You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Microsoft Graph在B2C中通过应用UI创建带MFA认证的用户

使用Microsoft Graph创建Azure AD B2C带双因素认证(手机+密码)的用户

前提条件

  • 已在Azure AD B2C租户中完成应用注册,且该应用已被授予User.ReadWrite.All、UserAuthenticationMethod.ReadWrite.All权限(应用权限或委派权限,根据调用场景选择)。
  • 已获取针对该应用的有效Microsoft Graph访问令牌。

步骤1:创建带密码的用户

调用POST /users接口创建用户,同时设置初始密码。请求体需包含用户基本信息、密码配置以及B2C用户标识:

{
  "accountEnabled": true,
  "displayName": "张三",
  "mailNickname": "zhangsan",
  "userPrincipalName": "zhangsan@yourb2ctenant.onmicrosoft.com",
  "passwordProfile": {
    "password": "StrongPass_123",
    "forceChangePasswordNextSignIn": false
  },
  "identities": [
    {
      "signInType": "emailAddress",
      "issuer": "yourb2ctenant.onmicrosoft.com",
      "issuerAssignedId": "zhangsan@example.com"
    }
  ]
}
  • identities字段根据B2C用户流类型调整:如果是用户名登录,signInType设为userName,issuerAssignedId填写用户名。
  • forceChangePasswordNextSignIn设为false可避免用户首次登录必须修改密码,按需调整。

步骤2:添加手机MFA认证方法

用户创建成功后,调用POST /users/{userId}/authentication/phoneMethods接口绑定用户的手机作为MFA方法:

{
  "phoneNumber": "+8613800138000",
  "phoneType": "mobile"
}
  • userId为上一步创建用户后返回的id值。
  • 手机号码需使用国际标准格式,比如中国大陆号码以+86开头。

步骤3:(可选)设置默认MFA方法

若需要将该手机设为用户默认的MFA验证方式,调用POST /users/{userId}/authentication/phoneMethods/{phoneMethodId}/setAsPreferred接口,其中phoneMethodId是步骤2返回的手机方法ID。


注意事项

  • 密码需符合Azure AD B2C的密码复杂度规则,比如长度至少8位、包含大小写字母、数字或特殊字符。
  • 所有Graph API请求需使用Azure AD B2C租户对应的Graph端点:https://graph.microsoft.com/v1.0。
  • 应用权限需由B2C租户管理员完成同意授权,否则无法调用相关接口。

内容的提问来源于stack exchange,提问作者Allan Xu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 04:57:26