SEB Server: Indicators, Restrictions and Client Checks

By Paul Flanders ·

There are several layers of protection and visibility you set up on an exam before it runs: monitoring indicators, the automated SEB restriction, the App-Signature-Key check and SEB Client Groups. Together they make sure the Safe Exam Browser clients connecting to your exam are the real thing, that the Moodle quiz can only be reached through a properly configured Safe Exam Browser, and that supporters can spot problems quickly on the day. Exam Administrators handle this preparation work.

What this product is for

Locking down the Safe Exam Browser is only half the job. You also need to know who is connected, whether their device is healthy, and whether anything looks suspicious. Indicators give you that visibility. The automated SEB restriction makes sure the Moodle quiz cannot be opened in any other browser, and the App-Signature-Key check helps confirm that the Safe Exam Browser itself has not been tampered with. SEB Client Groups let you sort connected clients into useful groups during monitoring, for example by exam room or by operating system.

Main features

  • Built-in monitoring indicators for ping, battery, Wi-Fi, errors, warnings and info logs.
  • Per-indicator thresholds with colour coding so that supporters can see issues at a glance.
  • Automated SEB restriction that locks the Moodle quiz to the correct Safe Exam Browser configuration.
  • App-Signature-Key checks to confirm Safe Exam Browser client integrity.
  • A numerical trust threshold for App-Signature-Key, balancing strictness with practicality.
  • SEB Client Groups by IP address range or operating system, used to group monitoring views.
  • Filters on the monitoring view to show or hide groups during an exam.

How to use it

Monitoring indicators

An indicator is something SEB Server measures about each connected Safe Exam Browser. Each indicator shows as a column on the monitoring view, with a value per student, and a colour that changes when a threshold is crossed.

The indicators you can use

  • Last Ping Time. Milliseconds since the last ping from a Safe Exam Browser. Use this to spot lost connections. SEB Server adds a default Last Ping Time indicator to every new exam.
  • Battery Status. Battery level on devices not plugged in. Use this to warn supporters about students whose battery is running low.
  • WiFi Status. Wi-Fi signal strength on devices connecting over Wi-Fi. Helps you spot weak networks.
  • Errors. Number of error logs that a Safe Exam Browser has reported.
  • Warnings. Number of warning logs reported.
  • Info Log. Number of info-level events. Most useful with a tag filter for specific events you care about.

Add or change an indicator

  1. Open the exam from Exam Administration, then Exam.
  2. Scroll to the Indicators section.
  3. To add a new indicator, choose Add Indicator from the action pane.
  4. Give the indicator a name. This name appears as the column header in the monitoring view.
  5. Choose the Type. A short description of the type appears beneath the selector.
  6. Pick a Default Color. This is shown when the measured value has not crossed any threshold.
  7. Add one or more thresholds using the plus sign. For each threshold, set a numeric value and a colour. When the measured value crosses the threshold, the cell will switch to that colour.
  8. Save the indicator.

To change a threshold later, double-click the indicator in the list, edit it and save.

Recommended starting points

The defaults that work well for most UK institutions are:

  • Keep the default Last Ping Time indicator. Set a yellow threshold around 5000 ms and a red threshold around 15000 ms as a starting point.
  • Add Battery Status with thresholds at 30 percent and 10 percent.
  • Add Errors with thresholds at 1 and 5 errors per client.

Adjust to match your own network conditions and your supporters' tolerance for noise.

Automated SEB restriction

The automated SEB restriction tells Moodle to only accept connections from Safe Exam Browsers whose Config-Key matches the Exam Configuration you attached. Without this, a student could in theory bypass Safe Exam Browser by visiting the Moodle quiz in a normal browser. With it, Moodle refuses any other type of connection.

Apply the SEB lock

  1. Open the exam.
  2. Choose Apply SEB Lock from the action pane.
  3. SEB Server will push the Config-Key, and any other supported restriction details, to Moodle.

Use Release SEB Lock to lift the restriction. This is useful if you want to test the Moodle quiz outside Safe Exam Browser.

Edit SEB restriction details

Choose SEB Restriction Details to open a dialog showing every restriction attribute the Moodle plugin supports. You can add a comma-separated list of Browser-Exam-Keys here if you have generated any. The Config-Key field is filled in automatically from the attached Exam Configuration.

Once the lock is active, any change you make to the attached Exam Configuration that changes the Config-Key is pushed to Moodle automatically. You do not need to re-apply the lock.

App-Signature-Key (ASK) checks

The App-Signature-Key is a hash generated by each Safe Exam Browser at runtime. Official Safe Exam Browser releases all produce the same hash. A tampered build produces a different one. SEB Server can use this to confirm that the connecting Safe Exam Browser is a genuine release.

Turn on ASK checking

  1. Open the exam.
  2. Choose App Signature Key from the action pane.
  3. Enable the feature.
  4. Set a Numerical Trust Threshold. If more clients connect with the same ASK than this number, the ASK is treated as trusted automatically. A typical starting value is between 3 and 5, depending on the size of your cohort.
  5. Save.

When the feature is enabled, the shield icon on the exam page is shown without a strike-through.

Grant an ASK explicitly

If you know the ASK of an approved Safe Exam Browser build, you can grant it in advance. From the App Signature Key page, select the ASK from the list of received ASKs and choose Add Security Grant. Give the grant a name (for example SEB 3.6 for Windows) and save. Any client that connects with this ASK is then automatically trusted.

During an exam, you can also grant an ASK from the monitoring view if a client comes in with a previously unknown ASK that you want to approve. See the article on monitoring for the supporter's view of this.

SEB Client Groups

A SEB Client Group is a label you apply to connected Safe Exam Browsers based on some property, so supporters can filter the monitoring view. Two types are supported:

  • IP Address Range. Group clients by where they are connecting from. Useful when each exam room has its own static IP range.
  • SEB OS. Group clients by operating system, for example Windows, macOS, iOS or iPadOS.

Add a SEB Client Group

  1. Open the exam and scroll past the indicators section to SEB Client Groups.
  2. Choose Add Client Group from the action pane.
  3. Enter a name, for example Room E1 or Windows clients.
  4. Pick a colour for the group, so supporters can tell it apart on the monitoring view.
  5. Choose the Type:
    • For IP Address Range, enter the start and end IPv4 addresses. The range is inclusive.
    • For SEB OS, choose the operating system.
  6. Save.

One Safe Exam Browser can match more than one group at once, for example Room E1 and Windows. That is by design.

Common tasks

Set up a typical exam for a UK GCSE or A-Level cohort. Keep the default Last Ping Time indicator and tune its thresholds. Add Errors and Battery Status indicators. Enable App-Signature-Key with a trust threshold of 5. Apply the SEB Lock. Create a SEB Client Group per exam room based on the room's IP range, with distinct colours.

Loosen up a test setup before going live. Use Release SEB Lock to let testers open the quiz in any browser. Re-apply the lock before the exam goes live.

Approve a custom Safe Exam Browser build. Grant the build's ASK explicitly through the App Signature Key page so that all connecting clients are trusted from the start.

Watch one exam room only on the day. Make sure each room has an IP-based SEB Client Group. In the monitoring view, use the Client Group Filter on the action pane to hide all rooms except the one you want.

Things to know

The Last Ping Time indicator is added by default to every new exam. We recommend keeping it in place because it is the single best signal that a client has disconnected.

Threshold colours are entirely up to you. A common convention is green for healthy, amber for warning and red for critical. Stick to a consistent palette across your indicators so supporters do not need to relearn the meaning each time.

Automated SEB restriction is delivered by the SEB Server Plugin for Moodle. With the plugin in place, Apply SEB Lock pushes the Config-Key to Moodle and updates it whenever the Exam Configuration changes.

When you change the attached Exam Configuration while the SEB Lock is active, SEB Server will refresh the Config-Key on Moodle automatically. This can make the change take slightly longer to complete than usual.

App-Signature-Key checks are processed in batches, not at the exact moment a Safe Exam Browser connects. A new connection may briefly show as "(No ASK Grant)" before the check completes. Denied clients are marked red with a "- ASK Grant Denied" tag in monitoring.

SEB Client Group filters in monitoring use show-priority: if a client belongs to two groups and you hide only one, the client remains visible. To hide a client completely, every group it belongs to must be hidden.

One SEB Client Group can apply to many clients, and one client can apply to many groups at once. This is intentional and lets you combine IP and OS filtering.

Troubleshooting

Indicators are not showing in monitoring. Check that the indicators are saved on the exam, and that the exam is running. Indicators only display for active exams with connected clients.

The SEB Lock did not apply. Confirm the Moodle setup is Moodle with SEB Server Plugin, that the plugin in Moodle is up to date and enabled, and that the API account used by SEB Server has permission to apply quiz access restrictions through the plugin.

Lots of clients are marked "(No ASK Grant)". The ASK check runs in batches. Wait a moment and refresh. If clients stay in this state, check whether they have sent an ASK at all, as older Safe Exam Browser versions may not. Consider using the Numerical Trust Threshold to allow well-known ASKs through automatically.

A trusted Safe Exam Browser is being denied. Select the client in monitoring or in the ASK list and use Add Security Grant to explicitly trust its ASK. Subsequent connections with the same ASK will be trusted automatically.

SEB Client Groups do not appear in monitoring. Check that you have at least one client group defined on the exam, and that you have at least one connected client whose IP or OS matches. The Client Group(s) column only shows for exams with groups defined.

Frequently asked questions

Will students be told why their connection was refused?
Safe Exam Browser will show its own error if it cannot connect or is rejected. SEB Server does not control the exact wording the student sees.

How strict should the Numerical Trust Threshold be?
A higher number is stricter and less forgiving of unfamiliar clients. A typical starting value is between 3 and 5. Set it lower if your cohort is small, higher if you have many students and want to limit risk from manipulated builds.

Can I add my own indicator types?
No. Indicator types are built into SEB Server and cannot be extended through the user interface.

What is a Browser-Exam-Key (BEK)?
A BEK is another key used for SEB restriction, generated from a particular Safe Exam Browser configuration. You can paste BEK values into the SEB Restriction Details dialog as a comma-separated list. SEB Server cannot generate BEKs itself.

Can I use Client Groups without setting up indicators?
Yes. The two features are independent. Add whichever helps your team.

Summary

Indicators tell supporters what is happening to connected clients, automated SEB restriction stops the Moodle quiz being opened in anything other than the correct Safe Exam Browser, the App-Signature-Key check defends against tampered Safe Exam Browser builds, and SEB Client Groups let your team focus the monitoring view on one room or one operating system at a time. With these in place, the exam is ready for proctoring and live monitoring.

These articles are produced and maintained by Essington ITS, a UK-based IT services provider specialising in the deployment of SEB Server the secure online assessment platform.

 

person people found this useful.

Related

Knowledge base 10 Jun 2026

Personal Notebook in eLLM

The personal notebook in eLLM allows users to organise and store notes, images, and files in a private, searchable timeline. It ensures privacy by keeping contents visible only to the user, and it can be integrated with the assistant for personalised answers.

Knowledge base 9 Jun 2026

Git Commands Quick Reference Guide

This quick reference guide covers essential Git commands for repository setup, staging, branching, merging, and working with remote repositories, making it a handy tool for developers to streamline their workflow.

Knowledge base 9 Jun 2026

Organisation Skills in the eLLM Admin Console

The article explains how the eLLM Admin Console allows organisations to create and manage shared instruction sets called "organisation skills" to ensure consistent responses across teams. These skills can be customised, restricted to specific groups, and integrated with extern…

Expand 29 Jul 2026

How AI can support pupils with SEND

Explore how AI tools are aiding pupils with special educational needs and disabilities by simplifying text, breaking down tasks, and enhancing accessibility. Learn about the considerations schools should make before implementation.

Expand 29 Jul 2026

AI policy and practice in further education

Further education colleges need distinct AI policies due to their unique mix of vocational courses, diverse age groups, and specific funding and inspection requirements. This guidance highlights the importance of tailored AI approaches in FE settings.