Create and manage KBA questions for users
During registration or enrollment of a knowledge-based authenticator (KBA), the user selects several questions and provides easily-remembered answers. Later, when they are challenged with one or more knowledge-based questions, they can answer them to authenticate. You can allow the user to alter the answers at any time, provided they are logged in to IDaaS.
A question can only be included in a user's KBA if the language preference matches the language of the question created.
Before you add or disable questions, review your language coverage. Users can only enroll and answer questions that are available in their selected language.
You can do the following:
- Enable or disable system and custom questions
- Create and edit custom questions for users
- Delete custom questions
Disable questions
You cannot delete system questions, but you can disable them. When disabled, the question is not available to users for KBA authentication.
-
Click > Configuration > Knowledge Base Authentications. The Knowledge-based Authenticators page appears. By default, the System Defined Questions appear.
-
Do one of the following as required:
- Click System Questions.
- Click Custom Questions to access the list of Custom Questions.
-
Click to disable a question.
-
Click to re-enable a question.
Disabling a question removes it from future challenge selection and future enrollments, but it does not delete the question record.
Create custom questions
- Click > Configuration > Knowledge Base Authentications. The Knowledge-based Authenticators page appears.
- Click Custom Questions.
- Select the localized language from the drop-down list.
- Click Add. The Add Question dialog box appears.
- Enter the Question.
- Click Save. The question appears in the Custom Questions list page.
- Repeat these steps to add more questions.
Use clear wording in custom questions so users in each language can understand and answer them consistently.
Edit and delete custom questions
- Click > Configuration > Knowledge Base Authentications. The Knowledge-based Authenticators page appears.
- Click Custom Questions.
- Do the following as required:
- Click the question you need to edit. The Edit Question dialog box appears.
- Edit the question and click Save.
- Click and click Delete on the confirmation prompt to delete a question.
When you delete a custom question, it is no longer available for new enrollments or future challenge selection.
Validate your changes
After you add, edit, disable, or delete questions, verify the following:
- The question list reflects the expected status in the selected language.
- Disabled questions are not available during question enrollment.
- New or edited questions appear with the expected wording.
- Deleted questions no longer appear in the custom question list.