Managed guest sessions
A managed guest session provides a policy-controlled shared browsing environment without requiring each person to sign in with an enterprise account.
Use it for shared workstations, loan devices, reception computers, and other multi-user environments. Use Kiosk instead when a device should run one full-screen app.
Before you begin
- Use a Business+ managed device.
- Place shared devices in a dedicated organisational unit.
- Define session length, permitted apps, browsing restrictions, and data-retention requirements.
- Decide whether users need a full multi-site desktop session. Use Kiosk for one full-screen app.
- Keep an administrator recovery path outside the shared-device unit while testing.
Enable the session
- Open Business+ → Managed Guest Session Settings.
- Select the shared-device organisational unit.
- Find Managed guest session under General.
- Enable it.
- Configure Maximum user session length if the session must end automatically. The current field accepts 1 to 1440 minutes; leave it empty for an unlimited session.
- Optionally upload custom terms of service, an avatar, and wallpaper.
- Review Updated setting entries and click Save.
Add apps and extensions
- Open Business+ → Apps & Extensions.
- Select the Managed Guest Sessions tab.
- Select the same organisational unit.
- Click Add and choose the app or extension source.
- Set the installation policy.
- Click Save.
Configure session behaviour
Return to Business+ → Managed Guest Session Settings. The current page includes:
- Apps and extensions, task manager, Manifest V2 behaviour, and background lifetime.
- Security, incognito mode, browser history, browsing-data lifetime, screenshots, remote debugging, and other security controls.
- Remote access, client/host domains, firewall traversal, relay servers, UDP range, clipboard size, and enterprise remote support.
- Session settings, logout controls.
- Network, proxy, TLS, DNS-over-HTTPS, QUIC, WebRTC, and authentication.
- Startup and Content, homepage, startup pages, browser launch, site permissions, downloads, pop-ups, and capture.
- Power and shutdown, idle, screen, sleep, lid, and lock behaviour.
- Hardware and Accessibility, storage, USB, camera, microphone, keyboard, screen reader, magnifier, and other supported controls.
Apply only settings required for the shared-device use case. A restrictive network or website policy can also block sign-in, policy sync, or required app dependencies.
Session data
A managed guest session does not require each person to use an enterprise account. Define what should happen to browsing history, downloads, cookies, cache, passwords, autofill, site settings, and hosted-app data.
Test sign-out behaviour directly. Do not assume that closing a browser window, ending a session, and erasing all device user data have the same effect.
Verify
- Restart a pilot device.
- Confirm that the managed guest session appears on the sign-in screen.
- Open the session and check apps, websites, session length, and sign-out behaviour.
- Test network, printing, downloads, USB/peripherals, and accessibility where required.
- End the session and verify that data is handled according to policy.
- Restart and repeat once before wider rollout.
Common problems
- Session is missing, check the device's organisational unit and that Managed guest session is enabled.
- Apps are missing, confirm the Managed Guest Sessions app tab and the same unit were used.
- Unexpected settings, check inheritance and local overrides.
- Websites fail, check URL lists, proxy, DNS, certificates, app runtime-host rules, and authentication redirects.
- Session ends too soon, check the 1 to 1440 minute maximum session value and power/idle settings.
- Kiosk behaviour appears instead, confirm the device is not configured with a kiosk auto-launch app for that unit.
What's next
- Manage apps and extensions, deploy apps to managed guest sessions.
- Control website access, set URL rules for guest browsing.
- Sign-in and local user data, compare guest sessions with other device modes.