如何通过Microsoft Graph API读取Azure AD域密码策略及关联用户
Using Microsoft Graph API to Manage Azure AD Password Policies & User Associations
1. Read Domain-Specific Password Policies
To fetch password policy attributes for a specific domain:
- Call the Get Domain endpoint:
GET https://graph.microsoft.com/v1.0/domains/{domain-id} - The response includes a
passwordPolicyobject with key attributes:passwordExpirationDays: Days until passwords expire for users in this domainpasswordHistoryCount: Number of previous passwords that can't be reusedminimumPasswordLength: Required minimum password length
- For multiple domains, repeat the request for each domain ID you need to inspect.
2. Identify Users Subject to a Domain's Policy
To find users that follow a domain's policy (excluding those with individual overrides):
- Filter users by UPN suffix matching the domain, and exclude those with password policy overrides like disabled expiration:
GET https://graph.microsoft.com/v1.0/users?$filter=endsWith(userPrincipalName,'@{domain-name}') and not contains(passwordPolicies,'DisablePasswordExpiration') and not contains(passwordPolicies,'DisableStrongPassword')&$select=id,userPrincipalName,passwordPolicies - Note: Users assigned to custom Password Authentication Policies take precedence over domain/org policies. To exclude these users, add filters to exclude members of groups targeted by such policies, or check their
authenticationMethodssettings.
3. Check Organization-Wide Password Expiration Policy
The policy found in admin.microsoft.com → Settings → Org Settings → Security & Privacy → Password Expiration Policy maps directly to the organization resource in Graph:
- Retrieve the org-wide policy with:
GET https://graph.microsoft.com/v1.0/organization - Key properties to check:
passwordExpirationDays: Default expiration period (90 days by default)passwordPolicies: Flags likeDisablePasswordExpiration(if global expiration is turned off)
- To update this policy (with appropriate permissions), use the Update Organization endpoint:
PATCH https://graph.microsoft.com/v1.0/organization/{org-id} Content-Type: application/json { "passwordExpirationDays": 90, "passwordPolicies": "None" }
4. API Feasibility & MSOnline Replacement
All requirements are fully supported by Microsoft Graph API (v1.0, no beta endpoints required). This replaces deprecated MSOnline cmdlets:
Get-MsolPasswordPolicy→ Replaced byGET /domains/{domain-id}(domain policies) orGET /organization(org-wide policy)Get-MsolUserwith password policy filters → Replaced byGET /userswith the$filterclauses above
Required Permissions
Your app must have these permissions (delegated or application):
Domain.Read.All: Read domain password policiesUser.Read.All: List users and their password attributesOrganization.Read.All: Read org-wide password policy- (Optional)
Organization.ReadWrite.All: Update org-wide policy
内容的提问来源于stack exchange,提问作者Neerajyadav Kumar
相关产品推荐
相关产品推荐

