4.2.2. Configuring Security Questions

Security questions are disabled by default. To guard against unauthorized access, you can specify that users be prompted with security questions if they request a password reset. A default set of questions is provided, but you can add to these, or overwrite them. To enable security questions, set "securityQuestions" to true in the conf/ui-configuration.json file.

{
    "configuration" : {
        "securityQuestions" : true,
...    
    

Specify the list of questions to be asked in the conf/ui-secquestions.json file.

Refresh your browser after this configuration change for the change to be picked up by the UI.