Another Check-In · A04

Enrollment administration

35 minutes. · 10 slides

Lesson video coming soon. The player below contains a sample video, not this lesson. You can use the written lesson and slide guide now.

Open video on YouTube ↗

Download slide guide (PDF)10 pages · 4.2 MB

Work through the lesson

Use these explanations alongside the slide guide. Expand any section to read its full explanation.

Before the demonstration

  • Your assigned responsibility
  • The correct training record
  • Evidence of the result

Today’s outcome
Device authorization and recovery have a traceable correct identity and lifecycle.

Read the full explanation

Before we begin, check these prerequisites: C01–C02; linked fictional user/staff pair; service boundary verified. The intended outcome is: Device authorization and recovery have a traceable correct identity and lifecycle. Keep a note of the training identity and date so that you can recognize the result. We will pause before any action that your role or the exercise does not authorize.

The enrollment target

  • Open Admin > Enrollment Tokens, choose the correct user/staff target and confirm the pair

In this step
Confirm both the account and linked staff identity. A token authorizes enrollment for a particular target. Issuing it to the wrong pair can create a device problem even when the email address looks familiar.

Read the full explanation

Open Admin > Enrollment Tokens, choose the correct user/staff target and confirm the pair. Confirm both the account and linked staff identity. A token authorizes enrollment for a particular target. Issuing it to the wrong pair can create a device problem even when the email address looks familiar. I will pause here so you can identify the control or result that tells us where we are in the workflow.

Token issue and delivery

  • Set bounded validity and issue token
  • deliver via the approved channel and verify enrollment completion

In this step
Choose bounded validity and use the approved delivery channel. Keep the token out of recordings and shared slides. Follow the employee’s completion result rather than assuming that issuing a token enrolled a browser.

Read the full explanation

Set bounded validity and issue token; deliver via the approved channel and verify enrollment completion. Choose bounded validity and use the approved delivery channel. Keep the token out of recordings and shared slides. Follow the employee’s completion result rather than assuming that issuing a token enrolled a browser. I will pause here so you can identify the control or result that tells us where we are in the workflow.

Recovery evidence

  • For recovery inspect active device, last use/sync and lifecycle before choosing a replacement or reissue action

In this step
Inspect the active device, last use and synchronization information before choosing recovery. Pending attendance may need protection. A replacement decision should explain what is happening to the old and intended new browser.

Read the full explanation

For recovery inspect active device, last use/sync and lifecycle before choosing a replacement or reissue action. Inspect the active device, last use and synchronization information before choosing recovery. Pending attendance may need protection. A replacement decision should explain what is happening to the old and intended new browser. I will pause here so you can identify the control or result that tells us where we are in the workflow.

Replacement decision

  • Decide a replacement request with a reason and verify resulting device/token history

In this step
Read the request and record a reason for the decision. Inspect the resulting device and token history. Recovery restrictions and cooldowns may prevent an immediate new issue even when the employee has a real need.

Read the full explanation

Decide a replacement request with a reason and verify resulting device/token history. Read the request and record a reason for the decision. Inspect the resulting device and token history. Recovery restrictions and cooldowns may prevent an immediate new issue even when the employee has a real need. I will pause here so you can identify the control or result that tells us where we are in the workflow.

Reassignment lockout

  • Escalate reassignment lockout to actual admin
  • admin checks identity, confirmation and reason before release in an authorized case

In this step
The actual admin role handles the protected lockout release. Other enrollment issuers should escalate with the verified identity and case details. A broader-looking menu or custom role name does not replace that requirement.

Read the full explanation

Escalate reassignment lockout to actual admin; admin checks identity, confirmation and reason before release in an authorized case. The actual admin role handles the protected lockout release. Other enrollment issuers should escalate with the verified identity and case details. A broader-looking menu or custom role name does not replace that requirement. I will pause here so you can identify the control or result that tells us where we are in the workflow.

Common problems

  • Issuing to the wrong staff link
  • distributing token screenshots
  • overlooking pending offline evidence
  • assuming every token manager can release lockout

A useful support report
The task and record
The expected result
The actual message
The authorized next step

Read the full explanation

Let us consider the mistakes that can disrupt this workflow. Issuing to the wrong staff link; distributing token screenshots; overlooking pending offline evidence; assuming every token manager can release lockout. Describe what you expected and what the application actually showed before choosing a remedy. Preserve the relevant record and error. The role responsible for a review or configuration change should make that decision. Do not borrow broader access simply to finish the exercise.

Guided practice

  • Issue one short-lived training token to the prepared identity, observe C02 completion and process a prepared replacement request
  • Non-admin explains lockout escalation

Evidence to show
The correct training case
The result or permitted decision
Your explanation of the next step

Read the full explanation

Now it is your turn. Issue one short-lived training token to the prepared identity, observe C02 completion and process a prepared replacement request. Non-admin explains lockout escalation. Work within the assigned training role. When you finish, show the result and explain which identity and date it belongs to. If the exercise includes a restricted action, explain the decision and its authorized owner rather than carrying it out without approval.

Practice debrief

  • Correct context and permitted action
  • A result you can trace
  • A clear next step if blocked

Expected result
Device authorization and recovery have a traceable correct identity and lifecycle.

Read the full explanation

The expected outcome is: Device authorization and recovery have a traceable correct identity and lifecycle. Walk me through the record you used and the result you found. Explain these workflow checkpoints in order: Open Admin > Enrollment Tokens, choose the correct user/staff target and confirm the pair. Set bounded validity and issue token; deliver via the approved channel and verify enrollment completion. For recovery inspect active device, last use/sync and lifecycle before choosing a replacement or reissue action. Decide a replacement request with a reason and verify resulting device/token history. Escalate reassignment lockout to actual admin; admin checks identity, confirmation and reason before release in an authorized case. For an exception, name the evidence you would preserve and the person with authority to take the next action.