Device pairing and management

Michael Pollitt
Michael Pollitt
  • Updated

To ensure that only authorised devices can access the site data it is possible to monitor and control device access from directly within your risr/ assess instance.

Enrolling iPads

Once the iPad application is installed on each device, the individual device must then be paired with the instance before it can access any exam information. This is achieved through the use of a domain name and secret combination.

To find the domain and secret, navigate to Settings > Devices. If you are accessing your site for the first time you will need to press the generate a new secret button, as shown below.

The system will then generate both a device secret (10-digit code) and QR code (both obscured in the image for security reasons).

For security purposes, we recommend regenerating your device secret regularly. Use the Generate new secret button to do so. Where a secret is regenerated, existing enrolments will remain active, but new enrolments will need to use the new details.

On the device, open up the installed application and either type the domain and secret shown on the site into the corresponding fields, or scan the QR code using the device's camera and press Enrol.

The device is now paired with the instance and will remain so until either: 

It is only possible to have the app paired with one instance of risr/ assess at any one time. If you are moving between instances (perhaps from test to live) you will need to re-enrol the iPads to the new instance.

Access via assess for browser

The assess for browser application does not need to be paired with the instance in advance of a exam. When a candidate or examiner accesses an exam using the browser application, a device record is automatically created in the index.

There is an optional configuration setting <LINK> to force browser access to be approved before it can access the site. If you would like this to be switched on please contact us to discuss.

Managing enrolled devices

Once devices are associated with the instance, either through iPad pre-enrolment or automatic browser enrolment, you have the option to monitor and manage this access via the instance backend. To find this, navigate to Settings > Devices. The screen is shown in the image below:

Enrol devices.png

    1. Search bar: Search for a specific device in the enrolment list.
    2. Sort options: Sort the enrolment list in ascending or descending order according to either then the device first accessed the site, alphabetically by name or when a change was last recorded. 
    3. Device names: iPads are displayed with a concatenated vendor ID and iOS version. Browser access records the operating system, browser and version.

      Longstanding users may be used to seeing iPad device names listed on the device page. Unfortunately, we lost access to the device name as a result of the security updates that Apple introduced in iOS 16. The vendor identifier is now the only available ID reference.

    4. First access: A record of when the device was first paired with the site.
    5. Changed: A record of when the enrolment was last changed (i.e. blocked or removed from the list).
    6. Action buttons: These buttons allow you to control the device's access in the following ways:
      • Remove: This simply removes the device from the list (it does not remove the device from the instance). Best used if you block a device and do not intend to reinstate it.
      • Approve: The button to approve browser access if the site is configured as such.
      • Block: Blocks the device from accessing the site. If a device is blocked it becomes possible to "re-approve" the device using the "re-approve" button.

Bulk device management

As discussed, it is possible not only to install the app in bulk but also to manage enrolments in this way. To do this in Apple configurator you must first download the site's plist file which is available on the Settings > Device page:

 

The plist file contains the site's domain and secret combination in the following format:

<key>domain</key>
<string>subdomain.assess.risr.global</string>
<key>secret</key>
<string>xxxx-xxx-xxx</string>

To enrol the iPads:

  1. Add the plist file to the application using Apple Configurator under Actions > Add > Documents. When asked to chose an application, select risr/ assess. You will need to select the iPads that you would like to apply the configuration to, before adding the documents.
  2. On launching, the app enrolment and configuration will occur automatically without needing to manually enter the details. The iPads will need an internet connection to complete the enrolment.
  3. The launch continues as from the "Enrolling ... please wait" progress screen in the Manual process.

The process will be slightly different in other MDM solutions, but the guiding principle is the same. Where the domain and secret are added to the MDM the information can be pushed out and used to pair the devices with the instance in bulk.

Was this article helpful?

0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.