为Azure AD B2C配置用户自选MFA方法及相关疑问咨询
针对Azure AD B2C MFA配置的解决方案
问题1:用户启用MFA并同步Per-user MFA状态
添加邮箱、电话等认证方法不会自动触发Per-user MFA状态从Disabled变为Enabled,需要分两步操作:
步骤1:让用户添加指定的MFA验证方式
通过Microsoft Graph API为用户添加对应认证方法:
- 添加邮箱验证:
POST /users/{user-id}/authentication/emailMethods Content-Type: application/json { "emailAddress": "user@example.com" } - 添加短信/电话验证:
POST /users/{user-id}/authentication/phoneMethods Content-Type: application/json { "phoneNumber": "+1234567890", "phoneType": "mobile" } - 添加微软认证应用:
需要引导用户完成注册流程,可调用以下API初始化注册:POST /users/{user-id}/authentication/microsoftAuthenticatorMethods/deviceRegistrationDetails
步骤2:更新Per-user MFA状态为Enabled
调用Graph API更新用户的强认证要求,将MFA状态设为Enabled:
PATCH /users/{user-id} Content-Type: application/json { "strongAuthenticationRequirements": [ { "@odata.type": "#microsoft.graph.strongAuthenticationRequirement", "state": "enabled", "realm": "", "rememberDevicesNotIssuedByMicrosoft": false } ] }
执行后,Azure AD B2C的Per-user multifactor authentication页面中该用户的状态会同步为Enabled。
问题2:MFA Enabled状态下的验证触发逻辑
- 默认行为:当Per-user MFA状态为Enabled时,用户每次登录都需要完成MFA验证(短信、电话或认证应用),无论操作类型。
- 自定义触发场景:如果不想每次登录都验证,需要通过条件访问策略替代Per-user MFA配置。条件访问可以设置仅在特定场景触发MFA,比如:
- 用户从非信任位置登录
- 用户执行高风险操作(如修改密码、更改个人信息)
- 用户使用非信任设备登录
这种情况下,Per-user MFA状态可以保持Disabled,完全通过条件访问策略控制MFA的触发时机。
内容的提问来源于stack exchange,提问作者Pham Huu Truong
相关产品推荐
相关产品推荐

