KBA Verification node
Presents KBA questions to the user, collects answers to those questions, and verifies the input against the user’s stored answers.
Use this node for additional authentication when resetting a forgotten password or username.
To set the number of KBA questions, edit Configure > Security Questions > Questions > Number in the IDM admin UI.
Availability
| Product | Available? |
|---|---|
PingOne Advanced Identity Cloud |
Yes |
PingAM (self-managed) |
Yes 1 |
Ping Identity Platform (self-managed) |
Yes |
1 This functionality requires that you configure AM as part of a Ping Identity Platform deployment.
Configuration
| Property | Usage |
|---|---|
KBA Attribute |
The managed object attribute in which KBA questions and answers are stored. |
Identity Attribute |
The attribute used to identify the managed object in the underlying identity service (PingIDM). |
Callbacks
The node sends a PasswordCallback for each KBA question that requires verification, prompting the user to answer the question.