You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure中通过PowerShell移除用户号码并吊销MFA会话的命令咨询

使用PowerShell处理离职用户的MFA关联号码移除与会话吊销

完全可以通过PowerShell(推荐使用Microsoft Graph PowerShell模块)完成这些操作,具体步骤如下:

前置准备

  1. 安装Microsoft Graph PowerShell模块:
Install-Module Microsoft.Graph -Force -AllowClobber
  1. 连接模块并获取必要权限:
Connect-MgGraph -Scopes UserAuthenticationMethod.ReadWrite.All, User.ReadWrite.All

1. 移除用户关联的电话号码

替换目标用户的UPN或Azure AD用户ID,执行命令删除所有绑定的电话号码:

# 替换为离职用户的UPN或用户ID
$targetUser = "departed-user@yourdomain.com"

# 获取用户所有电话号码认证方法
$phoneAuthMethods = Get-MgUserAuthenticationPhoneMethod -UserId $targetUser

# 遍历删除每一个号码
foreach ($method in $phoneAuthMethods) {
    Remove-MgUserAuthenticationPhoneMethod -UserId $targetUser -PhoneAuthenticationMethodId $method.Id
    Write-Host "已移除用户 $targetUser 的电话号码: $($method.PhoneNumber)"
}

2. 吊销用户的MFA会话

执行以下命令吊销用户所有登录会话(包含MFA会话),用户下次登录需重新完成MFA验证:

Revoke-MgUserSignInSession -UserId $targetUser
Write-Host "已吊销用户 $targetUser 的所有登录/MFA会话"

3. 保存操作记录

如果需要留存操作日志,可将结果输出到本地文件:

$logFile = ".\DepartedUser_MFA_Operations.log"
$timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss"

Add-Content -Path $logFile -Value "[$timestamp] 处理用户: $targetUser"
Add-Content -Path $logFile -Value "[$timestamp] 移除的电话号码: $($phoneAuthMethods.PhoneNumber -join ', ')"
Add-Content -Path $logFile -Value "[$timestamp] 已成功吊销MFA会话`n"

注意事项

  • 确保执行操作的账号拥有UserAuthenticationMethod.ReadWrite.All和User.ReadWrite.All权限
  • 操作前务必确认目标用户信息正确,避免误操作
  • 可通过Get-MgUserAuthenticationPhoneMethod -UserId $targetUser验证号码是否已完全移除

内容的提问来源于stack exchange,提问作者Suri007

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 12:06:27