---
title: KBA Decision node
description: Configure the KBA Decision node to check whether a user account has the minimum number of knowledge-based authentication security questions defined.
component: auth-node-ref
version: 8
page_id: auth-node-ref::kba-decision
canonical_url: https://docs.pingidentity.com/auth-node-ref/latest/kba-decision.html
llms_txt: https://docs.pingidentity.com/auth-node-ref/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
keywords: ["Nodes &amp; Trees", "Journeys", "Authentication"]
page_aliases: ["auth-node-kba-decision.adoc"]
superseded_by: https://docs.pingidentity.com/auth-node-ref/latest/kba-decision.html
section_ids:
  example: Example
  availability: Availability
  inputs: Inputs
  dependencies: Dependencies
  configuration: Configuration
  outputs: Outputs
  callbacks: Callbacks
  outcomes: Outcomes
  errors: Errors
---

# KBA Decision node

The KBA Decision node checks whether the user account has the required minimum number of knowledge-based authentication (KBA) security questions.

Use this node as part of a progressive profile journey to ensure an end user has defined answers to the minimum number of questions required by the system.

## Example

In this simple login journey, the end user must answer a set number of security questions before they can authenticate.

![Journey showing the KBA Decision](_images/kba-journey.png)

* The [Page node](page.html) containing the [Platform Username node](platform-username.html) and [Platform Password node](platform-password.html) prompts for credentials.

* The [Data Store Decision node](data-store-decision.html) validates the username-password credentials.

* The KBA Decision node verifies that the user profile includes enough security questions.

  * If the profile includes sufficient questions, the [KBA Verification node](kba-verification.html) prompts the user for answers to those questions, and authenticates them if they answer correctly.

  * If the profile doesn't include sufficient questions, the [KBA Definition node](kba-definition.html) prompts the user for additional questions and answers.

  * The [Patch Object node](patch-object.html) updates the user profile with the additional questions. The [KBA Verification node](kba-verification.html) prompts the user for answers to the questions, and authenticates them if they answer correctly.

## Availability

| Product                                                                                                                                 | Available? |
| --------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| PingOne Advanced Identity Cloud                                                                                                         | Yes        |
| PingAM (self-managed)&#xA;&#xA;This functionality requires that you configure AM as part of a sample Ping Identity Platform deployment. | Yes        |
| Ping Identity Platform (self-managed)                                                                                                   | Yes        |

## Inputs

This node reads the `userName` from the shared state, if available. The value is used as the identity attribute to locate the user in the identity store. The key name is configurable via the Identity Attribute configuration property.

## Dependencies

This node assumes you have configured a required minimum number of security questions.

To set the number of security questions, go to Configure > Security Questions > Questions > Number in the IDM admin UI.

## Configuration

| Property           | Usage                                                     |
| ------------------ | --------------------------------------------------------- |
| Identity Attribute | The attribute used to identify the managed object in IDM. |

## Outputs

This node doesn't change the shared state.

## Callbacks

This node doesn't send any callbacks.

## Outcomes

* `True`

  The user profile has at least the minimum number of KBA questions.

* `False`

  The user profile doesn't have the minimum number of KBA questions.

## Errors

The node can log the following errors:

* `Failed to retrieve configuration values`

  The KBA configuration is unavailable or invalid (minimum answers to define is negative, or KBA property name is null).

* `Unable to read object`

  The identity store returns no object for the provided user identity.
