You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Microsoft Graph API读取Azure AD域密码策略及关联用户

Using Microsoft Graph API to Manage Azure AD Password Policies & User Associations

1. Read Domain-Specific Password Policies

To fetch password policy attributes for a specific domain:

  • Call the Get Domain endpoint:
    GET https://graph.microsoft.com/v1.0/domains/{domain-id}
    
  • The response includes a passwordPolicy object with key attributes:
    • passwordExpirationDays: Days until passwords expire for users in this domain
    • passwordHistoryCount: Number of previous passwords that can't be reused
    • minimumPasswordLength: Required minimum password length
  • For multiple domains, repeat the request for each domain ID you need to inspect.

2. Identify Users Subject to a Domain's Policy

To find users that follow a domain's policy (excluding those with individual overrides):

  • Filter users by UPN suffix matching the domain, and exclude those with password policy overrides like disabled expiration:
    GET https://graph.microsoft.com/v1.0/users?$filter=endsWith(userPrincipalName,'@{domain-name}') and not contains(passwordPolicies,'DisablePasswordExpiration') and not contains(passwordPolicies,'DisableStrongPassword')&$select=id,userPrincipalName,passwordPolicies
    
  • Note: Users assigned to custom Password Authentication Policies take precedence over domain/org policies. To exclude these users, add filters to exclude members of groups targeted by such policies, or check their authenticationMethods settings.

3. Check Organization-Wide Password Expiration Policy

The policy found in admin.microsoft.com → Settings → Org Settings → Security & Privacy → Password Expiration Policy maps directly to the organization resource in Graph:

  • Retrieve the org-wide policy with:
    GET https://graph.microsoft.com/v1.0/organization
    
  • Key properties to check:
    • passwordExpirationDays: Default expiration period (90 days by default)
    • passwordPolicies: Flags like DisablePasswordExpiration (if global expiration is turned off)
  • To update this policy (with appropriate permissions), use the Update Organization endpoint:
    PATCH https://graph.microsoft.com/v1.0/organization/{org-id}
    Content-Type: application/json
    {
      "passwordExpirationDays": 90,
      "passwordPolicies": "None"
    }
    

4. API Feasibility & MSOnline Replacement

All requirements are fully supported by Microsoft Graph API (v1.0, no beta endpoints required). This replaces deprecated MSOnline cmdlets:

  • Get-MsolPasswordPolicy → Replaced by GET /domains/{domain-id} (domain policies) or GET /organization (org-wide policy)
  • Get-MsolUser with password policy filters → Replaced by GET /users with the $filter clauses above

Required Permissions

Your app must have these permissions (delegated or application):

  • Domain.Read.All: Read domain password policies
  • User.Read.All: List users and their password attributes
  • Organization.Read.All: Read org-wide password policy
  • (Optional) Organization.ReadWrite.All: Update org-wide policy

内容的提问来源于stack exchange,提问作者Neerajyadav Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 22:07:55