Configures knowledge-based security questions as a second authentication factor. Users select questions and provide answers during enrolment; their answers are validated at login.
Settings
- Questions
-
The list of questions presented to users during enrolment and verification. Enter one question per line.
Example questions:
- What is the name of your first pet?
- What city were you born in?
- What is your mother's maiden name?
- Minimum to Answer
- The number of questions that the user must answer correctly at login. Default is 2. Setting this higher than the total number of configured questions will prevent users from ever authenticating — ensure there are always more questions than this minimum.
Security questions provide weak security if the answers are publicly guessable (e.g. from social media). Consider combining this factor with TOTP or email OTP for stronger assurance.