You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MSOnline的StrongAuthenticationRequirement在MSGraph中的等效实现?

使用Microsoft Graph PowerShell替代MSOnline模块强制启用用户MFA

是的,你可以使用Microsoft Graph PowerShell模块实现完全等效的功能,该模块支持PowerShell Core和Windows PowerShell,是微软官方推荐的MSOnline模块替代方案。

等效代码实现

1. 准备工作

先确保已安装并连接Microsoft Graph PowerShell模块:

# 首次运行时安装模块
Install-Module -Name Microsoft.Graph -Force -AllowClobber

# 连接Graph并获取必要权限
Connect-MgGraph -Scopes "User.ReadWrite.All", "AuthenticationMethod.ReadWrite.All"

2. 单个用户强制启用MFA的等效代码

这段代码和你原MSOnline代码逻辑完全匹配,为指定用户设置全局(所有依赖方)的MFA强制要求:

# 定义MFA强制要求配置
$strongAuthConfig = @{
    relyingParty = "*"
    state = "Enforced"
}

# 将配置应用到目标用户($upn为用户的UserPrincipalName)
Set-MgUser -UserId $upn -BodyParameter @{
    strongAuthenticationRequirements = @($strongAuthConfig)
}

更推荐的批量管理方案

针对大规模用户的MFA强制管理,微软更推荐使用条件访问策略,相比单个用户设置更灵活、易于维护:

# 创建条件访问策略,强制所有用户访问任何应用时使用MFA
New-MgIdentityConditionalAccessPolicy -DisplayName "全局MFA强制策略" -State "Enabled" -Conditions @{
    Users = @{
        IncludeUsers = @("all")
    }
    Applications = @{
        IncludeApplications = @("all")
    }
} -GrantControls @{
    Operator = "OR"
    BuiltInControls = @("mfa")
}

内容的提问来源于stack exchange,提问作者tyteen4a03

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 16:40:34