SEB Server: Connection and Exam Configurations (Lockdown)

By Paul Flanders ·

Two pieces of configuration sit between SEB Server and the Safe Exam Browser on a student's device. A Connection Configuration tells Safe Exam Browser how to reach your SEB Server. An Exam Configuration tells Safe Exam Browser exactly how to lock the device down for one particular exam. Exam Configuration Templates let you reuse a standard set of settings across many exams.

Institutional Administrators create Connection Configurations. Exam Administrators create Exam Configurations and Templates.

What this product is for

You only need to give Safe Exam Browser two things to run a secure exam: somewhere to connect to, and a set of rules about what is allowed once it gets there. SEB Server separates those two ideas so the connection part can be reused across many exams, while each exam can have its own bespoke lockdown rules. Together, they replace the manual SEB configuration file work that staff would otherwise have to do for every exam.

Main features

  • Connection Configurations for setting up secure connections from Safe Exam Browser to SEB Server.
  • Optional password or certificate encryption on Connection Configurations.
  • A fallback strategy for when SEB Server is briefly unreachable.
  • Optional restriction of a Connection Configuration to specific exams.
  • Exam Configurations holding the full set of SEB lockdown settings for one exam.
  • A clear lifecycle: Under Construction, Ready To Use, In Use.
  • Copy, import and export of exam settings as .seb files.
  • Exam Configuration Templates for reusing default settings across many exams.
  • An undo feature that reverts unsaved SEB settings changes to the last published version.

How to use it

Connection Configurations

A Connection Configuration is what students download or run to start Safe Exam Browser pointing at your SEB Server. You only need one for the institution, although you can have more if you want to separate cohorts or exams.

Create a Connection Configuration

  1. Sign in as an Institutional Administrator.
  2. Go to SEB Configuration, then Connection Configuration.
  3. Choose Add Connection Configuration.
  4. Enter a unique name, for example Autumn Term 2026, Standard.
  5. Choose a Configuration Purpose:
    • Starting an Exam tells Safe Exam Browser to use the settings just for this session and not overwrite anything locally. This is the safer option for most institutions.
    • Configuring a Client tells Safe Exam Browser to also store the settings locally on that device.
  6. Optionally enter a Configuration Password. Students will be prompted for this password when Safe Exam Browser loads the configuration. This is recommended if the file might be shared widely.
  7. Optionally choose Encrypt with Certificate if you prefer certificate-based encryption.
  8. If you want a fallback strategy, tick With Fallback and fill in the fallback URL, connection attempts, interval, timeout, fallback password and quit password as needed.
  9. Optionally select specific exams that this configuration should make available. Leaving this blank means Safe Exam Browser will list every running exam.
  10. Save the configuration.

Activate and export

A new Connection Configuration is created inactive. To use it:

  1. Open the configuration and choose Activate Connection Configuration.
  2. Choose Export Connection Configuration to download a file called SEBServerSettings.seb.
  3. Make this file available to students, either through a download link on a trusted internal page, by email, or built into a managed Safe Exam Browser deployment.

Deactivate a Connection Configuration

When a configuration is no longer needed, open it and choose Deactivate Connection Configuration. Any Safe Exam Browser that tries to connect with that configuration will receive an HTTP 401 Unauthorised response.

Exam Configurations

An Exam Configuration holds the lockdown settings for one exam: which websites are allowed, whether copy and paste is blocked, what the quit password is, whether spell check is allowed, and so on. These are the same settings you would otherwise set with the SEB Configuration Tool, but stored centrally.

Create an Exam Configuration

  1. Sign in as an Exam Administrator.
  2. Go to SEB Configuration, then Exam Configuration.
  3. Choose Add Exam Configuration.
  4. Enter a unique name and an optional description.
  5. Set the Status to Under Construction while you are still working on it. Set it to Ready To Use when you are ready to attach it to an exam.
  6. Save the configuration.
  7. Choose Edit SEB Settings to open the full settings page.

Edit the SEB settings

The SEB settings page is laid out in tabs, just like the Safe Exam Browser Configuration Tool on Windows. As you change a setting, it is sent to SEB Server straight away and held as an open working revision. Nothing you change here is visible to exams or Safe Exam Browser clients until you publish.

  1. Work through the tabs and set values for the lockdown rules you need.
  2. Use Undo to revert all unsaved changes back to the last published state.
  3. When you are happy with the changes, choose Save / Publish Settings. This makes the new revision live for any exam that uses this configuration.

Common lockdown choices

The full SEB settings list is long. The choices most often used at UK institutions include the quit password, the allowed and blocked URLs (URL Filter), whether spell check or the on-screen keyboard is permitted, whether the student can use additional applications, what the SEB browser window looks like, and what shortcut keys are disabled. The settings page describes each option as you hover over it.

Status changes

An Exam Configuration moves through three statuses:

  • Under Construction. Still being edited and cannot be attached to an exam.
  • Ready To Use. Finished and available to be picked when setting up an exam.
  • In Use. Attached to an exam. Settings become read-only.

Copy, import and export

One Exam Configuration can only be attached to one exam. If you want the same settings for several exams, copy the configuration and give the copy a new name. Use Copy Exam Configuration from the action pane and choose whether to include the full edit history.

To use an existing .seb file made with the Safe Exam Browser Configuration Tool, choose Import Exam Configuration, pick the file and give it a unique name. If the file is password-protected, enter the password during import.

To test settings locally with Safe Exam Browser, open the configuration, open the SEB settings and choose Export SEB Settings. SEB Server will offer a file called SEBExamSettings.seb to download.

Generate a Config-Key

A Config-Key is a hash of your settings that Moodle and Safe Exam Browser use to confirm they agree on the configuration. SEB Server creates and applies the Config-Key automatically when you attach an Exam Configuration to an exam. If you need the key for manual use, choose Export Config-Key and copy the value from the pop-up.

Exam Configuration Templates

Templates let you set defaults for many Exam Configurations at once. They are useful when most of your exams share the same lockdown style, with only small differences.

  1. Go to SEB Configuration, then Configuration Template.
  2. Choose Add Configuration Template, enter a name and save.
  3. In the template view, edit individual SEB settings attributes to set the default value you want.
  4. For each attribute, decide whether it should be shown in Exam Configurations created from this template, or hidden. Use Remove From View or Attach To View as needed.
  5. To create an Exam Configuration directly from the template, choose Create Exam Configuration.

Templates are an experimental feature in the current SEB Server release and may change in future versions.

Common tasks

Make a standard configuration available to every Safe Exam Browser in your institution. Create one active, encrypted Connection Configuration, export it, and publish the file on a trusted internal page that students can download from before each exam.

Reuse the same lockdown for two exams in the same week. Build the first Exam Configuration and set it to Ready To Use. Attach it to the first exam. Make a copy for the second exam, change anything that needs to differ, set it to Ready To Use and attach it to the second exam.

Test that your lockdown rules behave as expected. Open the Exam Configuration, choose Export SEB Settings, open the file on a test device with Safe Exam Browser, and try the behaviour. Adjust the settings in SEB Server and re-export until you are happy.

Change settings for an exam that is already running. First go to the monitoring view and confirm there are no active Safe Exam Browser clients connected. Open the Exam Configuration, set its status from In Use back to Under Construction, edit the settings and choose Save / Publish Settings. SEB Server will block the publish if any clients are still connected.

Things to know

A Connection Configuration only tells Safe Exam Browser how to reach SEB Server. The lockdown rules come from the Exam Configuration, which is attached separately to each exam.

Connection Configurations are sensitive. They contain the information Safe Exam Browser needs to connect to your server. If you suspect a configuration has been leaked, deactivate it and create a new one.

One Exam Configuration can only be attached to one exam at a time. If you need the same rules in many exams, copy the configuration.

SEB settings are saved as an open working revision while you edit. Until you choose Save / Publish Settings, your changes are not yet live. Safe Exam Browser clients receive the last published version, not the working revision.

Some Safe Exam Browser settings are handled differently in SEB Server. Start URL, embedded resources, additional dictionaries, additional resources, embedded certificates and the Browser Exam Key are either not supported on SEB Server, used differently, or generated automatically. If a setting you expect is missing or behaves differently, this is the likely reason.

Changing settings on an Exam Configuration that is attached to a running exam is only allowed when there are no active Safe Exam Browser connections at the moment of publishing.

UK English note: spellings, dates and times across SEB Server screens may use international defaults. Your own time zone setting controls how dates display, and using DD/MM/YYYY in any free-text fields will keep things consistent for UK colleagues.

Troubleshooting

I cannot attach an Exam Configuration to an exam. The configuration must be in the Ready To Use status, and it must not already be attached to another exam. Check both.

The Save / Publish Settings action is greyed out. Settings can only be edited when the configuration is in Under Construction. If it is In Use, change the status back to Under Construction first.

The publish failed because clients are connected. SEB Server prevents publishing changes while a running exam has active connections, to avoid mixed configurations across students. Wait for all clients to disconnect, or schedule changes outside exam hours.

Importing a .seb file failed. Check that the file is from a compatible Safe Exam Browser Configuration Tool version and that the password is correct. The name you give the imported configuration must be unique.

Frequently asked questions

Do students see the lockdown settings before they start?
No. The settings are sent to Safe Exam Browser silently when it connects, and the lockdown takes effect when the exam opens.

Do I need a separate Connection Configuration for each exam?
No. One Connection Configuration per institution is enough in most cases. Use several only if you want to separate audiences or apply different fallback rules.

Can I encrypt the Exam Configuration as well as the Connection Configuration?
Yes. When you attach an Exam Configuration to an exam, you can set a password that Safe Exam Browser will prompt for. As Safe Exam Browser already talks to SEB Server over HTTPS, this extra step is not usually needed.

What is a Config-Key?
A Config-Key is a hash that proves the Safe Exam Browser is using the exact settings you intended. SEB Server generates it automatically when you attach the configuration to an exam, and pushes it to Moodle as part of the SEB restriction.

Can I revert a change to an Exam Configuration?
You can undo all changes since the last publish using the Undo action. There is no full history-based revert at present.

Summary

A Connection Configuration is how Safe Exam Browser finds your SEB Server. An Exam Configuration is how Safe Exam Browser knows what to lock down for one exam. Templates make repeated work faster. Get these right and you are ready to import a Moodle quiz as an exam and attach a configuration to it.

These articles are produced and maintained by Essington ITS, a UK-based IT services provider specialising in the deployment of SEB Server the secure online assessment platform.

 

person people found this useful.

Related

Knowledge base 10 Jun 2026

Personal Notebook in eLLM

The personal notebook in eLLM allows users to organise and store notes, images, and files in a private, searchable timeline. It ensures privacy by keeping contents visible only to the user, and it can be integrated with the assistant for personalised answers.

Knowledge base 9 Jun 2026

Git Commands Quick Reference Guide

This quick reference guide covers essential Git commands for repository setup, staging, branching, merging, and working with remote repositories, making it a handy tool for developers to streamline their workflow.

Knowledge base 9 Jun 2026

Organisation Skills in the eLLM Admin Console

The article explains how the eLLM Admin Console allows organisations to create and manage shared instruction sets called "organisation skills" to ensure consistent responses across teams. These skills can be customised, restricted to specific groups, and integrated with extern…

Expand 29 Jul 2026

How AI can support pupils with SEND

Explore how AI tools are aiding pupils with special educational needs and disabilities by simplifying text, breaking down tasks, and enhancing accessibility. Learn about the considerations schools should make before implementation.

Expand 29 Jul 2026

AI policy and practice in further education

Further education colleges need distinct AI policies due to their unique mix of vocational courses, diverse age groups, and specific funding and inspection requirements. This guidance highlights the importance of tailored AI approaches in FE settings.