You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将本地Active Directory手机号自动同步至Azure AD的MFA字段?

本地AD手机号自动同步到Azure AD MFA认证字段方案

一、现有用户批量自动迁移方法

可以通过PowerShell + Microsoft Graph API实现无手动操作的批量迁移,替代你之前尝试的无效方案,步骤如下:

1. 准备工作

  • 安装最新版Microsoft Graph PowerShell模块:
Install-Module Microsoft.Graph -Force -AllowClobber
  • 赋予操作账号权限:需要AuthenticationMethod.ReadWrite.All、User.Read.All、Directory.Read.All权限,用全局管理员账号登录授权:
Connect-MgGraph -Scopes "AuthenticationMethod.ReadWrite.All", "User.Read.All", "Directory.Read.All"
Select-MgProfile -Name beta # 认证方法操作需使用beta端点

2. 批量迁移脚本

脚本会从本地AD读取用户手机号(优先取General标签的mobile属性,无值则取Telephones标签的telephoneNumber),匹配Azure AD用户后自动添加为MFA认证手机号:

# 获取本地AD所有用户及手机号属性
$localADUsers = Get-ADUser -Filter * -Properties mobile, telephoneNumber, UserPrincipalName

foreach ($user in $localADUsers) {
    # 匹配Azure AD用户(通过UserPrincipalName关联)
    $azureUser = Get-MgUser -Filter "UserPrincipalName eq '$($user.UserPrincipalName)'"
    
    if ($azureUser) {
        # 优先使用mobile属性,无值则用telephoneNumber
        $targetPhone = $user.mobile ? $user.mobile : $user.telephoneNumber
        
        if ($targetPhone) {
            # 统一转换为E.164格式(必须带国家码前缀,示例为+86,根据实际调整)
            if (-not $targetPhone.StartsWith("+")) {
                $targetPhone = "+86$($targetPhone -replace '\D', '')" # 去除非数字字符后加国家码
            }

            try {
                # 检查用户是否已存在该手机号认证方法,避免重复添加
                $existingPhones = Get-MgUserAuthenticationPhoneMethod -UserId $azureUser.Id
                if (-not ($existingPhones | Where-Object { $_.PhoneNumber -eq $targetPhone })) {
                    New-MgUserAuthenticationPhoneMethod -UserId $azureUser.Id -PhoneType "mobile" -PhoneNumber $targetPhone
                    Write-Host "✅ 成功同步用户 $($user.UserPrincipalName) 的MFA手机号"
                } else {
                    Write-Host "ℹ️ 用户 $($user.UserPrincipalName) 已存在该手机号认证方法,跳过"
                }
            } catch {
                Write-Host "❌ 处理用户 $($user.UserPrincipalName) 失败:$($_.Exception.Message)"
            }
        } else {
            Write-Host "ℹ️ 用户 $($user.UserPrincipalName) 无可用手机号,跳过"
        }
    } else {
        Write-Host "⚠️ 未在Azure AD中找到用户 $($user.UserPrincipalName),跳过"
    }
}

3. 注意事项

  • 手机号必须符合E.164国际标准格式(如+8613800138000),否则Graph API会拒绝请求
  • 若需定期同步,可将脚本设置为本地任务计划,每周/每月执行一次
  • 注意Graph API速率限制,批量操作时可添加Start-Sleep -Seconds 1避免触发限流

二、新建用户自动同步方案

针对本地AD新建用户并同步到Azure AD后,自动将手机号同步至MFA字段,有两种可行方案:

方案1:Power Automate云流触发

  1. 创建云流,触发条件选择**「当Azure AD用户被创建时」**
  2. 添加「调用HTTP」动作,配置如下:
    • 方法:POST
    • URI:https://graph.microsoft.com/beta/users/@{triggerBody()?['id']}/authentication/phoneMethods
    • 身份验证:选择「Active Directory OAuth」,配置租户ID、应用ID(需提前注册Graph应用并赋予AuthenticationMethod.ReadWrite.All权限)
    • 请求体:
      {
          "phoneNumber": "+86@{body('获取本地AD用户手机号')?['mobile']}",
          "phoneType": "mobile"
      }
      
  3. 新增「执行PowerShell脚本」动作(或使用AD连接器),根据用户UPN从本地AD获取mobile属性值,填入上述请求体

方案2:本地AD事件触发PowerShell脚本

  1. 监控本地AD服务器的事件ID 4720(用户创建事件)
  2. 创建任务计划,当该事件触发时执行脚本:
    • 脚本从事件中提取新建用户的UPN
    • 读取该用户的mobile属性
    • 通过Graph API同步至Azure AD的MFA认证字段(逻辑同批量迁移脚本)

关于Microsoft.Graph.Identity.Signins无效的说明

该模块的部分功能已被整合到Microsoft Graph的认证方法端点(beta版本),建议直接使用上述基于Microsoft.Graph模块的方案,避免依赖旧版模块的兼容性问题。

内容的提问来源于stack exchange,提问作者Vf59

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 13:24:53