How to Allow Only One Website on Windows 10

Published January 22, 2023 by Renuka Shahane in Kiosk Software
About Scalefusion
 

One Platform for Devices, Access, and Security

  • Manage every device, laptops, phones, and tablets from one dashboard
  • Employees sign in to company devices and work apps with one login, no separate passwords
  • Automatically check devices against security benchmarks and block risky apps and sites

Book a Demo

Every device.
Every OS.
One platform.

Start Free Trial

No credit card required, full access to all features.

You can allow only one website in Windows 10 by using browser kiosk mode, Assigned Access, web filtering, firewall rules, or an MDM solution. For businesses, schools, and public-use devices, MDM-based restriction to a single approved URL is a more reliable approach. For centrally managed kiosk fleets, MDM can help IT configure a dedicated browser experience, apply supported website restrictions, and maintain kiosk policies remotely across enrolled Windows devices.

Key Takeaways

Allowing only one website on Windows 10 transforms standard devices into focused, purpose-built kiosks for self-service, learning, digital signage, and frontline workflows.

  • Create Purpose-Built Experiences: Restricting a Windows device to a single website helps create a controlled and focused environment for public or frontline use.
  • Deploy via Centralized MDM: For organizations managing multiple or distributed kiosk devices, MDM provides a centralized way to deploy, update, and maintain kiosk configurations without managing each endpoint individually.
  • Account for Website Dependencies: When allowlisting a single URL, IT admins must also allow essential dependencies like login domains, APIs, and CDNs for the site to function properly.
  • Choose Between Two Kiosk Modes: IT admins can configure devices into a single-app kiosk running only the browser in full screen, or a multi-app kiosk running a restricted set of approved applications.
Note: Windows 10 version 22H2 reached end of support on October 14, 2025. Organizations using ESU or Windows 10 LTSC/LTSB editions should check the lifecycle that applies to their specific release before maintaining or deploying Windows 10 kiosks.

Why restrict Windows devices to one website?

Limiting a Windows 10 device to a single web application supports various business goals:

  • Enhanced focus: Helps prevent users from accessing distracting or irrelevant websites when configured correctly.
  • Data security: Limits users to the configured app experience and applies web restrictions, reducing unnecessary access to other apps, sites, and Windows surfaces.
  • Ease of use: Provides a simplified, self-serve interface for customers and non-technical staff.
  • Cost management: Helps reduce unauthorized data consumption on cellularly connected fleet devices.

Methods comparison: Choosing the right approach

Before locking down your devices, review the common methods used to restrict web access:

MethodBest forStrengthLimitation
Windows Assigned Access/Edge kiosk modeIndividual or small locally administered deploymentsRuns Microsoft Edge or a selected app in a restricted kiosk experienceRequires careful URL, account, and kiosk policy configuration
MDM kiosk policyCentrally managed or distributed fleetsCentral deployment, remote updates, monitoring, and policy enforcementRequires device enrollment and admin setup
Browser URL allow/block policiesManaged browser environmentsCan allow one URL and block other URLs in supported browsersMust account for login domains, CDNs, redirects, and embedded resources
DNS or web filteringNetwork-level support controlBlocks unwanted domains outside the device policyLess precise for one-web-app kiosk flows and may affect other apps
Hosts file or browser extensionTesting or personal useSimple to try on one deviceEasy to bypass, hard to scale, and unreliable for business kiosks

When using the Windows Assigned Access/Edge kiosk mode method to deploy a single-website environment, you leverage Microsoft’s native lockdown capabilities. As outlined in Microsoft’s Assigned Access overview, these configurations restrict a Windows device as a kiosk. Specifically, configuring a single-app kiosk allows you to force a browser like Microsoft Edge to run full screen, hiding the desktop and Start Menu entirely.

If you want to configure a restricted web experience alongside access to a few select native apps (like a calculator or camera), a multi-app kiosk is the right choice. For managed deployments, Microsoft documents that its own kiosk settings and equivalent MDM platforms like Scalefusion allow IT admins to cleanly configure the Edge Kiosk URL and push allowed-website policies directly to a multi-app Start Menu.

Evaluating the options

Choosing the right lockdown strategy depends strictly on operational scale, security risks, and management overhead. While superficial workarounds such as browser extensions or local host file edits might suffice for a temporary test environment, they fail in production. These makeshift methods are fragile, highly vulnerable to user bypass, and offer very little tamper resistance.

For production kiosk deployments, Windows Assigned Access can provide an OS-managed kiosk or restricted user experience that limits users to the configured app experience. Configuring Assigned Access manually is effective for a single lobby terminal. However, it forces IT personnel to touch every machine, creating a massive bottleneck as the deployment grows. 

For distributed deployments, local configuration increases administrative effort because IT must configure and maintain each kiosk individually. MDM can centrally deploy and maintain Windows kiosk configurations across managed devices. In Scalefusion, the available implementation can use Windows MDM CSP or the Scalefusion MDM Agent, depending on the selected kiosk mode and device environment.

FeatureLocally configured kioskCentrally managed kiosk
Primary purposeConfigures a single local Windows machine for a specific app experienceDeploys and updates kiosk policies remotely across an enrolled fleet
Deployment methodLocal Windows Settings, PowerShell, or local Provisioning PackagesOver-the-air (OTA) cloud dashboard deployment
ConfigurationManual or local XML configuration files per machineCentralized configuration profiles and Windows CSP/MDM Agent policies
App managementRequires physical interaction or local scripts to update appsCentrally distributed app pushes and updates
Monitoring & actionsRequires on-site inspection for errorsRemote telemetry, remote reboots, and remote troubleshooting
OS updatesManaged by local Windows Update settingsEnforced, deferred, or scheduled remotely by IT admin

The scaling problem is one of the reasons modern IT teams rely on MDM. Centralized management via MDM reduces the operational work required to configure and maintain distributed kiosk devices. Plus, IT gains from over-the-air deployment, real-time telemetry, and silent policy updates across thousands of distributed endpoints simultaneously. MDM transforms a high-overhead manual chore into an efficient, repeatable cloud operation.

Prerequisites for website lockdown

Before applying kiosk profiles, ensure you have the following in place:

Crucial tip on allowed website dependencies: A single website may depend on additional domains for login, images, scripts, payment, analytics, APIs, or identity provider redirects. Before rollout, test the website and add only the required supporting domains to the allowlist.

In Scalefusion, the workflow combines Windows device profiles with Allowed Websites and the appropriate kiosk/app configuration. IT admins can create the approved website entry, enable it in the Windows profile, configure the required kiosk experience, and assign the profile to managed devices. The exact implementation differs between Single App/Kiosk Mode and Multi-App Kiosk Mode.

Single-app vs. Multi-app kiosk mode: Which one to choose?

Single-app kiosk: It locks the device to a single app running in full screen. For a browser-based workflow, it can launch one designated browser as the primary user experience. Microsoft Assigned Access supports Edge in a full-screen kiosk experience, while Scalefusion provides additional Single App/Kiosk configuration options based on the app type and enrollment mode.

Multi-app kiosk: It locks the device to more than one app. Deploy it when users need access to a defined set of approved applications rather than a single app. In Scalefusion, the interface and enforcement behavior depend on whether the policy is applied through Windows MDM CSP or the Scalefusion MDM Agent.

Manual configurations such as modifying the hosts file, using browser extensions, or setting up Assigned Access locally might work for a single test device. However, they are difficult to scale, secure, and maintain across a fleet. For organizations deploying public kiosks, frontline devices, or educational terminals, MDM is a more effective way to centrally enforce and monitor these policies.

Let’s look at the step-by-step methods to allow only one website using an MDM solution like Scalefusion.

Method 1: Allow only one website using single-app kiosk mode

Note: For current prerequisites and dashboard options, see the Scalefusion Help guide for Windows Single App/Kiosk Mode.

  1. Log into the Scalefusion dashboard: From the left menu section, navigate to Device Profiles & Policies > Allowed Websites.

Before we dive into the steps to lock Windows 10 devices to a single website, watch this video to learn how to allow only certain websites on your Windows fleet.

Allow Only One Website on Windows
  1. Allowlist the website: Click on Allow a Website. Enter the name and URL of the website you want to allow. Save your settings.
One Website in kiosk mode
  1. Create a device profile: Go to Device Profiles & Policies > Device Profiles and create a new Windows 10/11 profile.
Allow Only One Website
  1. Configure single-app mode: Choose Skip Application Policy in Select Apps.
Only One Website on Windows
  1. In Allowed Websites, enable the website you allowlisted in Step 2.
Windows single app kiosk mode
  1. Configure the kiosk app: Choose a browser app in Settings > Single/Kiosk App Mode. Note: For the policy to take effect, the selected browser app should be pre-installed on the Windows machine.
Kiosk App Mode
  1. Configure browser settings: Select the website you allowlisted in Step 2 as the default launch URL and set the browser installation path. Hide browser navigation keys. Enter the user account for the kiosk app.
Windows kiosk app.
  1. Apply the policy: Save the device profile and assign it to your target device groups.
Modal: Apply to Devices or Groups with tabs for Device Groups, User Groups, Devices; shows zero selections and a list of groups with counts.

Method 2: Allow only one website using multi-app kiosk mode

Note: For current prerequisites and dashboard options, see the Scalefusion Help guide for ‘Configure Multi-App Kiosk on Windows.’

  1. Log into the Scalefusion dashboard: From the left menu section, navigate to Device Profiles & Policies > Allowed Websites.
Allowed Websites
  1. Allowlist the website: Click on Allow a Website. Enter the name and URL of the website you want to allow. Save your settings.
Allowed Websites in windows
  1. Create a device profile: Go to Device Profiles & Policies > Device Profiles and create a new Windows 10/11 profile.
Allowed Websites in windows device
  1. Configure multi-app mode: In Multi-App Kiosk Mode, choose how to apply the policy. Note: In Scalefusion MDM Agent mode, you get the ‘Enable Advanced Protection using App Locker’ option to prevent users from launching disallowed apps.
Multi-App Kiosk Mode
  1. Add the user account: In Add User Info, configure the user account this policy will be applied to.
Windows Multi-App Kiosk Mode
  1. Add multiple apps: In Select Apps, enable the apps, including a browser app, that you want to allow end users to access.
Allowed one Websites
  1. In Allowed Websites, enable the website you allowlisted in Step 2.
Allowed only one Websites
  1. Apply the policy: Save the device profile and assign it to your target device groups.
Allowed Websites

Industry use cases of allowing one website on Windows 10

Restricting access to a single website provides controlled web access across various sectors:

  • Retail and hospitality: Tablets locked to an online catalog or self-service check-in portal to support customer engagement and reduce distractions.
  • Healthcare: Kiosks locked to a patient registration portal limit users to the configured app experience, supporting privacy alongside broader organizational security controls.
  • Education: Lab computers restricted to a single testing website, helping prevent access to unauthorized internet resources during exams.
  • Logistics and frontline: Warehouse workstations restricted to a cloud-based inventory application to support uptime and simplify the daily worker experience.

Restrict Website Access with Ease!

Allow only one website in Windows 10 effortlessly.

Get a Free Trial

Best practices for single website restriction on Windows 10

Enable session resets: For public-facing kiosks, configure browser policies to automatically clear cache, cookies, and session data after a set period of inactivity.

Match the browser to kiosk workflow: Each supported browser has different behavior in MDM. Validate the selected browser and ‘allowed websites’ configuration against the intended restriction before rollout.

Test allowed website dependencies: Always test your site and allowlist critical dependencies like login domains (e.g., Microsoft Entra ID), CDNs, APIs, and payment gateways before deployment.

Hide navigation controls: Disable the address bar, back/forward buttons, and developer tools to help prevent users from navigating away from the intended app.

Enable single website access on Windows 10 with Scalefusion

Restricting Windows 10 devices to a single website is a practical way to support purpose-driven, secure digital experiences. Whether it’s for retail kiosks, self-service stations in hospitality, or focused learning environments in education, the ability to allow only one website on Windows helps provide better control, reduce distractions, and improve user engagement.

While local methods like manual Assigned Access or browser extensions might work for a quick test on a single computer, they are difficult to manage at scale for business deployments.

Using an MDM solution like Scalefusion UEM allows IT admins to centrally manage devices, configure Edge kiosk URLs, and deploy necessary domain allowlists across their entire fleet to provide controlled web access. Instead of manually configuring each machine, IT teams can efficiently deploy policies and support compliance efforts over the air.

FAQs

1. How can I block all websites except one on Windows 10?

For business or kiosk deployments, a more reliable method is to use Windows kiosk mode with a managed browser and an allowed website policy through MDM. Other methods are not suitable for scalable deployment, easier to bypass, harder to manage, and have technical limitations.

2. Can I use the Windows hosts file or Firewall instead?

While you can edit the hosts file or set manual firewall rules, these methods typically operate at the IP/network level rather than providing clean, URL-level website allowlisting. They are highly brittle, do not handle modern CDNs well, and are not recommended as fleet-grade business methods.

3. Does kiosk mode ensure the device is fully secure?

Kiosk mode limits users to the configured app experience, reducing unnecessary access to other apps and Windows surfaces. It should be used alongside patching, account controls, network security, and other controls required by the organization’s security or compliance program.

4. Which versions of Windows 10 support kiosk mode?

Native kiosk mode (Assigned Access) is available on Windows 10 Pro, Enterprise, and Education editions. Windows 10 Home does not support this feature natively. For organizations looking to lock down a fleet of devices to a single website using MDM, ensuring devices run a supported Windows 10 or Windows 11 edition is a necessary prerequisite.

5. How do I exit or unlock a Windows 10 kiosk device?

How you exit or remove kiosk mode depends on how the device was configured. For MDM-managed devices, IT can remove or update the assigned kiosk policy centrally. For locally configured Assigned Access devices, an IT admin can remove or change the kiosk configuration using the applicable Windows administration method, such as Settings or PowerShell.


Renuka Shahane
Renuka Shahane
Renuka Shahane is a writer and editor at Scalefusion blog. An avid reader who loves writing about technology, she likes translating technical jargon into consumable content.

More from the blog

How to deploy and manage Claude Code in the...

Your developers have probably already found Claude Code. The question is whether your IT team has. That gap, between when...

5 Strategies to Secure Your Public-Facing Kiosks

With technology taking over manual operations, businesses are increasingly relying on digital devices. The deployment of public-facing kiosks for...

How to Set up Apple TV in Kiosk Mode

You can set up Apple TV in kiosk mode by using Apple Business Manager with an MDM solution to...