Follow

Installation Guide - Digiexam IWA on Managed Chrome OS

Overview

Digiexam requires both the Isolated Web App (IWA) and the Digiexam Chromebook Sidecar to be working properly. These are installed differently depending upon which scenario Digiexam is intended to be used.  

There are two scenarios in which Digiexam can be used:


Open Book exams - no Lockdown is applied. This requires the user to be signed in to their User account on the Chromebook. In this scenario the Google Administrator must deploy both the IWA and the Sidecar separately.


Locked-down exams - This requires the user to start the app from Kiosk (signed out of their user account). In this scenario the Google Administrator must attach the Digiexam Sidecar from within the IWA’s Extension section.

Important: The Sidecar is installed as a separate managed extension only for signed-in user sessions. In kiosk mode, do not add it as an independent kiosk item; attach it from the Digiexam IWA’s Extensions section.

Before you begin

  • Use an administrator account in your Google Workspace with permission to manage ChromeOS devices, device policies, apps, and extensions.
  • Chromebooks must be enrolled in your organization and assigned the required ChromeOS management licence.
  • Use ChromeOS 128 or later for the open book IWA deployment and ChromeOS 134 or later for the lockdown IWA deployment.
  • Identify the Organizational Unit (OU) or group containing the managed student accounts and the OU containing the kiosk devices. These may be different.
  • Apply every setting to the intended OU or group. A correct policy applied to the wrong OU will not reach the expected users or devices.
  • After changing a policy, click Save or Override. Policy changes can require time to propagate.
  • When applying policies/settings to a “Parent” OU or group - make sure to verify that settings are correctly inherited to any sub-groups below
Terminology: “User session” means a student signs in with a managed account. “Kiosk mode” means Digiexam runs from the ChromeOS sign-in screen in a locked-down kiosk session.

1. Shared deployment values

IWA Bundle ID alsfb3ygfh4zkgt3ftglc5l5pzdldc6g6vx6xt4c4bktili7tntlgaacai
Update Manifest URL https://chromebook.digiexam.com/update.json
Sidecar Extension ID gdcflbjnpgoonfcaibakkdbgdghooofk
Verified Access service account kiosk-mode-verifier@digiexam-cluster.iam.gserviceaccount.com
Copy exactly! Do not add spaces, replace characters, use a different update URL, or substitute another service account.

 


2. Verified Access (signed-in, Open book exams)

IWA and Digiexam Sidecar are installed separately. 
 

NOTE: If your organization only intends to use Digiexam for locked-down exams you can skip this part and proceed to chapter 3 - Install for Chrome OS Kiosk mode

Deployment order

  1. Configure the required Verified Access policies for users and devices.
  2. Install the Digiexam IWA and Sidecar under Users & browsers.
  3. Confirm the required user-session application settings and verify that values are inherited correctly in any sub- groups

2.1 User-session verification policy

  1. Sign in to the Google Admin console.
  2. Go to Devices > Chrome > Settings. The User & browser settings page opens by default.
  3. Select the OU or group containing the managed student accounts.
  4. Find User verification.
  5. Set Verified Mode to Require verified mode boot for Verified Access.
  6. Under Service accounts which are allowed to receive user data, add the Verified Access service account from section 1.
  7. Click Save or Override.
Why this is required: The Sidecar uses the user challenge in signed-in sessions. Requiring verified mode also causes Developer Mode sessions to fail the Verified Access check.

2.2 Install for signed-in user sessions (Open book exams)

Under Users & browsers, the IWA and Sidecar are installed as two separate managed items.

2.2.1 Install the Digiexam IWA

  1. Go to Devices > Chrome > Apps & extensions > Users & browsers
  2. Select the OU or group containing the managed student accounts.
  3. Point to Add (+) and select Add an Isolated Web App.
  4. Enter the IWA Bundle ID and Update Manifest URL from Section 1.
  5. Click Save.
  6. Open the newly added IWA entry and set Installation policy to Force install + pin to ChromeOS taskbar.
  7. Click Save or Override.

2.2.2 Install the Digiexam Chromebook Sidecar

  1. Remain on Devices > Chrome > Apps & extensions > Users & browsers and keep the same OU or group selected.
  2. Point to Add (+) and select Add Chrome app or extension by ID.
  3. Search by the Sidecar Extension ID from Section 1. If needed, use Add Chrome app or extension by ID.
  4. Select Digiexam Chromebook Sidecar.
  5. Set Installation policy to Force install.
  6. Enable Certificate management > Allow enterprise challenge.
  7. Click Save or Override.
Required pairing: The IWA and Sidecar must be assigned to the same intended student population. Installing only one component is not a supported Digiexam user-session configuration.

 

2.3 Configure the signed-in user-session deployment

The values below must match the Digiexam reference configuration. Settings marked “Inherited is acceptable” do not require a local override when the inherited value already matches.

2.3.1 Digiexam IWA settings

Setting Required state How to apply
Installation policy Force install + pin to ChromeOS taskbar Set locally
Pin to a custom version Off / not configured Inherited from Google default
Set a custom update channel Off / not configured Inherited from Google default
Launch on login Allow user to launch manually Inherited or set locally
Managed configuration No custom configuration Leave without configuring

Google Admin Users & browsers panel showing the Digiexam IWA configured for force install and pin, with manual launch and default version settings.

Reference: required Digiexam IWA settings under Users & browsers.

2.3.2 Sidecar extension settings

Setting Required state How to apply
Installation policy Force install Set locally
Extension mandatory for Incognito Off Inherited from Google default
Include in Chrome Web Store Recommended Off Inherited from Google default
Allow enterprise challenge On Set locally
Permissions and URL access Use default permissions for this organization Inherited from Google default
Blocked hosts / Allowed hosts No entries Leave empty

 

2.4 Validate the signed-in user session

Sign in with a managed student account from the configured user OU or group.

Confirm that Digiexam appears in the ChromeOS launcher and on the taskbar.

Confirm that Digiexam Chromebook Sidecar is installed by the administrator.

Open chrome://policy, click Reload policies, and confirm that the expected policies have no errors.

Start Digiexam and confirm that the verification flow does not report a missing Sidecar or missing enterprise challenge permission.

 


3. Install for ChromeOS kiosk mode

Digiexam Sidecar is installed as an extension inside the IWA

Deployment order

  1. Install the Digiexam IWA under Kiosks.
  2. Confirm the required kiosk settings and attach the Sidecar inside the IWA.
  3. Verify that all values are inherited correctly in any sub- groups
  4. Validate on test Chromebooks before broad rollout.

3.1 Kiosk/device verification policy

  1. Go to Devices > Chrome > Settings > Device settings.
  2. Select the OU containing the ChromeOS devices that will run Digiexam in kiosk mode.
  3. Under Enrollment and access, set "Verified access to Enable for content protection”.
  4. Set Verified mode to “Require verified mode boot for verified access”.
  5. Under Services with full access, add the Verified Access service account from Section 1.
  6. Click Save or Override.

 

3.2 Add the Digiexam IWA as a kiosk app

  1. Go to Devices > Chrome > Apps & extensions > Kiosks.
  2. Select the OU containing the ChromeOS devices used for locked-down exams.
  3. Point to Add (+) and select Add an Isolated Web App.
  4. Enter the IWA Bundle ID and Update Manifest URL from section 1.
  5. Click Save.
  6. Open the IWA entry and confirm that Installation policy is Installed.
Do not add a standalone kiosk extension: The Sidecar must be attached from inside the Digiexam IWA configuration. Do not create a separate Sidecar row under Kiosks.

3.2.1 Attach the Sidecar inside the kiosk IWA

  1. In the Kiosks list, click the Digiexam IWA row to open its settings panel.
  2. Scroll to Extensions.
  3. Click Add extension.
  4. Select Add from Chrome Web Store and find the Sidecar using the Extension ID from Section 1.
  5. Select Digiexam Chromebook Sidecar.
  6. Confirm that the Sidecar name and extension ID appear under Extensions.
  7. Click Save or Override.

3.3 Configure the kiosk deployment

Confirm every state below. The current Google Admin console may show some values as inherited from Google default. This is acceptable where indicated, provided the effective state matches the table.

Setting Required state How to apply
Installation policy Installed Set locally / confirm
Pin to a custom version Off / not configured Inherited from Google default
Set a custom update channel Off / not configured Inherited from Google default
Allow App to Manage Power On Set locally
Enable Unified Desktop (BETA) Off Inherited from Google default
Allow On-screen Keyboard On Inherited from Google default
Set Keyboard Top Row as FN Keys Off Inherited from Google default
Allow new windows to open (full screen) On Set locally
Web app can run offline On Inherited from Google default
Managed configuration No JSON value Leave without configuring
Extensions Digiexam Chromebook Sidecar attached Set locally inside IWA
Power permission: Allow App to Manage Power is mandatory. Digiexam uses the ChromeOS power API during an active exam to prevent normal idle timers from dimming the screen, turning it off, or suspending the device.
Full-screen windows: Enable Allow new windows to open (full screen) so Digiexam can open the required full-screen windows during the kiosk exam flow.

 

3.4 Validate the kiosk session

Sign out or restart the Chromebook and launch Digiexam from the kiosk app menu, or confirm that it auto-launches when configured.

Confirm that the IWA opens in a locked-down kiosk session.

Confirm that the IWA detects and communicates with the attached Sidecar.

Start a test exam and confirm that kiosk/device verification succeeds.

Confirm that any required new windows open in full-screen mode.

Leave the test exam idle long enough to confirm that the screen remains awake while the exam is active.

Temporarily interrupt network access during a controlled test and confirm that the expected offline behaviour is available.

 


 

 

Are you having troubles with the installation? Please have a look at our IWA Troubleshooting Guide, if the issue persist: contact us at support@digiexam.com.  

 

 

Was this article helpful?
2 out of 3 found this helpful

Comments