I manage several shared computers that use generic accounts and need to be locked down as much as possible. Each machine should provide access to only two or three approved websites and two or three desktop applications. We use on-premises Active Directory and Group Policy, with no Microsoft Intune. What is the most practical way to configure this? Can a multi-app kiosk setup be deployed through Group Policy or another built-in Windows tool?
3 Answers
Group Policy can handle parts of this, especially browser policies, managed favorites, Software Restriction Policies, and AppLocker. The catch is that building a genuinely locked-down desktop takes a lot of testing and maintenance. You have to account for every helper process, update component, file association, and escape route, so it can become messy quickly.
If the built-in kiosk features do not meet the requirements, a third-party kiosk or endpoint-management product may be worth evaluating. These tools usually provide a simpler interface for allowlisting applications and websites and managing several kiosk computers, though licensing costs need to be weighed against the time required to maintain a custom Group Policy solution.
Windows multi-app kiosk mode is probably the best built-in option. It supports a defined list of desktop applications and allowed websites, and it can be deployed with a provisioning package rather than requiring Intune. Check that the Windows edition and build support multi-app assigned access, since older Windows 11 builds had some issues.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures