Azure中通过PowerShell移除用户号码并吊销MFA会话的命令咨询
使用PowerShell处理离职用户的MFA关联号码移除与会话吊销
完全可以通过PowerShell(推荐使用Microsoft Graph PowerShell模块)完成这些操作,具体步骤如下:
前置准备
- 安装Microsoft Graph PowerShell模块:
Install-Module Microsoft.Graph -Force -AllowClobber
- 连接模块并获取必要权限:
Connect-MgGraph -Scopes UserAuthenticationMethod.ReadWrite.All, User.ReadWrite.All
1. 移除用户关联的电话号码
替换目标用户的UPN或Azure AD用户ID,执行命令删除所有绑定的电话号码:
# 替换为离职用户的UPN或用户ID $targetUser = "departed-user@yourdomain.com" # 获取用户所有电话号码认证方法 $phoneAuthMethods = Get-MgUserAuthenticationPhoneMethod -UserId $targetUser # 遍历删除每一个号码 foreach ($method in $phoneAuthMethods) { Remove-MgUserAuthenticationPhoneMethod -UserId $targetUser -PhoneAuthenticationMethodId $method.Id Write-Host "已移除用户 $targetUser 的电话号码: $($method.PhoneNumber)" }
2. 吊销用户的MFA会话
执行以下命令吊销用户所有登录会话(包含MFA会话),用户下次登录需重新完成MFA验证:
Revoke-MgUserSignInSession -UserId $targetUser Write-Host "已吊销用户 $targetUser 的所有登录/MFA会话"
3. 保存操作记录
如果需要留存操作日志,可将结果输出到本地文件:
$logFile = ".\DepartedUser_MFA_Operations.log" $timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss" Add-Content -Path $logFile -Value "[$timestamp] 处理用户: $targetUser" Add-Content -Path $logFile -Value "[$timestamp] 移除的电话号码: $($phoneAuthMethods.PhoneNumber -join ', ')" Add-Content -Path $logFile -Value "[$timestamp] 已成功吊销MFA会话`n"
注意事项
- 确保执行操作的账号拥有
UserAuthenticationMethod.ReadWrite.All和User.ReadWrite.All权限 - 操作前务必确认目标用户信息正确,避免误操作
- 可通过
Get-MgUserAuthenticationPhoneMethod -UserId $targetUser验证号码是否已完全移除
内容的提问来源于stack exchange,提问作者Suri007
相关产品推荐
相关产品推荐

