How to Allow Only One Website on Windows 10

Published January 22, 2023 by Renuka Shahane in Kiosk Software
About Scalefusion
 

One Platform for Devices, Access, and Security

  • Manage every device, laptops, phones, and tablets from one dashboard
  • Employees sign in to company devices and work apps with one login, no separate passwords
  • Automatically check devices against security benchmarks and block risky apps and sites

Book a Demo

Every device.
Every OS.
One platform.

Start Free Trial

No credit card required, full access to all features.

You can allow only one website in Windows 10 by using browser kiosk mode, Assigned Access, web filtering, firewall rules, or an MDM solution to restrict the device to a single approved URL. For businesses, schools, and public-use devices, MDM-based website restriction is the most reliable approach because it lets IT teams remotely lock Windows 10 devices to one website, block unauthorized browsing, and keep devices secure for focused use cases.

Key Takeaways

Allowing only one website on Windows 10 transforms standard devices into secure, purpose-built kiosks for self-service, learning, digital signage, and frontline workflows.

  • Use Dedicated Kiosk Mode: Single-app mode restricts the device to one website, while multi-app kiosk mode can provide access to the approved website alongside selected business applications.
  • Create a Strict Website Allowlist: Add only the required website and block all other domains to reduce distractions, prevent unauthorized browsing, and limit exposure to malicious or inappropriate content.
  • Lock Down Browser Controls: Hide the address bar, disable back and forward navigation, restrict external links, and auto-launch the approved website to prevent users from leaving the intended experience.
  • Apply Policies Centrally at Scale: A UEM platform allows IT teams to configure website and browser settings once and publish them remotely to individual Windows devices or device groups.
  • Maintain Security and Availability: Regular browser and operating system updates, scheduled session resets, network filtering, remote monitoring, and pre-deployment testing help keep single-website kiosks secure and operational.


Is it possible to allow only one website on Windows devices? Absolutely, and it’s a common requirement for businesses and institutions that rely on focused, secure device usage. When Windows 10 devices are deployed as dedicated kiosks, configuring them to run a single website ensures a controlled and distraction-free experience.

From retail stores showcasing their online catalogs to hospitality setups offering self-service check-ins or bookings, single website access plays a critical role. In education as well, institutions often need to block all websites except one on Windows devices to keep students focused on a specific learning platform.

With the right kiosk configuration, Windows devices can be transformed into purpose-built tools that deliver seamless and secure web access. Solutions like Scalefusion Windows MDM make it easy to enforce such restrictions or lock kiosk devices to only one website and manage them at scale.

Why restrict Windows devices to one website?

Restricting Windows devices to a single website is a practical approach for organizations that want to create a controlled, secure, and purpose-driven user experience. Whether used in retail stores, schools, or public kiosks, limiting access ensures devices are used exactly as intended.

Key reasons to block all websites except one on Windows devices:

  • Enhanced security: Allow access only to a trusted website, reducing exposure to malicious content, phishing attacks, and unauthorized browsing.
  • Improved productivity and focus: Eliminate distractions by blocking unrelated websites, ensuring users stay engaged with the intended task or application.
  • Consistent user experience: Deliver a uniform interface across all devices, which is ideal for kiosks, self-service stations, and customer-facing environments.
  • Reduced misuse and errors: Prevent users from navigating away, downloading unauthorized files, or making unintended system changes.
  • Lower IT overhead: Ensure fewer variables for easier troubleshooting, reduced maintenance, and streamlined device management.
  • Better bandwidth and data control: Limit internet usage to a single website for controlling data costs and optimizing network performance.
  • Purpose-built device usage: Transform Windows devices into dedicated tools for specific use cases like browsing a catalog, taking surveys, or accessing a web app.

Methods to allow only one website on Windows 10

Scalefusion Windows MDM allows businesses to lock their kiosk devices to only one website. There are two ways to restrict Windows 10 devices to a single website:

How to allow only certain websites on Windows devices

Before we dive into the steps to lock Windows 10 devices to a single website, watch this video to learn how to allow only certain websites on your Windows fleet.

Restrict Website Access with Ease!

Allow only one website in Windows 10 effortlessly.

Get a Free Trial

Steps to allow only one website on Windows 10 devices

Locking Windows devices to a single website is effortless with Scalefusion.
Experience every step of the process firsthand with our interactive demo:

This approach allows you to restrict web access to only one website, ensuring a secure and controlled browsing experience on Windows devices. It helps improve productivity and minimizes the risk of unauthorized or unsafe web usage.

Single-app kiosk mode method

Here’s a step-by-step process of allowing only one website on Windows 10 devices in single-app mode:

Getting started: Configure Scalefusion Windows 10 management on your devices.

Step 1: Navigate to the Allowed Websites section under Device Profiles & Policies on the Scalefusion dashboard.

ScaleFusion admin: Allowed Websites screen showing no websites added yet, with action buttons (Clear Cache, Browser Settings, Allow a Website).

Step 2: Click the Allowed a Website button. Enter the name and URL of the website you want to allow. In this example, we are allowing Scalefusion on Windows 10 devices. Click Next to save your settings. Skip the Apple and Android settings as they are not relevant for Windows 10.

Modal titled 'Allow a Website' with fields for Website Name and Website Link, and a HomeScreen visibility toggle; background shows the Scalefusion dashboard of allowed websites.

Step 3: Go to the Device Profiles & Policies section and select the Windows 10 profile you want to configure. If you haven’t created one, start by setting up a new Windows 10 device profile. Enter the device profile name and hit Submit.

Modal titled 'Create New Profile' with platform tabs (Android, iOS, Windows, macOS, Linux, ChromeOS) and a text field containing 'Windows 10 Single Website'

Step 4: To allow only one website in single-app mode, choose Skip Application Policy.

Create New Profile page with left navigation and three policy options: Multi-App Kiosk Mode, App Locker Policy, and Skip Application Policy.

Step 5: Go to Allowed Websites to enable the website that you want to allow on your Windows 10 devices. Toggle on the Enabled button against the website that you want to allow.

Settings page for creating a new profile; left navigation and a table of allowed websites with Enable toggles, showing ScaleFusion enabled and others disabled.

Step 6: Configure Google Chrome in Settings > Single/Kiosk App Mode to restrict access to only the allowed website on your Windows 10 devices.

Screen showing a 'Create New Profile' wizard for configuring a kiosk app, with Windows or Scalefusion kiosk mode options and a profile name field at the top right.

Step 7: To prevent users from accessing other websites, disable forward and back navigation and hide the address bar in Google Chrome from Configure Browser Settings on the same page. Configure user account selection for kiosk and click Create Profile.

Profile creation screen: selecting application type and browser app with a left navigation pane and Create Profile button at top-right

Step 8: If you want to allow only one website on Windows 10 devices using a Microsoft kiosk browser, select Windows Kiosk Browser in Select the Browser App on the same page. Disable browser navigation settings the same way as Chrome to ensure users can access only the allowed website.

Create New Profile page with left Settings menu and right form to configure a browser kiosk app (third-party browser).

Step 9: Navigate to Device Profiles & Policies, select the device profile you have created, and apply it to your Windows 10 device groups or individual devices. You will now see only one allowed website accessible across your Windows 10 fleet.

Modal titled 'Apply to Devices or Groups' for selecting device groups to apply changes to (Device Groups, User Groups, Devices) with search, and a list of groups.

Multi-app kiosk mode method

Here’s a step-by-step process of allowing only one website on Windows 10 devices in multi-app mode:

Getting started: Configure Scalefusion Windows 10 management on your devices.

Step 1: Navigate to the Allowed Websites section under Device Profiles & Policies on the Scalefusion dashboard.

ScaleFusion admin console: Allowed Websites page with 'No website added yet!' message, left navigation visible, and three information cards about Safari on iOS and ProSurf for iOS.

Step 2: Click the Allowed a Website button. Enter the name and URL of the website you want to allow. In this example, we are allowing Scalefusion on Windows 10 devices. Click Next to save your settings. Skip the Apple and Android settings as they are not relevant for Windows 10.

Modal dialog 'Allow a Website' with fields for site name and URL; HomeScreen visibility toggled on; example values shown (Scalefusion, scalefusion.com).

Step 3: Go to the Device Profiles & Policies section and select the Windows 10 profile you want to configure. If you haven’t created one, start by setting up a new Windows 10 device profile. Enter the device profile name and hit Submit.

Modal dialog: Create New Profile for Windows 10 Single Website in Scalefusion with Cancel and Submit buttons

Step 4: To allow only one website in multi-app mode, choose Multi-App Kiosk Mode. Configure policy mode, enabling Advanced Protection using App Locker if you’re applying the policy using Scalefusion MDM Agent App.

Create New Profile wizard: left navigation, top header, profile name field, and three policy mode cards with Multi-App Kiosk Mode highlighted.

Step 5: Add user information. In Select Apps, choose Google Chrome and enable it.

Profile setup page showing app selection; Google Chrome listed with enable toggle.

Optionally, navigate to General Settings for selecting Google Chrome to auto-launch it on your Windows 10 device. Configure Display Settings if required.

Screenshot of a 'Create New Profile' wizard showing tabs for Select Apps, Allowed Websites, Passcode Settings, and a right-side 'Add Win32 App' button.

Step 6: Go to Allowed Websites to enable the website that you want to allow on your Windows 10 devices. Toggle on the Enabled button against the website that you want to allow.

Dashboard: Create New Profile screen with profile name field and a list of allowed websites with enabled toggles on each row.

Step 7: Navigate to Device Profiles & Policies, select the device profile you have created, and apply it to your Windows 10 device groups or individual devices. You will now see only one allowed website accessible across your Windows 10 fleet.

Modal titled 'Apply to Devices or Groups' with tabs for Device Groups, User Groups, and Devices; includes search field, an informational banner, and a table of groups with device counts (e.g., Stnd8 0, vaibhav 1).

You can successfully allow only one website in Windows 10 devices using the steps mentioned above.

Industry use cases for restricting Windows 10 devices to one website

Restricting Windows devices to a single website transforms them into purpose-built digital kiosks. By locking access to only one web app or URL, organizations can create a controlled, secure, and distraction-free environment tailored to specific business needs. This approach is widely adopted across industries where focused user interaction and data security are critical.

Here are some key industry use cases:

Retail: In-store browsing & self-service kiosks

Retail businesses use single-website Windows kiosks to display product catalogs, online storefronts, or promotional pages. Customers can browse items, check availability, or place orders without accessing unrelated websites. This ensures brand consistency while preventing misuse of in-store devices.

Hospitality: Self check-in, booking, and ordering

Hotels, restaurants, and service centers deploy kiosks for self check-ins, reservations, and ordering systems. Locking devices to a single website ensures users interact only with the intended service portal, improving efficiency and reducing staff dependency.

Education: Controlled digital learning environments

Schools and training centers restrict devices to a single learning platform, examination portal, or educational website. This eliminates distractions, prevents access to unauthorized content, and helps maintain focus during classes or assessments.

Healthcare: Patient check-in & information access

Hospitals and clinics use locked-down Windows kiosks for patient registration, appointment scheduling, and health information portals. They allow only one website on Windows to ensure patient data privacy and prevent accidental or intentional misuse of sensitive systems.

Logistics and transportation: Driver & fleet management

In logistics, devices used by drivers can be restricted to a single web-based tracking or reporting system. This ensures compliance, reduces distractions, and improves operational efficiency for fleet management.

Corporate & frontline operations: Task-specific devices

Organizations deploy Windows devices locked to internal dashboards, CRM portals, or workflow applications for frontline workers. This setup minimizes distractions and ensures employees use devices strictly for business-critical tasks.

Digital signage: Public information & display systems

Single-website kiosks are commonly used for digital signage, information displays, and interactive wayfinding systems. These devices continuously run a specific webpage or dashboard, delivering consistent information without user interference.

Best practices for allowing only one website on Windows 10

Implementing a single-website kiosk setup on your Windows 10 fleet can be straightforward, but maintaining it securely and efficiently requires a few best practices. These ensure your devices stay locked down, reliable, and user-friendly over time.

1. Use dedicated kiosk mode instead of workarounds

Always configure devices using Windows kiosk mode (single-app or multi-app) rather than relying only on browser settings or extensions. Kiosk mode ensures the device is fully locked down, preventing access to the desktop, system settings, or other apps.

2. Add only the required website to your allowlist

Allowing multiple URLs defeats the purpose of restricting Windows devices to a single website. Create a strict allowlist with just the required website and block everything else. This reduces exposure to malicious or irrelevant content and keeps the user experience focused.

3. Lock down browser controls

Disable navigation elements like the address bar, back/forward buttons, and external links. This prevents users from navigating away from the allowed website even within the browser environment.

4. Set the website as the homepage and auto-launch

Configure the browser to automatically launch the allowed website on startup. This ensures a seamless experience and eliminates the need for user interaction after reboot or session reset.

5. Prevent access to unsupported browsers

Ensure only the configured browser (e.g., Chrome or Windows Kiosk Browser) is available. Disable or restrict other browsers like Edge if they cannot enforce strict website restrictions.

6. Enable automatic session reset or device reboot

For public-facing kiosks, schedule periodic reboots or session resets. This clears cache, cookies, and user data, maintaining performance and preventing misuse.

7. Use secure network controls

Complement kiosk restrictions with network-level controls such as firewalls or DNS filtering. This adds an extra layer of protection by blocking unauthorized domains outside the device configuration.

8. Monitor and manage devices remotely

Use an MDM solution like Scalefusion to monitor device health, push updates, and troubleshoot issues remotely. Continuous monitoring helps ensure uptime and compliance across all deployed devices.

9. Keep the system and browser updated

Regular updates patch vulnerabilities and improve performance. Outdated browsers or OS versions can introduce security risks even in a restricted setup.

10. Test thoroughly before deployment

Before rolling out devices at scale, test the configuration in real-world scenarios. Validate that users cannot bypass restrictions and that the website behaves correctly in kiosk mode.

Enable single website access on Windows 10 with Scalefusion

Restricting Windows 10 devices to a single website is a practical way to create secure, purpose-driven digital experiences. Whether it’s for retail kiosks, self-service stations in hospitality, or focused learning environments in education, the ability to allow only one website on Windows ensures better control, reduced distractions, and improved user engagement.

With Scalefusion UEM, businesses can efficiently block all websites except one on Windows devices, whether through the single-app or multi-app kiosk mode method. Scalefusion helps you take full command of your Windows devices and lock them down to a single website, maintaining performance and security. Start streamlining your operations and delivering a seamless user experience across your Windows fleet.

FAQs

1. How can I block all websites except one on Windows 10?

To allow only one website on Windows 10, use built-in tools like Windows Defender Firewall with Advanced Security, Microsoft Family Safety, or LAN proxy settings, third-party software, or manually edit the host file. Create a custom rule to block all traffic except for a specific URL, effectively restricting browsing to the approved site only. However, a Windows MDM solution like Scalefusion can be a better choice because of factors such as centralized and enterprise-grade control, bulk remote deployment, advanced management and kiosk modes, enforcement level, feature depth, and detailed reporting.

2. How can I restrict browsing to specific websites in Windows 10?

Restricting access to certain websites on Windows 10 involves various methods. You can use Microsoft Family Safety or Windows Firewall, modify the host file, configure proxy and browser settings, enforce parental controls, or deploy third-party software or browser extensions to enforce the restriction. These methods ensure users can only access the designated websites while blocking access to others. However, Windows MDM platforms like Scalefusion are a more robust, enterprise-grade alternative to these methods, allowing you to centrally manage a list of approved websites across your entire fleet.

3. What are the benefits of allowing only one website in Windows 10?

Allowing only one website in Windows 10 offers several benefits. It enhances productivity by minimizing distractions, improving focus on essential tasks, and reducing the risk of exposure to potentially harmful or inappropriate content. Additionally, it can enhance security by limiting access to trusted and verified websites only.

4. How do I block websites on Google Chrome?

To block websites on Chrome, use the “BlockSite” extension. Install it from the Chrome Web Store, and then access its settings by clicking the extension icon. Add the URLs of websites you want to block, and they will be inaccessible from your browser. For stronger, tamper-resistant controls, consider using MDM solutions like Scalefusion. These tools allow you to enforce website restrictions across managed devices rather than relying on browser-level extensions alone.

5. Can I restrict browser access to only one website on Windows without using third-party tools?

Yes, you can modify Windows Group Policy (GPO), use Registry Editor, or configure browser kiosk mode to restrict browsers to only one website. Instead of third-party tools, you can consider using a Windows MDM solution like Scalefusion which offers professional-grade lockdown features that are much more difficult to bypass than other methods. It allows you to restrict browser access to only one allowed website across thousands of Windows devices from a single dashboard.


Renuka Shahane
Renuka Shahane
Renuka Shahane is a writer and editor at Scalefusion blog. An avid reader who loves writing about technology, she likes translating technical jargon into consumable content.

More from the blog

How to Set up Apple TV in Kiosk Mode

You can set up Apple TV in kiosk mode by using Apple Business Manager with an MDM solution to...

Windows LAPS: Benefits, best practices & deployment

Windows LAPS is a Microsoft security feature that automatically manages and rotates local administrator account passwords on Windows devices....

How to enable Windows S mode: A complete guide

Windows S mode represents a fundamentally different approach to using Windows, one that favors structure over unmanaged flexibility. It...