如何在Microsoft Graph API v1.0中查询用户MFA状态?
在Microsoft Graph v1.0中获取组织用户MFA状态的可行方案
方案1:查询单个用户的MFA配置状态
通过v1.0的authentication/methods端点,可获取用户已配置的所有认证方法,以此判断其MFA状态:
- 请求端点:
GET https://graph.microsoft.com/v1.0/users/{user-id}/authentication/methods - 权限要求:需具备
UserAuthenticationMethod.Read.All(应用权限)或UserAuthenticationMethod.Read(委派权限) - 判断逻辑:响应中若包含以下任意一种认证方法类型,说明用户已配置MFA:
microsoftAuthenticatorAuthenticationMethodphoneAuthenticationMethodfido2AuthenticationMethodsoftwareOathAuthenticationMethod
方案2:批量查询组织内用户MFA状态
若需要批量获取所有用户的MFA配置情况,可通过$expand关联用户的认证方法:
- 请求端点:
GET https://graph.microsoft.com/v1.0/users?$expand=authentication/methods&$select=id,userPrincipalName,displayName - 注意:返回结果包含所有用户及其认证方法,需自行过滤出已配置MFA的用户。
关于beta版本返回空列表的补充说明
beta分支的credentialUserRegistrationDetails返回空列表,通常是因为缺少Reports.Read.All应用权限,或租户内暂无用户完成MFA注册,但该端点仅存在于beta分支,v1.0无直接替代项。
内容的提问来源于stack exchange,提问作者Amit Nahmias
相关产品推荐
相关产品推荐

