- Password Reset
- Security Question and Answer
- Okta Classic Engine
The following guideline applies to the security question used for recovery:
- The answer to the security question must be at least 4 characters long. A higher minimum length requirement can be set by adjusting the appropriate password policy's Answer Complexity value. To do this, from Okta Admin Console, navigate to Security > Authentication > Password.
- The answer to the security question cannot be the user's password or username.
- The answer to the security question cannot contain part of the question.
- If a user has forgotten the answer to their security question and is unable to reset the password, the Admin can do that by pulling up the user's profile in the Okta admin console and clicking the Reset Password button.
- Admins can also use API, as instructed in the document mentioned in the Related References section.
