You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为Azure AD B2C配置用户自选MFA方法及相关疑问咨询

针对Azure AD B2C MFA配置的解决方案

问题1:用户启用MFA并同步Per-user MFA状态

添加邮箱、电话等认证方法不会自动触发Per-user MFA状态从Disabled变为Enabled,需要分两步操作:

步骤1:让用户添加指定的MFA验证方式

通过Microsoft Graph API为用户添加对应认证方法:

  • 添加邮箱验证:
    POST /users/{user-id}/authentication/emailMethods
    Content-Type: application/json
    
    {
      "emailAddress": "user@example.com"
    }
    
  • 添加短信/电话验证:
    POST /users/{user-id}/authentication/phoneMethods
    Content-Type: application/json
    
    {
      "phoneNumber": "+1234567890",
      "phoneType": "mobile"
    }
    
  • 添加微软认证应用:
    需要引导用户完成注册流程,可调用以下API初始化注册:
    POST /users/{user-id}/authentication/microsoftAuthenticatorMethods/deviceRegistrationDetails
    

步骤2:更新Per-user MFA状态为Enabled

调用Graph API更新用户的强认证要求,将MFA状态设为Enabled:

PATCH /users/{user-id}
Content-Type: application/json

{
  "strongAuthenticationRequirements": [
    {
      "@odata.type": "#microsoft.graph.strongAuthenticationRequirement",
      "state": "enabled",
      "realm": "",
      "rememberDevicesNotIssuedByMicrosoft": false
    }
  ]
}

执行后,Azure AD B2C的Per-user multifactor authentication页面中该用户的状态会同步为Enabled。

问题2:MFA Enabled状态下的验证触发逻辑

  • 默认行为:当Per-user MFA状态为Enabled时,用户每次登录都需要完成MFA验证(短信、电话或认证应用),无论操作类型。
  • 自定义触发场景:如果不想每次登录都验证,需要通过条件访问策略替代Per-user MFA配置。条件访问可以设置仅在特定场景触发MFA,比如:
    • 用户从非信任位置登录
    • 用户执行高风险操作(如修改密码、更改个人信息)
    • 用户使用非信任设备登录
      这种情况下,Per-user MFA状态可以保持Disabled,完全通过条件访问策略控制MFA的触发时机。

内容的提问来源于stack exchange,提问作者Pham Huu Truong

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 12:47:19