How to Lock Down an iPad for Customer-Facing Use

The iPad is one of the most widely deployed customer-facing devices in the world. Retailers use them at checkout. Restaurants use them at the table and at the counter. Hotels use them for guest check-in and in-room services. Healthcare facilities use them for patient intake and wayfinding. The hardware is familiar, durable in its consumer form, and readily available.

The challenge is that a stock iPad is a general-purpose device. Without the right configuration, a customer-facing iPad can be navigated away from its intended app, have its settings changed, access the internet freely, or expose whatever account is logged into it. That is not acceptable for a business deployment.

Locking down an iPad for customer-facing use requires Apple’s supervised mode and a properly configured MDM platform. This guide covers exactly what to set up and why each step matters.

Step 1: Understand Apple Supervised Mode

Everything in iPad lockdown for business starts with supervised mode. Supervised mode is Apple’s designation for corporate-owned devices that are fully managed by an organization. It unlocks a significantly expanded set of MDM management capabilities that are not available on unsupervised devices.

Without supervised mode, an MDM can push apps and enforce some basic restrictions, but users can still remove the MDM profile, navigate to the App Store, and change many device settings. Supervised mode removes those escape routes. The organization has full control, and the MDM profile cannot be removed by the user.

Supervised mode can be applied in two ways:

  • Through Apple Business Manager (ABM) combined with Moki’s MDM. Devices purchased through Apple or an authorized reseller are automatically enrolled in ABM and can be supervised at activation. This is the preferred approach for new deployments.
  • Through Apple Configurator 2 on a Mac, which can apply supervision to devices that were not purchased through ABM. This is the fallback for devices already in hand that need to be enrolled manually.

Moki’s iOS MDM platform integrates with Apple Business Manager to support supervised enrollment and all of the management capabilities that come with it.

Step 2: Enroll the Device in Moki

Once supervision is applied, the device needs to be enrolled in Moki’s MDM platform to receive its configuration profile. For devices going through Apple Business Manager, this happens automatically at activation. When the device is powered on, it contacts Apple’s servers, receives the MDM enrollment profile from Moki, and enrolls without any user action at the device.

For devices enrolled through Apple Configurator 2, the enrollment MDM profile is applied during the Configurator process, and the device enrolls in Moki when it connects to the internet.

After enrollment, the device appears in the Moki dashboard and is ready to receive configuration.

Step 3: Apply Single App Mode or Guided Access

The core of iPad lockdown for customer-facing use is restricting the device to a single application. Apple offers two mechanisms for this:

Single App Mode (SAM) is a supervised-only feature controlled entirely by the MDM. When Single App Mode is enabled for a specific app through Moki, the device locks itself to that application. The Home button, the Control Center, notifications, and all navigation outside the locked app are disabled. The user cannot leave the app under any circumstances without the MDM releasing the lock.

Single App Mode is the right choice for true customer-facing kiosk deployments where the device should never show anything other than the designated app. It is the strictest form of lockdown available on iOS.

Guided Access is a device-level feature that a user or technician can enable directly on the device. It also locks the device to a single app and can restrict touch input to specific areas of the screen. Guided Access is useful in situations where a human is present to initiate the lockdown, such as a device handed to a patient or customer for a specific interaction.

For most unattended customer-facing deployments, Single App Mode through Moki is the correct configuration. Moki’s iOS management capabilities support Single App Mode configuration as part of the device profile.

Step 4: Configure Restrictions Through the MDM Profile

Beyond locking to a single app, a properly configured customer-facing iPad profile should include restrictions that prevent any deviation from the intended device state. Through Moki, the following restrictions should be configured for most customer-facing deployments:

  • Disable the App Store so no additional apps can be downloaded
  • Disable Safari and any other browser that is not part of the locked experience
  • Disable screen recording, AirDrop, and AirPlay to prevent content sharing
  • Disable notifications so system alerts do not interrupt the customer experience
  • Disable the camera if the use case does not require it
  • Disable Siri to prevent voice commands from being used to navigate outside the locked app
  • Configure the screen to turn off after a defined idle period and return to the app start state
  • Disable in-app purchases if the app includes any marketplace functionality
  • Set a passcode restriction so the device cannot be accessed without IT credentials

These restrictions are configured in the device profile within Moki and applied remotely. Any device in the assigned profile group receives the restrictions automatically upon enrollment or profile update.

Step 5: Configure Wi-Fi and Network Settings

A customer-facing iPad should connect to the correct Wi-Fi network automatically without requiring manual configuration at the device. The MDM profile should include the Wi-Fi credentials for the deployment network so the device connects at activation and reconnects automatically after reboots.

For deployments in environments where customers have access to the same network, consider using a dedicated VLAN or network segment for managed devices to isolate their traffic. MDM does not configure the network infrastructure itself, but Moki can push Wi-Fi profiles that direct devices to the correct SSID for their location.

Step 6: Set Up Monitoring and Alerts

A locked-down iPad that no one is watching is still a risk. Moki’s alert system should be configured to notify the appropriate team member when:

  • The device goes offline for longer than a defined threshold
  • The battery drops below a level that could cause the device to power off
  • The app crashes or stops running
  • The device is no longer in Single App Mode unexpectedly

For point-of-sale environments, a down device is a lost transaction. For digital kiosk environments, a down device is a failed customer experience. Real-time alerts through Moki mean those situations are detected and addressed in minutes rather than discovered hours later.

Step 7: Test Before Deployment

Every customer-facing iPad configuration should be fully tested before the device ships to a location. A pre-deployment checklist should confirm:

  • Single App Mode is active and the correct app launches at startup
  • All restricted features are disabled and cannot be accessed
  • Wi-Fi connects automatically at the deployment network
  • The device appears correctly in the Moki dashboard with the correct profile applied
  • Alerts are configured and a test alert has fired successfully
  • Remote reboot and remote app push have been tested and confirmed functional

Testing one device thoroughly before a bulk deployment prevents misconfigured devices from reaching customers and eliminates the support burden of troubleshooting configuration errors at remote locations.

Ongoing Management of Locked-Down iPads

After deployment, all app updates, content changes, and configuration adjustments happen remotely through Moki. There is no need to physically touch the device for routine management. App updates are pushed silently through Apple Business Manager. Profile changes are applied remotely and take effect at the next device check-in. If a device needs to be rebooted, it can be done from the Moki dashboard without calling anyone at the location.

Moki’s iOS platform is built specifically for this kind of dedicated device management, handling the supervision, enrollment, lockdown, and ongoing monitoring in a single unified workflow.

Schedule a Moki demo to see iPad lockdown and supervision in action, or start a free trial to begin configuring your first supervised iOS deployment. Moki’s support resources cover the Apple Business Manager integration and Configurator enrollment steps in detail.

See Moki in Action

Request a Demo today with by phone, email, or just fill out the form






Skip to content