Skip to main content

Managed guest sessions

A managed guest session provides a policy-controlled shared browsing environment without requiring each person to sign in with an enterprise account.

Use it for shared workstations, loan devices, reception computers, and other multi-user environments. Use Kiosk instead when a device should run one full-screen app.

Before you begin​

  • Use a Business+ managed device.
  • Place shared devices in a dedicated organisational unit.
  • Define session length, permitted apps, browsing restrictions, and data-retention requirements.
  • Decide whether users need a full multi-site desktop session. Use Kiosk for one full-screen app.
  • Keep an administrator recovery path outside the shared-device unit while testing.

Enable the session​

  1. Open Business+ → Managed Guest Session Settings.
  2. Select the shared-device organisational unit.
  3. Find Managed guest session under General.
  4. Enable it.
  5. Configure Maximum user session length if the session must end automatically. The current field accepts 1 to 1440 minutes; leave it empty for an unlimited session.
  6. Optionally upload custom terms of service, an avatar, and wallpaper.
  7. Review Updated setting entries and click Save.

Add apps and extensions​

  1. Open Business+ → Apps & Extensions.
  2. Select the Managed Guest Sessions tab.
  3. Select the same organisational unit.
  4. Click Add and choose the app or extension source.
  5. Set the installation policy.
  6. Click Save.

Configure session behaviour​

Return to Business+ → Managed Guest Session Settings. The current page includes:

  • Apps and extensions, task manager, Manifest V2 behaviour, and background lifetime.
  • Security, incognito mode, browser history, browsing-data lifetime, screenshots, remote debugging, and other security controls.
  • Remote access, client/host domains, firewall traversal, relay servers, UDP range, clipboard size, and enterprise remote support.
  • Session settings, logout controls.
  • Network, proxy, TLS, DNS-over-HTTPS, QUIC, WebRTC, and authentication.
  • Startup and Content, homepage, startup pages, browser launch, site permissions, downloads, pop-ups, and capture.
  • Power and shutdown, idle, screen, sleep, lid, and lock behaviour.
  • Hardware and Accessibility, storage, USB, camera, microphone, keyboard, screen reader, magnifier, and other supported controls.

Apply only settings required for the shared-device use case. A restrictive network or website policy can also block sign-in, policy sync, or required app dependencies.

Session data​

A managed guest session does not require each person to use an enterprise account. Define what should happen to browsing history, downloads, cookies, cache, passwords, autofill, site settings, and hosted-app data.

Test sign-out behaviour directly. Do not assume that closing a browser window, ending a session, and erasing all device user data have the same effect.

Verify​

  1. Restart a pilot device.
  2. Confirm that the managed guest session appears on the sign-in screen.
  3. Open the session and check apps, websites, session length, and sign-out behaviour.
  4. Test network, printing, downloads, USB/peripherals, and accessibility where required.
  5. End the session and verify that data is handled according to policy.
  6. Restart and repeat once before wider rollout.

Common problems​

  • Session is missing, check the device's organisational unit and that Managed guest session is enabled.
  • Apps are missing, confirm the Managed Guest Sessions app tab and the same unit were used.
  • Unexpected settings, check inheritance and local overrides.
  • Websites fail, check URL lists, proxy, DNS, certificates, app runtime-host rules, and authentication redirects.
  • Session ends too soon, check the 1 to 1440 minute maximum session value and power/idle settings.
  • Kiosk behaviour appears instead, confirm the device is not configured with a kiosk auto-launch app for that unit.

What's next​