MSOnline的StrongAuthenticationRequirement在MSGraph中的等效实现?
使用Microsoft Graph PowerShell替代MSOnline模块强制启用用户MFA
是的,你可以使用Microsoft Graph PowerShell模块实现完全等效的功能,该模块支持PowerShell Core和Windows PowerShell,是微软官方推荐的MSOnline模块替代方案。
等效代码实现
1. 准备工作
先确保已安装并连接Microsoft Graph PowerShell模块:
# 首次运行时安装模块 Install-Module -Name Microsoft.Graph -Force -AllowClobber # 连接Graph并获取必要权限 Connect-MgGraph -Scopes "User.ReadWrite.All", "AuthenticationMethod.ReadWrite.All"
2. 单个用户强制启用MFA的等效代码
这段代码和你原MSOnline代码逻辑完全匹配,为指定用户设置全局(所有依赖方)的MFA强制要求:
# 定义MFA强制要求配置 $strongAuthConfig = @{ relyingParty = "*" state = "Enforced" } # 将配置应用到目标用户($upn为用户的UserPrincipalName) Set-MgUser -UserId $upn -BodyParameter @{ strongAuthenticationRequirements = @($strongAuthConfig) }
更推荐的批量管理方案
针对大规模用户的MFA强制管理,微软更推荐使用条件访问策略,相比单个用户设置更灵活、易于维护:
# 创建条件访问策略,强制所有用户访问任何应用时使用MFA New-MgIdentityConditionalAccessPolicy -DisplayName "全局MFA强制策略" -State "Enabled" -Conditions @{ Users = @{ IncludeUsers = @("all") } Applications = @{ IncludeApplications = @("all") } } -GrantControls @{ Operator = "OR" BuiltInControls = @("mfa") }
内容的提问来源于stack exchange,提问作者tyteen4a03
相关产品推荐
相关产品推荐

