You can allow only one website in Windows 10 by using browser kiosk mode, Assigned Access, web filtering, firewall rules, or an MDM solution to restrict the device to a single approved URL. For businesses, schools, and public-use devices, MDM-based website restriction is the most reliable approach because it lets IT teams remotely lock Windows 10 devices to one website, block unauthorized browsing, and keep devices secure for focused use cases.
Key Takeaways
Allowing only one website on Windows 10 transforms standard devices into secure, purpose-built kiosks for self-service, learning, digital signage, and frontline workflows.
- Use Dedicated Kiosk Mode: Single-app mode restricts the device to one website, while multi-app kiosk mode can provide access to the approved website alongside selected business applications.
- Create a Strict Website Allowlist: Add only the required website and block all other domains to reduce distractions, prevent unauthorized browsing, and limit exposure to malicious or inappropriate content.
- Lock Down Browser Controls: Hide the address bar, disable back and forward navigation, restrict external links, and auto-launch the approved website to prevent users from leaving the intended experience.
- Apply Policies Centrally at Scale: A UEM platform allows IT teams to configure website and browser settings once and publish them remotely to individual Windows devices or device groups.
- Maintain Security and Availability: Regular browser and operating system updates, scheduled session resets, network filtering, remote monitoring, and pre-deployment testing help keep single-website kiosks secure and operational.
Is it possible to allow only one website on Windows devices? Absolutely, and it’s a common requirement for businesses and institutions that rely on focused, secure device usage. When Windows 10 devices are deployed as dedicated kiosks, configuring them to run a single website ensures a controlled and distraction-free experience.
From retail stores showcasing their online catalogs to hospitality setups offering self-service check-ins or bookings, single website access plays a critical role. In education as well, institutions often need to block all websites except one on Windows devices to keep students focused on a specific learning platform.
With the right kiosk configuration, Windows devices can be transformed into purpose-built tools that deliver seamless and secure web access. Solutions like Scalefusion Windows MDM make it easy to enforce such restrictions or lock kiosk devices to only one website and manage them at scale.
Why restrict Windows devices to one website?
Restricting Windows devices to a single website is a practical approach for organizations that want to create a controlled, secure, and purpose-driven user experience. Whether used in retail stores, schools, or public kiosks, limiting access ensures devices are used exactly as intended.
Key reasons to block all websites except one on Windows devices:
- Enhanced security: Allow access only to a trusted website, reducing exposure to malicious content, phishing attacks, and unauthorized browsing.
- Improved productivity and focus: Eliminate distractions by blocking unrelated websites, ensuring users stay engaged with the intended task or application.
- Consistent user experience: Deliver a uniform interface across all devices, which is ideal for kiosks, self-service stations, and customer-facing environments.
- Reduced misuse and errors: Prevent users from navigating away, downloading unauthorized files, or making unintended system changes.
- Lower IT overhead: Ensure fewer variables for easier troubleshooting, reduced maintenance, and streamlined device management.
- Better bandwidth and data control: Limit internet usage to a single website for controlling data costs and optimizing network performance.
- Purpose-built device usage: Transform Windows devices into dedicated tools for specific use cases like browsing a catalog, taking surveys, or accessing a web app.
Methods to allow only one website on Windows 10
Scalefusion Windows MDM allows businesses to lock their kiosk devices to only one website. There are two ways to restrict Windows 10 devices to a single website:
- Lock the Windows 10 device in single-app mode, allowing only one website.
- Lock the Windows 10 device in multi-app kiosk mode, allowing only one website in the selected browser.
How to allow only certain websites on Windows devices
Before we dive into the steps to lock Windows 10 devices to a single website, watch this video to learn how to allow only certain websites on your Windows fleet.
Restrict Website Access with Ease!
Allow only one website in Windows 10 effortlessly.
Steps to allow only one website on Windows 10 devices
Locking Windows devices to a single website is effortless with Scalefusion.
Experience every step of the process firsthand with our interactive demo:
This approach allows you to restrict web access to only one website, ensuring a secure and controlled browsing experience on Windows devices. It helps improve productivity and minimizes the risk of unauthorized or unsafe web usage.
Single-app kiosk mode method
Here’s a step-by-step process of allowing only one website on Windows 10 devices in single-app mode:
Getting started: Configure Scalefusion Windows 10 management on your devices.
Step 1: Navigate to the Allowed Websites section under Device Profiles & Policies on the Scalefusion dashboard.

Step 2: Click the Allowed a Website button. Enter the name and URL of the website you want to allow. In this example, we are allowing Scalefusion on Windows 10 devices. Click Next to save your settings. Skip the Apple and Android settings as they are not relevant for Windows 10.

Step 3: Go to the Device Profiles & Policies section and select the Windows 10 profile you want to configure. If you haven’t created one, start by setting up a new Windows 10 device profile. Enter the device profile name and hit Submit.

Step 4: To allow only one website in single-app mode, choose Skip Application Policy.

Step 5: Go to Allowed Websites to enable the website that you want to allow on your Windows 10 devices. Toggle on the Enabled button against the website that you want to allow.

Step 6: Configure Google Chrome in Settings > Single/Kiosk App Mode to restrict access to only the allowed website on your Windows 10 devices.

Step 7: To prevent users from accessing other websites, disable forward and back navigation and hide the address bar in Google Chrome from Configure Browser Settings on the same page. Configure user account selection for kiosk and click Create Profile.

Step 8: If you want to allow only one website on Windows 10 devices using a Microsoft kiosk browser, select Windows Kiosk Browser in Select the Browser App on the same page. Disable browser navigation settings the same way as Chrome to ensure users can access only the allowed website.

Step 9: Navigate to Device Profiles & Policies, select the device profile you have created, and apply it to your Windows 10 device groups or individual devices. You will now see only one allowed website accessible across your Windows 10 fleet.

Multi-app kiosk mode method
Here’s a step-by-step process of allowing only one website on Windows 10 devices in multi-app mode:
Getting started: Configure Scalefusion Windows 10 management on your devices.
Step 1: Navigate to the Allowed Websites section under Device Profiles & Policies on the Scalefusion dashboard.

Step 2: Click the Allowed a Website button. Enter the name and URL of the website you want to allow. In this example, we are allowing Scalefusion on Windows 10 devices. Click Next to save your settings. Skip the Apple and Android settings as they are not relevant for Windows 10.

Step 3: Go to the Device Profiles & Policies section and select the Windows 10 profile you want to configure. If you haven’t created one, start by setting up a new Windows 10 device profile. Enter the device profile name and hit Submit.

Step 4: To allow only one website in multi-app mode, choose Multi-App Kiosk Mode. Configure policy mode, enabling Advanced Protection using App Locker if you’re applying the policy using Scalefusion MDM Agent App.

Step 5: Add user information. In Select Apps, choose Google Chrome and enable it.

Optionally, navigate to General Settings for selecting Google Chrome to auto-launch it on your Windows 10 device. Configure Display Settings if required.

Step 6: Go to Allowed Websites to enable the website that you want to allow on your Windows 10 devices. Toggle on the Enabled button against the website that you want to allow.

Step 7: Navigate to Device Profiles & Policies, select the device profile you have created, and apply it to your Windows 10 device groups or individual devices. You will now see only one allowed website accessible across your Windows 10 fleet.

You can successfully allow only one website in Windows 10 devices using the steps mentioned above.
Industry use cases for restricting Windows 10 devices to one website
Restricting Windows devices to a single website transforms them into purpose-built digital kiosks. By locking access to only one web app or URL, organizations can create a controlled, secure, and distraction-free environment tailored to specific business needs. This approach is widely adopted across industries where focused user interaction and data security are critical.
Here are some key industry use cases:
Retail: In-store browsing & self-service kiosks
Retail businesses use single-website Windows kiosks to display product catalogs, online storefronts, or promotional pages. Customers can browse items, check availability, or place orders without accessing unrelated websites. This ensures brand consistency while preventing misuse of in-store devices.
Hospitality: Self check-in, booking, and ordering
Hotels, restaurants, and service centers deploy kiosks for self check-ins, reservations, and ordering systems. Locking devices to a single website ensures users interact only with the intended service portal, improving efficiency and reducing staff dependency.
Education: Controlled digital learning environments
Schools and training centers restrict devices to a single learning platform, examination portal, or educational website. This eliminates distractions, prevents access to unauthorized content, and helps maintain focus during classes or assessments.
Healthcare: Patient check-in & information access
Hospitals and clinics use locked-down Windows kiosks for patient registration, appointment scheduling, and health information portals. They allow only one website on Windows to ensure patient data privacy and prevent accidental or intentional misuse of sensitive systems.
Logistics and transportation: Driver & fleet management
In logistics, devices used by drivers can be restricted to a single web-based tracking or reporting system. This ensures compliance, reduces distractions, and improves operational efficiency for fleet management.
Corporate & frontline operations: Task-specific devices
Organizations deploy Windows devices locked to internal dashboards, CRM portals, or workflow applications for frontline workers. This setup minimizes distractions and ensures employees use devices strictly for business-critical tasks.
Digital signage: Public information & display systems
Single-website kiosks are commonly used for digital signage, information displays, and interactive wayfinding systems. These devices continuously run a specific webpage or dashboard, delivering consistent information without user interference.
Best practices for allowing only one website on Windows 10
Implementing a single-website kiosk setup on your Windows 10 fleet can be straightforward, but maintaining it securely and efficiently requires a few best practices. These ensure your devices stay locked down, reliable, and user-friendly over time.
1. Use dedicated kiosk mode instead of workarounds
Always configure devices using Windows kiosk mode (single-app or multi-app) rather than relying only on browser settings or extensions. Kiosk mode ensures the device is fully locked down, preventing access to the desktop, system settings, or other apps.
2. Add only the required website to your allowlist
Allowing multiple URLs defeats the purpose of restricting Windows devices to a single website. Create a strict allowlist with just the required website and block everything else. This reduces exposure to malicious or irrelevant content and keeps the user experience focused.
3. Lock down browser controls
Disable navigation elements like the address bar, back/forward buttons, and external links. This prevents users from navigating away from the allowed website even within the browser environment.
4. Set the website as the homepage and auto-launch
Configure the browser to automatically launch the allowed website on startup. This ensures a seamless experience and eliminates the need for user interaction after reboot or session reset.
5. Prevent access to unsupported browsers
Ensure only the configured browser (e.g., Chrome or Windows Kiosk Browser) is available. Disable or restrict other browsers like Edge if they cannot enforce strict website restrictions.
6. Enable automatic session reset or device reboot
For public-facing kiosks, schedule periodic reboots or session resets. This clears cache, cookies, and user data, maintaining performance and preventing misuse.
7. Use secure network controls
Complement kiosk restrictions with network-level controls such as firewalls or DNS filtering. This adds an extra layer of protection by blocking unauthorized domains outside the device configuration.
8. Monitor and manage devices remotely
Use an MDM solution like Scalefusion to monitor device health, push updates, and troubleshoot issues remotely. Continuous monitoring helps ensure uptime and compliance across all deployed devices.
9. Keep the system and browser updated
Regular updates patch vulnerabilities and improve performance. Outdated browsers or OS versions can introduce security risks even in a restricted setup.
10. Test thoroughly before deployment
Before rolling out devices at scale, test the configuration in real-world scenarios. Validate that users cannot bypass restrictions and that the website behaves correctly in kiosk mode.
Enable single website access on Windows 10 with Scalefusion
Restricting Windows 10 devices to a single website is a practical way to create secure, purpose-driven digital experiences. Whether it’s for retail kiosks, self-service stations in hospitality, or focused learning environments in education, the ability to allow only one website on Windows ensures better control, reduced distractions, and improved user engagement.
With Scalefusion UEM, businesses can efficiently block all websites except one on Windows devices, whether through the single-app or multi-app kiosk mode method. Scalefusion helps you take full command of your Windows devices and lock them down to a single website, maintaining performance and security. Start streamlining your operations and delivering a seamless user experience across your Windows fleet.
FAQs
1. How can I block all websites except one on Windows 10?
To allow only one website on Windows 10, use built-in tools like Windows Defender Firewall with Advanced Security, Microsoft Family Safety, or LAN proxy settings, third-party software, or manually edit the host file. Create a custom rule to block all traffic except for a specific URL, effectively restricting browsing to the approved site only. However, a Windows MDM solution like Scalefusion can be a better choice because of factors such as centralized and enterprise-grade control, bulk remote deployment, advanced management and kiosk modes, enforcement level, feature depth, and detailed reporting.
2. How can I restrict browsing to specific websites in Windows 10?
Restricting access to certain websites on Windows 10 involves various methods. You can use Microsoft Family Safety or Windows Firewall, modify the host file, configure proxy and browser settings, enforce parental controls, or deploy third-party software or browser extensions to enforce the restriction. These methods ensure users can only access the designated websites while blocking access to others. However, Windows MDM platforms like Scalefusion are a more robust, enterprise-grade alternative to these methods, allowing you to centrally manage a list of approved websites across your entire fleet.
3. What are the benefits of allowing only one website in Windows 10?
Allowing only one website in Windows 10 offers several benefits. It enhances productivity by minimizing distractions, improving focus on essential tasks, and reducing the risk of exposure to potentially harmful or inappropriate content. Additionally, it can enhance security by limiting access to trusted and verified websites only.
4. How do I block websites on Google Chrome?
To block websites on Chrome, use the “BlockSite” extension. Install it from the Chrome Web Store, and then access its settings by clicking the extension icon. Add the URLs of websites you want to block, and they will be inaccessible from your browser. For stronger, tamper-resistant controls, consider using MDM solutions like Scalefusion. These tools allow you to enforce website restrictions across managed devices rather than relying on browser-level extensions alone.
5. Can I restrict browser access to only one website on Windows without using third-party tools?
Yes, you can modify Windows Group Policy (GPO), use Registry Editor, or configure browser kiosk mode to restrict browsers to only one website. Instead of third-party tools, you can consider using a Windows MDM solution like Scalefusion which offers professional-grade lockdown features that are much more difficult to bypass than other methods. It allows you to restrict browser access to only one allowed website across thousands of Windows devices from a single dashboard.


