Overview
The Digiexam IWA solution consists of three installed components:
- The IWA app for signed-in user sessions (Open book exams)
- The IWA app for Kiosk sessions (Locked down exams)
- The Digiexam Chromebook Sidecar (A supporting extension that is required for Chromebook setup)
Digiexam requires both the Isolated Web App (IWA) and the Digiexam Chromebook Sidecar in order to work properly. A school's Google Administrator must complete deployment of both components for signed-in user sessions (open book) and then complete the similar deployment for kiosk mode (lockdown) use.
|
Important: The Digiexam Chromebook Sidecar is installed in different ways depending on if the app will be used in signed-in user sessions (Open book exam) or in Kiosk (Lockdown exam): Signed in (openbook): Install Sidecar as a separate managed extension. Kiosk (Lockdown): Attach Sidecar from the Digiexam IWA’s Extensions section. |
Prerequisites:
- Use an administrator account in your Google Workspace with permission to manage ChromeOS devices, device policies, apps, and extensions.
- Chromebooks must be enrolled in your organization and assigned the required ChromeOS management license.
- Use ChromeOS 128 or later for the signed-in IWA deployment and ChromeOS 134 or later for the kiosk IWA deployment.
- Identify the Organizational Unit(s) (OU) or group(s) containing the managed student accounts and the OU(s) containing the kiosk devices. These may be different and depend on your local configuration of your organization.
- Apply every setting to the intended OU or group. A correct policy applied to the wrong OU will not reach the expected users or devices.
- After changing a policy, click Save or Override. Policy changes can require time to propagate.
Deployment order
- Configure the required Verified Access policies for users and devices.
- Install the Digiexam IWA and Sidecar under Users & browsers.
- Confirm the required user-session application settings.
- Install the Digiexam IWA under Kiosks.
- Confirm the required kiosk settings and attach the Sidecar inside the IWA.
- Validate both modes on test Chromebooks before broad rollout.
1. Shared deployment values
| IWA Bundle ID | alsfb3ygfh4zkgt3ftglc5l5pzdldc6g6vx6xt4c4bktili7tntlgaacai |
| Update Manifest URL | https://chromebook.digiexam.com/update.json |
| Sidecar Extension ID | gdcflbjnpgoonfcaibakkdbgdghooofk |
| Verified Access service account | kiosk-mode-verifier@digiexam-cluster.iam.gserviceaccount.com |
| Copy exactly! Do not add spaces, replace characters, use a different update URL, or substitute another service account. | |
2. Required Verified Access policies
| Configure these policies separately from application installation. The user policy applies to signed-in sessions, while the device policy applies to kiosk sessions. |
2.1 User-session verification policy
- Sign in to the Google Admin console.
- Go to Devices > Chrome > Settings. The User & browser settings page opens by default.
- Select the Organizational Unit or group containing the managed student accounts.
- Find User verification.
- Set Verified Mode to Require verified mode boot for Verified Access.
- Under Service accounts which are allowed to receive user data, add the Verified Access service account from Section 1.
- Click Save or Override.
2.2 Kiosk/device verification policy
- Go to Devices > Chrome > Settings > Device settings.
- Select the OU containing the ChromeOS devices that will run Digiexam in kiosk mode.
- Under Enrollment and access, set "Verified access to Enable for content protection”.
- Set Verified mode to “Require verified mode boot for verified access”.
- Under Services with full access, add the Verified Access service account from Section 1.
- Click Save or Override.
3. Install for signed-in user sessions
| Important: Complete this entire section before configuring kiosk mode. Under Users & browsers, the IWA and Sidecar are installed as two separate managed items. |
3.1 Install the Digiexam IWA
- Go to Devices > Chrome > Apps & extensions > Users & browsers.
- Select the OU or group containing the managed student accounts.
- Point to Add (+) and select Add an Isolated Web App.
- Enter the IWA Bundle ID and Update Manifest URL from Section 1.
- Click Save.
- Open the newly added IWA entry and set Installation policy to Force install + pin to ChromeOS taskbar.
- Click Save or Override.
3.2 Install the Digiexam Chromebook Sidecar
- Remain on Devices > Chrome > Apps & extensions > Users & browsers and keep the same OU or group selected.
- Point to Add (+) and select Add Chrome app or extension by ID.
- Search by the Sidecar Extension ID from Section 1. If needed, use Add Chrome app or extension by ID.
- Select Digiexam Chromebook Sidecar.
- Set Installation policy to Force install.
- Enable Certificate management > Allow enterprise challenge.
- Click Save or Override.
| Required pairing: The IWA and Sidecar must be assigned to the same intended student population. Installing only one component is not a supported Digiexam user-session configuration. |
4. Configure the signed-in user-session deployment
The values below must match the Digiexam reference configuration. Settings marked “Inherited is acceptable” below does not require a local override when the inherited value already matches.
4.1 Digiexam IWA settings
| Setting | Required state | How to apply |
|---|---|---|
| Installation policy | Force install + pin to ChromeOS taskbar | Set locally |
| Pin to a custom version | Off / not configured | Inherited from Google default |
| Set a custom update channel | Off / not configured | Inherited from Google default |
| Launch on login | Allow user to launch manually | Inherited or set locally |
| Managed configuration | No custom configuration | Leave without configuring |
Reference: required Digiexam IWA settings under Users & browsers.
4.2 Sidecar extension settings
| Setting | Required state | How to apply |
|---|---|---|
| Installation policy | Force install | Set locally |
| Extension mandatory for Incognito | Off | Inherited from Google default |
| Include in Chrome Web Store Recommended | Off | Inherited from Google default |
| Allow enterprise challenge | On | Set locally |
| Permissions and URL access | Use default permissions for this organization | Inherited from Google default |
| Blocked hosts / Allowed hosts | No entries | Leave empty |
5. Install for ChromeOS kiosk mode
Kiosk mode is a separate deployment target. Adding the IWA under Users & browsers does not create a kiosk deployment.
5.1 Add the Digiexam IWA as a kiosk app
- Go to Devices > Chrome > Apps & extensions > Kiosks.
- Select the OU containing the ChromeOS devices used for locked-down exams.
- Point to Add (+) and select Add an Isolated Web App.
- Enter the IWA Bundle ID and Update Manifest URL from section 1.
- Click Save.
- Open the IWA entry and confirm that Installation policy is Installed.
| Do not add a standalone kiosk extension: The Sidecar must be attached from inside the Digiexam IWA configuration. Do not create a separate Sidecar row under Kiosks. |
5.2 Attach the Sidecar inside the kiosk IWA
- In the Kiosks list, click the Digiexam IWA row to open its settings panel.
- Scroll to Extensions.
- Click Add extension.
- Select Add from Chrome Web Store and find the Sidecar using the Extension ID from section 1.
- Select Digiexam Chromebook Sidecar.
- Confirm that the Sidecar name and extension ID appear under Extensions.
- Click Save or Override.
6. Configure the kiosk deployment
Confirm every state below. The current Google Admin console may show some values as inherited from Google default. This is acceptable where indicated, provided the effective state matches the table.
| Setting | Required state | How to apply |
|---|---|---|
| Installation policy | Installed | Set locally / confirm |
| Pin to a custom version | Off / not configured | Inherited from Google default |
| Set a custom update channel | Off / not configured | Inherited from Google default |
| Allow App to Manage Power | On | Set locally |
| Enable Unified Desktop (BETA) | Off | Inherited from Google default |
| Allow On-screen Keyboard | On | Inherited from Google default |
| Set Keyboard Top Row as FN Keys | Off | Inherited from Google default |
| Allow new windows to open (full screen) | On | Set locally |
| Web app can run offline | On | Inherited from Google default |
| Managed configuration | No JSON value | Leave without configuring |
| Extensions | Digiexam Chromebook Sidecar attached | Set locally inside IWA |
| Power permission: Allow App to Manage Power is mandatory. Digiexam uses the ChromeOS power API during an active exam to prevent normal idle timers from dimming the screen, turning it off, or suspending the device. |
| Full-screen windows: Enable Allow new windows to open (full screen) so Digiexam can open the required full-screen windows during the kiosk exam flow. |
7. Validate the deployment
Test at least one Chromebook from each applicable OU before broad rollout. After policy changes, reload policies and restart or sign out of the device so that the latest user and device policies are fetched.
7.1 Validate the signed-in user session
• Sign in with a managed student account from the configured user OU or group.
• Confirm that Digiexam appears in the ChromeOS launcher and on the taskbar.
• Confirm that Digiexam Chromebook Sidecar is installed by the administrator.
• Open chrome://policy, click Reload policies, and confirm that the expected policies have no errors.
• Start Digiexam and confirm that the verification flow does not report a missing Sidecar or missing enterprise challenge permission.
7.2 Validate the kiosk session
• Sign out or restart the Chromebook and launch Digiexam from the kiosk app menu, or confirm that it auto-launches when configured.
• Confirm that the IWA opens in a locked-down kiosk session.
• Confirm that the IWA detects and communicates with the attached Sidecar.
• Start a test exam and confirm that kiosk/device verification succeeds.
• Confirm that any required new windows open in full-screen mode.
• Leave the test exam idle long enough to confirm that the screen remains awake while the exam is active.
• Temporarily interrupt network access during a controlled test and confirm that the expected offline behavior is available.
Are you having troubles with the installation? Please contact us at support@digiexam.com.
Comments