Another Check-In · C02
Browser enrollment
20 minutes. · 10 slides
Lesson video coming soon. The player below contains a sample video, not this lesson. You can use the written lesson and slide guide now.
Work through the lesson
Use these explanations alongside the slide guide. Expand any section to read its full explanation.
Before the demonstration
- Your assigned responsibility
- The correct training record
- Evidence of the result
Today’s outcome
Correct browser is enrolled and learner knows how to request recovery without sharing keys.
Read the full explanation
Before we begin, check these prerequisites: C01 concepts; issuer-provided unexpired token for the correct user/staff pair; supported browser. The intended outcome is: Correct browser is enrolled and learner knows how to request recovery without sharing keys. Keep a note of the training identity and date so that you can recognize the result. We will pause before any action that your role or the exercise does not authorize.
The attendance browser
- Open the issuer link or /enroll in the browser that will record attendance
In this step
Use the browser you will take to work. Enrollment belongs to that browser profile. Opening the same address in another browser does not bring the enrolled identity with it.
Read the full explanation
Open the issuer link or /enroll in the browser that will record attendance. Use the browser you will take to work. Enrollment belongs to that browser profile. Opening the same address in another browser does not bring the enrolled identity with it. I will pause here so you can identify the control or result that tells us where we are in the workflow.
Token and owner
- Enter the token and a recognizable device label
- inspect Token owner
In this step
Check the person named by Token owner before continuing. A familiar device label helps you and the issuer recognize this browser later. If the owner is wrong, stop and ask the issuer to correct the assignment.
Read the full explanation
Enter the token and a recognizable device label; inspect Token owner. Check the person named by Token owner before continuing. A familiar device label helps you and the issuer recognize this browser later. If the owner is wrong, stop and ask the issuer to correct the assignment. I will pause here so you can identify the control or result that tells us where we are in the workflow.
Registration result
- Use Generate + Register and wait for confirmed completion
In this step
Wait for the completed registration result. Starting key generation alone does not prove that the server accepted the browser. Keep the browser profile and its site data intact after successful enrollment.
Read the full explanation
Use Generate + Register and wait for confirmed completion. Wait for the completed registration result. Starting key generation alone does not prove that the server accepted the browser. Keep the browser profile and its site data intact after successful enrollment. I will pause here so you can identify the control or result that tells us where we are in the workflow.
My Devices
- If account access is available, open Profile Security > My Devices and verify label/status
In this step
The device list provides a second place to check the result when your account permits it. Compare the label and status with the browser you just enrolled. A different label or unexpected status deserves investigation before attendance.
Read the full explanation
If account access is available, open Profile Security > My Devices and verify label/status. The device list provides a second place to check the result when your account permits it. Compare the label and status with the browser you just enrolled. A different label or unexpected status deserves investigation before attendance. I will pause here so you can identify the control or result that tells us where we are in the workflow.
Replacement requests
- For loss or replacement, use Replacement Requests for the linked staff ID, give the reason and await issuer action
In this step
A replacement request starts a controlled recovery process. Explain what happened and keep any pending attendance evidence. The issuer may need to review the current device and recovery restrictions before issuing anything new.
Read the full explanation
For loss or replacement, use Replacement Requests for the linked staff ID, give the reason and await issuer action. A replacement request starts a controlled recovery process. Explain what happened and keep any pending attendance evidence. The issuer may need to review the current device and recovery restrictions before issuing anything new. I will pause here so you can identify the control or result that tells us where we are in the workflow.
Common problems
- Enrolling in an incidental browser
- wrong token owner
- clearing site data
- assuming a token is an account password
A useful support report
The task and record
The expected result
The actual message
The authorized next step
Read the full explanation
Let us consider the mistakes that can disrupt this workflow. Enrolling in an incidental browser; wrong token owner; clearing site data; assuming a token is an account password. Describe what you expected and what the application actually showed before choosing a remedy. Preserve the relevant record and error. The role responsible for a review or configuration change should make that decision. Do not borrow broader access simply to finish the exercise.
Guided practice
- Enroll the designated training browser, identify its active device entry and describe the replacement request process
- Use a prepared invalid token for the exception demonstration
Evidence to show
The correct training case
The result or permitted decision
Your explanation of the next step
Read the full explanation
Now it is your turn. Enroll the designated training browser, identify its active device entry and describe the replacement request process. Use a prepared invalid token for the exception demonstration. Work within the assigned training role. When you finish, show the result and explain which identity and date it belongs to. If the exercise includes a restricted action, explain the decision and its authorized owner rather than carrying it out without approval.
Practice debrief
- Correct context and permitted action
- A result you can trace
- A clear next step if blocked
Expected result
Correct browser is enrolled and learner knows how to request recovery without sharing keys.
Read the full explanation
The expected outcome is: Correct browser is enrolled and learner knows how to request recovery without sharing keys. Walk me through the record you used and the result you found. Explain these workflow checkpoints in order: Open the issuer link or /enroll in the browser that will record attendance. Enter the token and a recognizable device label; inspect Token owner. Use Generate + Register and wait for confirmed completion. If account access is available, open Profile Security > My Devices and verify label/status. For loss or replacement, use Replacement Requests for the linked staff ID, give the reason and await issuer action. For an exception, name the evidence you would preserve and the person with authority to take the next action.