如何使用Microsoft Graph在B2C中通过应用UI创建带MFA认证的用户
使用Microsoft Graph创建Azure AD B2C带双因素认证(手机+密码)的用户
前提条件
- 已在Azure AD B2C租户中完成应用注册,且该应用已被授予
User.ReadWrite.All、UserAuthenticationMethod.ReadWrite.All权限(应用权限或委派权限,根据调用场景选择)。 - 已获取针对该应用的有效Microsoft Graph访问令牌。
步骤1:创建带密码的用户
调用POST /users接口创建用户,同时设置初始密码。请求体需包含用户基本信息、密码配置以及B2C用户标识:
{ "accountEnabled": true, "displayName": "张三", "mailNickname": "zhangsan", "userPrincipalName": "zhangsan@yourb2ctenant.onmicrosoft.com", "passwordProfile": { "password": "StrongPass_123", "forceChangePasswordNextSignIn": false }, "identities": [ { "signInType": "emailAddress", "issuer": "yourb2ctenant.onmicrosoft.com", "issuerAssignedId": "zhangsan@example.com" } ] }
identities字段根据B2C用户流类型调整:如果是用户名登录,signInType设为userName,issuerAssignedId填写用户名。forceChangePasswordNextSignIn设为false可避免用户首次登录必须修改密码,按需调整。
步骤2:添加手机MFA认证方法
用户创建成功后,调用POST /users/{userId}/authentication/phoneMethods接口绑定用户的手机作为MFA方法:
{ "phoneNumber": "+8613800138000", "phoneType": "mobile" }
userId为上一步创建用户后返回的id值。- 手机号码需使用国际标准格式,比如中国大陆号码以
+86开头。
步骤3:(可选)设置默认MFA方法
若需要将该手机设为用户默认的MFA验证方式,调用POST /users/{userId}/authentication/phoneMethods/{phoneMethodId}/setAsPreferred接口,其中phoneMethodId是步骤2返回的手机方法ID。
注意事项
- 密码需符合Azure AD B2C的密码复杂度规则,比如长度至少8位、包含大小写字母、数字或特殊字符。
- 所有Graph API请求需使用Azure AD B2C租户对应的Graph端点:
https://graph.microsoft.com/v1.0。 - 应用权限需由B2C租户管理员完成同意授权,否则无法调用相关接口。
内容的提问来源于stack exchange,提问作者Allan Xu
相关产品推荐
相关产品推荐

