
Evaluating the options
Choosing the right lockdown strategy depends strictly on operational scale, security risks, and management overhead. While superficial workarounds such as browser extensions or local host file edits might suffice for a temporary test environment, they fail in production. These makeshift methods are fragile, highly vulnerable to user bypass, and offer very little tamper resistance.
For production kiosk deployments, Windows Assigned Access can provide an OS-managed kiosk or restricted user experience that limits users to the configured app experience. Configuring Assigned Access manually is effective for a single lobby terminal. However, it forces IT personnel to touch every machine, creating a massive bottleneck as the deployment grows.
For distributed deployments, local configuration increases administrative effort because IT must configure and maintain each kiosk individually. MDM can centrally deploy and maintain Windows kiosk configurations across managed devices. In Scalefusion, the available implementation can use Windows MDM CSP or the Scalefusion MDM Agent, depending on the selected kiosk mode and device environment.
| Feature | Locally configured kiosk | Centrally managed kiosk |
|---|---|---|
| Primary purpose | Configures a single local Windows machine for a specific app experience | Deploys and updates kiosk policies remotely across an enrolled fleet |
| Deployment method | Local Windows Settings, PowerShell, or local Provisioning Packages | Over-the-air (OTA) cloud dashboard deployment |
| Configuration | Manual or local XML configuration files per machine | Centralized configuration profiles and Windows CSP/MDM Agent policies |
| App management | Requires physical interaction or local scripts to update apps | Centrally distributed app pushes and updates |
| Monitoring & actions | Requires on-site inspection for errors | Remote telemetry, remote reboots, and remote troubleshooting |
| OS updates | Managed by local Windows Update settings | Enforced, deferred, or scheduled remotely by IT admin |
The scaling problem is one of the reasons modern IT teams rely on MDM. Centralized management via MDM reduces the operational work required to configure and maintain distributed kiosk devices. Plus, IT gains from over-the-air deployment, real-time telemetry, and silent policy updates across thousands of distributed endpoints simultaneously. MDM transforms a high-overhead manual chore into an efficient, repeatable cloud operation.
Prerequisites for website lockdown
Before applying kiosk profiles, ensure you have the following in place:
Crucial tip on allowed website dependencies: A single website may depend on additional domains for login, images, scripts, payment, analytics, APIs, or identity provider redirects. Before rollout, test the website and add only the required supporting domains to the allowlist.
In Scalefusion, the workflow combines Windows device profiles with Allowed Websites and the appropriate kiosk/app configuration. IT admins can create the approved website entry, enable it in the Windows profile, configure the required kiosk experience, and assign the profile to managed devices. The exact implementation differs between Single App/Kiosk Mode and Multi-App Kiosk Mode.
Single-app vs. Multi-app kiosk mode: Which one to choose?
Single-app kiosk: It locks the device to a single app running in full screen. For a browser-based workflow, it can launch one designated browser as the primary user experience. Microsoft Assigned Access supports Edge in a full-screen kiosk experience, while Scalefusion provides additional Single App/Kiosk configuration options based on the app type and enrollment mode.
Multi-app kiosk: It locks the device to more than one app. Deploy it when users need access to a defined set of approved applications rather than a single app. In Scalefusion, the interface and enforcement behavior depend on whether the policy is applied through Windows MDM CSP or the Scalefusion MDM Agent.
Manual configurations such as modifying the hosts file, using browser extensions, or setting up Assigned Access locally might work for a single test device. However, they are difficult to scale, secure, and maintain across a fleet. For organizations deploying public kiosks, frontline devices, or educational terminals, MDM is a more effective way to centrally enforce and monitor these policies.
Let’s look at the step-by-step methods to allow only one website using an MDM solution like Scalefusion.
Method 1: Allow only one website using single-app kiosk mode
Note: For current prerequisites and dashboard options, see the Scalefusion Help guide for Windows Single App/Kiosk Mode.
- Log into the Scalefusion dashboard: From the left menu section, navigate to Device Profiles & Policies > Allowed Websites.
Before we dive into the steps to lock Windows 10 devices to a single website, watch this video to learn how to allow only certain websites on your Windows fleet.

- Allowlist the website: Click on Allow a Website. Enter the name and URL of the website you want to allow. Save your settings.

- Create a device profile: Go to Device Profiles & Policies > Device Profiles and create a new Windows 10/11 profile.

- Configure single-app mode: Choose Skip Application Policy in Select Apps.

- In Allowed Websites, enable the website you allowlisted in Step 2.

- Configure the kiosk app: Choose a browser app in Settings > Single/Kiosk App Mode. Note: For the policy to take effect, the selected browser app should be pre-installed on the Windows machine.

- Configure browser settings: Select the website you allowlisted in Step 2 as the default launch URL and set the browser installation path. Hide browser navigation keys. Enter the user account for the kiosk app.

- Apply the policy: Save the device profile and assign it to your target device groups.

Method 2: Allow only one website using multi-app kiosk mode
Note: For current prerequisites and dashboard options, see the Scalefusion Help guide for ‘Configure Multi-App Kiosk on Windows.’
- Log into the Scalefusion dashboard: From the left menu section, navigate to Device Profiles & Policies > Allowed Websites.

- Allowlist the website: Click on Allow a Website. Enter the name and URL of the website you want to allow. Save your settings.

- Create a device profile: Go to Device Profiles & Policies > Device Profiles and create a new Windows 10/11 profile.

- Configure multi-app mode: In Multi-App Kiosk Mode, choose how to apply the policy. Note: In Scalefusion MDM Agent mode, you get the ‘Enable Advanced Protection using App Locker’ option to prevent users from launching disallowed apps.

- Add the user account: In Add User Info, configure the user account this policy will be applied to.

- Add multiple apps: In Select Apps, enable the apps, including a browser app, that you want to allow end users to access.

- In Allowed Websites, enable the website you allowlisted in Step 2.

- Apply the policy: Save the device profile and assign it to your target device groups.

Industry use cases of allowing one website on Windows 10
Restricting access to a single website provides controlled web access across various sectors:
- Retail and hospitality: Tablets locked to an online catalog or self-service check-in portal to support customer engagement and reduce distractions.
- Healthcare: Kiosks locked to a patient registration portal limit users to the configured app experience, supporting privacy alongside broader organizational security controls.
- Education: Lab computers restricted to a single testing website, helping prevent access to unauthorized internet resources during exams.
- Logistics and frontline: Warehouse workstations restricted to a cloud-based inventory application to support uptime and simplify the daily worker experience.
Restrict Website Access with Ease!
Allow only one website in Windows 10 effortlessly.
Best practices for single website restriction on Windows 10
Enable session resets: For public-facing kiosks, configure browser policies to automatically clear cache, cookies, and session data after a set period of inactivity.
Match the browser to kiosk workflow: Each supported browser has different behavior in MDM. Validate the selected browser and ‘allowed websites’ configuration against the intended restriction before rollout.
Test allowed website dependencies: Always test your site and allowlist critical dependencies like login domains (e.g., Microsoft Entra ID), CDNs, APIs, and payment gateways before deployment.
Hide navigation controls: Disable the address bar, back/forward buttons, and developer tools to help prevent users from navigating away from the intended app.
Enable single website access on Windows 10 with Scalefusion
Restricting Windows 10 devices to a single website is a practical way to support purpose-driven, secure digital experiences. Whether it’s for retail kiosks, self-service stations in hospitality, or focused learning environments in education, the ability to allow only one website on Windows helps provide better control, reduce distractions, and improve user engagement.
While local methods like manual Assigned Access or browser extensions might work for a quick test on a single computer, they are difficult to manage at scale for business deployments.
Using an MDM solution like Scalefusion UEM allows IT admins to centrally manage devices, configure Edge kiosk URLs, and deploy necessary domain allowlists across their entire fleet to provide controlled web access. Instead of manually configuring each machine, IT teams can efficiently deploy policies and support compliance efforts over the air.
FAQs
1. How can I block all websites except one on Windows 10?
For business or kiosk deployments, a more reliable method is to use Windows kiosk mode with a managed browser and an allowed website policy through MDM. Other methods are not suitable for scalable deployment, easier to bypass, harder to manage, and have technical limitations.
2. Can I use the Windows hosts file or Firewall instead?
While you can edit the hosts file or set manual firewall rules, these methods typically operate at the IP/network level rather than providing clean, URL-level website allowlisting. They are highly brittle, do not handle modern CDNs well, and are not recommended as fleet-grade business methods.
3. Does kiosk mode ensure the device is fully secure?
Kiosk mode limits users to the configured app experience, reducing unnecessary access to other apps and Windows surfaces. It should be used alongside patching, account controls, network security, and other controls required by the organization’s security or compliance program.
4. Which versions of Windows 10 support kiosk mode?
Native kiosk mode (Assigned Access) is available on Windows 10 Pro, Enterprise, and Education editions. Windows 10 Home does not support this feature natively. For organizations looking to lock down a fleet of devices to a single website using MDM, ensuring devices run a supported Windows 10 or Windows 11 edition is a necessary prerequisite.
5. How do I exit or unlock a Windows 10 kiosk device?
How you exit or remove kiosk mode depends on how the device was configured. For MDM-managed devices, IT can remove or update the assigned kiosk policy centrally. For locally configured Assigned Access devices, an IT admin can remove or change the kiosk configuration using the applicable Windows administration method, such as Settings or PowerShell.


