You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Microsoft Entra CIAM中通过Users API创建账号并启用短信2FA

问题描述

我为外部用户创建了2个Microsoft Entra应用(CIAM):一个用于通过API创建用户(为提升安全性,限制仅允许API创建用户),另一个供用户登录。两个应用均支持多租户和个人Microsoft账号访问其API。我希望让所有通过API创建的用户,在登录另一个Entra应用时(使用Microsoft弹出式用户流),由CIAM触发短信2FA验证。目前我使用PHP Graph API在后端创建了带邮箱和密码的用户,新用户可登录另一个Entra应用,但找不到能让Entra应用添加短信2FA手机号的设置或API,请问该配置是否可行?

当前使用的PHP Graph API代码
// Obtain an access token with Application Permissions
$url = "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token";
try {
    $response = $client->post($url, [
        'form_params' => [
            'client_id' => $clientId,
            'client_secret' => $clientSecret,
            'scope' => 'https://graph.microsoft.com/.default',
            'grant_type' => 'client_credentials',
        ]
    ]);

    $tokenData = json_decode($response->getBody(), true);

    if (!isset($tokenData['access_token'])) {
        return ['error' => 'Unable to retrieve access token.'];
    }

    $accessToken = $tokenData['access_token'];
    $graphUrl = "https://graph.microsoft.com/v1.0/users";
    $userResponse = $client->post($graphUrl, [
        'headers' => [
            'Authorization' => "Bearer $accessToken",
            'Content-Type'  => 'application/json'
        ],
        'json' => [
            'accountEnabled' => true,
            'displayName'    => "$firstName $lastName",
            'givenName' => $firstName,
            'surname' => $lastName,
            'passwordPolicies' => "DisablePasswordExpiration, DisableStrongPassword",
            'identities'=> [
                            [
                                "signInType"=> "emailAddress",
                                "issuer"=> "abc.onmicrosoft.com",
                                "issuerAssignedId"=> $email
            ]
                            ],
            'passwordProfile' => [
                'forceChangePasswordNextSignIn' => false,
                'password'                     => $password
            ]
        ]
    ]);
    $userData = json_decode($userResponse->getBody(), true);

    if (isset($userData['id'])) {
        return [
            'user_id' => $userData['id'],
            'message' => 'User successfully created.'
        ];
    } else {
        return ['error' => 'User creation failed.'];
    }

} catch (Exception $e) {
    return ['error' => $e->getMessage()];
}
可行性说明及实现步骤

该配置完全可行,具体实现分为以下环节:

1. 配置CIAM租户的登录用户流,强制启用短信2FA

  • 登录Entra管理中心,进入你的CIAM租户后台
  • 导航至外部标识 > 用户流,选择用于登录的弹出式用户流
  • 在用户流的编辑步骤中,找到身份验证方法环节:
    • 将多重身份验证设置为"始终"
    • 在可用的多重身份验证方法中勾选"短信",并设为默认选项
  • 保存用户流后,所有使用该用户流登录的用户(包括API创建的用户)都会被要求完成短信2FA验证

2. 通过Graph API预配置用户的短信验证手机号(可选,优化登录体验)

如果希望用户首次登录时无需手动输入手机号,可以在创建用户后,通过Graph API为用户添加预验证的手机号:

  • 确保你的应用已获得User.ReadWrite.All的应用权限
  • 在用户创建成功后,添加以下代码片段:
$userId = $userData['id'];
$userPhone = "+86138xxxxxxx"; // 用户的国际格式手机号

// 更新用户的mobilePhone属性
$updateUserUrl = "https://graph.microsoft.com/v1.0/users/$userId";
$client->patch($updateUserUrl, [
    'headers' => [
        'Authorization' => "Bearer $accessToken",
        'Content-Type'  => 'application/json'
    ],
    'json' => [
        'mobilePhone' => $userPhone
    ]
]);

// 添加短信验证方法
$addAuthMethodUrl = "https://graph.microsoft.com/v1.0/users/$userId/authentication/phoneMethods";
$client->post($addAuthMethodUrl, [
    'headers' => [
        'Authorization' => "Bearer $accessToken",
        'Content-Type'  => 'application/json'
    ],
    'json' => [
        'phoneNumber' => $userPhone,
        'phoneType' => "mobile"
    ]
]);
  • 若不预配置手机号,用户首次登录时会被引导自行输入手机号并完成验证,同样能触发短信2FA流程

3. 验证效果

创建用户后,使用登录应用的弹出式用户流发起登录,系统会自动触发短信2FA验证步骤,符合需求。

内容的提问来源于stack exchange,提问作者Udeep

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 00:24:55