You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Microsoft Graph API更新Azure AD手机号后无法登录的问题

问题:通过Graph API更新Azure AD用户手机号后无法用新号码登录

我通过Microsoft Graph API的用户更新端点修改了Azure AD中用户的手机号,Azure AD后台已显示更新成功,但用户无法使用新手机号登录账号。使用的代码如下:

static async Task Main(string[] args)
{
    string tenantId = <tenant-id>;
    string clientId = <client-id>;
    string clientSecret = <client-secret>;
    var objectId = <object-id>;
    var newMobile = <new-mobile-number>;

    try
    {
        string accessToken = await GetAccessToken(tenantId, clientId, clientSecret);

        await ResetMobileNumber(accessToken, objectId, newMobile );

        Console.WriteLine("Mobile number reset successfully!");
    }
    catch (Exception ex)
    {
        Console.WriteLine($"An error occurred: {ex.Message}");
    }

}

static async Task<string> GetAccessToken(string tenantId, string clientId, string clientSecret)
{
    using (HttpClient client = new HttpClient())
    {
        string tokenEndpoint = $"https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token";
        var body = $"grant_type=client_credentials&client_id={clientId}&client_secret={clientSecret}&scope=https://graph.microsoft.com/.default";

        var response = await client.PostAsync(tokenEndpoint, new StringContent(body, Encoding.UTF8, "application/x-www-form-urlencoded"));
        var responseBody = await response.Content.ReadAsStringAsync();

        var tokenJson = System.Text.Json.JsonDocument.Parse(responseBody).RootElement;
        string accessToken = tokenJson.GetProperty("access_token").GetString();

        return accessToken;
    }
}

static async Task ResetMobileNumber(string accessToken, string objectId, string newMobile)
{
    using (HttpClient httpClient = new HttpClient())
    {
        httpClient.DefaultRequestHeaders.Add("Authorization", $"Bearer {accessToken}");

        string graphApiEndpoint = $"https://graph.microsoft.com/v1.0/users/{objectId}";

        var body = new
        {
            mobilePhone = newMobile
        };

        var jsonBody = System.Text.Json.JsonSerializer.Serialize(body);
        var content = new StringContent(jsonBody, Encoding.UTF8, "application/json");

        var response = await httpClient.PatchAsync(graphApiEndpoint, content);
        var responseBody = await response.Content.ReadAsStringAsync();
        response.EnsureSuccessStatusCode();

    }
}

原因分析

你当前仅更新了mobilePhone字段,这个字段是用户的联系电话属性,并非Azure AD中用于登录验证的身份标识字段。真正用于手机号登录的是用户的identities属性集合中的phoneNumber类型条目。

解决方法

需要修改Graph API的Patch请求,更新用户的identities属性,添加或替换手机号类型的登录标识。同时注意:

  • 确保应用已获得User.ReadWrite.All或Directory.ReadWrite.All的应用权限,且已完成管理员同意
  • 如果用户原有其他登录标识(如邮箱、用户名),必须在identities数组中保留,否则会被Patch操作移除,导致用户无法用原有方式登录

修改后的ResetMobileNumber方法代码

static async Task ResetMobileNumber(string accessToken, string objectId, string newMobile)
{
    using (HttpClient httpClient = new HttpClient())
    {
        httpClient.DefaultRequestHeaders.Add("Authorization", $"Bearer {accessToken}");

        string graphApiEndpoint = $"https://graph.microsoft.com/v1.0/users/{objectId}";

        // 构建包含手机号登录标识的请求体,注意保留原有其他登录标识
        var body = new
        {
            identities = new[]
            {
                new
                {
                    signInType = "phoneNumber",
                    issuer = "your-tenant-domain.com", // 替换为你的租户域名或租户ID
                    issuerAssignedId = newMobile // 格式需为+[国家代码][手机号],如+14255551234
                },
                // 示例:保留用户原有邮箱登录标识(如果存在)
                // new
                // {
                //     signInType = "emailAddress",
                //     issuer = "your-tenant-domain.com",
                //     issuerAssignedId = "user@your-tenant-domain.com"
                // }
            }
        };

        var jsonBody = System.Text.Json.JsonSerializer.Serialize(body);
        var content = new StringContent(jsonBody, Encoding.UTF8, "application/json");

        var response = await httpClient.PatchAsync(graphApiEndpoint, content);
        var responseBody = await response.Content.ReadAsStringAsync();
        response.EnsureSuccessStatusCode();
    }
}

关键说明

  1. issuer字段:填写你的租户域名(如contoso.com)或租户ID,确保与用户现有登录标识的issuer一致
  2. issuerAssignedId字段:手机号必须使用国际标准格式,以+开头,紧跟国家代码和手机号
  3. 保留原有标识:如果用户有其他登录方式,务必在identities数组中包含这些条目,避免丢失登录途径

内容的提问来源于stack exchange,提问作者Dilshan Prasad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 09:15:03