使用Microsoft Graph API更新Azure AD手机号后无法登录的问题
问题:通过Graph API更新Azure AD用户手机号后无法用新号码登录
我通过Microsoft Graph API的用户更新端点修改了Azure AD中用户的手机号,Azure AD后台已显示更新成功,但用户无法使用新手机号登录账号。使用的代码如下:
static async Task Main(string[] args) { string tenantId = <tenant-id>; string clientId = <client-id>; string clientSecret = <client-secret>; var objectId = <object-id>; var newMobile = <new-mobile-number>; try { string accessToken = await GetAccessToken(tenantId, clientId, clientSecret); await ResetMobileNumber(accessToken, objectId, newMobile ); Console.WriteLine("Mobile number reset successfully!"); } catch (Exception ex) { Console.WriteLine($"An error occurred: {ex.Message}"); } } static async Task<string> GetAccessToken(string tenantId, string clientId, string clientSecret) { using (HttpClient client = new HttpClient()) { string tokenEndpoint = $"https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token"; var body = $"grant_type=client_credentials&client_id={clientId}&client_secret={clientSecret}&scope=https://graph.microsoft.com/.default"; var response = await client.PostAsync(tokenEndpoint, new StringContent(body, Encoding.UTF8, "application/x-www-form-urlencoded")); var responseBody = await response.Content.ReadAsStringAsync(); var tokenJson = System.Text.Json.JsonDocument.Parse(responseBody).RootElement; string accessToken = tokenJson.GetProperty("access_token").GetString(); return accessToken; } } static async Task ResetMobileNumber(string accessToken, string objectId, string newMobile) { using (HttpClient httpClient = new HttpClient()) { httpClient.DefaultRequestHeaders.Add("Authorization", $"Bearer {accessToken}"); string graphApiEndpoint = $"https://graph.microsoft.com/v1.0/users/{objectId}"; var body = new { mobilePhone = newMobile }; var jsonBody = System.Text.Json.JsonSerializer.Serialize(body); var content = new StringContent(jsonBody, Encoding.UTF8, "application/json"); var response = await httpClient.PatchAsync(graphApiEndpoint, content); var responseBody = await response.Content.ReadAsStringAsync(); response.EnsureSuccessStatusCode(); } }
原因分析
你当前仅更新了mobilePhone字段,这个字段是用户的联系电话属性,并非Azure AD中用于登录验证的身份标识字段。真正用于手机号登录的是用户的identities属性集合中的phoneNumber类型条目。
解决方法
需要修改Graph API的Patch请求,更新用户的identities属性,添加或替换手机号类型的登录标识。同时注意:
- 确保应用已获得
User.ReadWrite.All或Directory.ReadWrite.All的应用权限,且已完成管理员同意 - 如果用户原有其他登录标识(如邮箱、用户名),必须在
identities数组中保留,否则会被Patch操作移除,导致用户无法用原有方式登录
修改后的ResetMobileNumber方法代码
static async Task ResetMobileNumber(string accessToken, string objectId, string newMobile) { using (HttpClient httpClient = new HttpClient()) { httpClient.DefaultRequestHeaders.Add("Authorization", $"Bearer {accessToken}"); string graphApiEndpoint = $"https://graph.microsoft.com/v1.0/users/{objectId}"; // 构建包含手机号登录标识的请求体,注意保留原有其他登录标识 var body = new { identities = new[] { new { signInType = "phoneNumber", issuer = "your-tenant-domain.com", // 替换为你的租户域名或租户ID issuerAssignedId = newMobile // 格式需为+[国家代码][手机号],如+14255551234 }, // 示例:保留用户原有邮箱登录标识(如果存在) // new // { // signInType = "emailAddress", // issuer = "your-tenant-domain.com", // issuerAssignedId = "user@your-tenant-domain.com" // } } }; var jsonBody = System.Text.Json.JsonSerializer.Serialize(body); var content = new StringContent(jsonBody, Encoding.UTF8, "application/json"); var response = await httpClient.PatchAsync(graphApiEndpoint, content); var responseBody = await response.Content.ReadAsStringAsync(); response.EnsureSuccessStatusCode(); } }
关键说明
issuer字段:填写你的租户域名(如contoso.com)或租户ID,确保与用户现有登录标识的issuer一致issuerAssignedId字段:手机号必须使用国际标准格式,以+开头,紧跟国家代码和手机号- 保留原有标识:如果用户有其他登录方式,务必在
identities数组中包含这些条目,避免丢失登录途径
内容的提问来源于stack exchange,提问作者Dilshan Prasad
相关产品推荐
相关产品推荐

