You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Azure AD B2C Graph API查询用户是否已配置MFA?

Checking MFA Configuration for Azure AD B2C Users via Microsoft Graph API

Absolutely, you can verify whether a specific Azure AD B2C user has set up MFA using the Microsoft Graph API (note that Azure AD B2C now uses the unified Microsoft Graph instead of the legacy Azure AD Graph). Let me walk you through the exact steps to make this work.

Key Background

Azure AD B2C stores MFA configuration details for users in specific user properties exposed via Microsoft Graph. The most reliable way to check for configured MFA methods is by looking at the strongAuthenticationMethods property.

Step 1: Required Permissions

First, ensure your registered application in Azure AD B2C has the right API permissions. For read-only access to user MFA data, you’ll need:

  • User.Read.All (application permission) if you’re querying users in bulk or without a user context
  • User.Read (delegated permission) if you’re querying the authenticated user’s own MFA status

Don’t forget to grant admin consent for application permissions after adding them.

Step 2: Query the User’s MFA Status

Use a GET request to fetch the user’s profile, specifically requesting the strongAuthenticationMethods property (along with any other user details you need).

Example API Call

GET https://graph.microsoft.com/v1.0/users/{user-object-id}?$select=id,displayName,strongAuthenticationMethods

Replace {user-object-id} with the target user’s object ID (you can find this in the Azure AD B2C portal under Users).

Step 3: Interpret the Response

The strongAuthenticationMethods array in the response will list all MFA methods the user has configured. If this array is non-empty, the user has set up MFA. Each entry includes a methodType field that specifies the type of MFA method, such as:

  • phoneOneTimePassword: SMS or voice call verification
  • microsoftAuthenticatorPush: Microsoft Authenticator app push notifications
  • fido2SecurityKey: FIDO2 security key
  • softwareOneTimePassword: Third-party authenticator app (like Google Authenticator)

Sample Response Snippet

{
  "id": "12345678-1234-1234-1234-1234567890ab",
  "displayName": "John Doe",
  "strongAuthenticationMethods": [
    {
      "methodType": "microsoftAuthenticatorPush",
      "isDefault": true,
      "id": "abc123..."
    },
    {
      "methodType": "phoneOneTimePassword",
      "isDefault": false,
      "id": "def456..."
    }
  ]
}

Important Notes

  • Distinguish "Configured" vs. "Required": A user might be required to set up MFA via a B2C policy but haven’t completed the setup yet. In this case, strongAuthenticationMethods will be empty.
  • Legacy Property: You might see references to strongAuthenticationPhoneNumber in older docs—this is a deprecated property, so stick to strongAuthenticationMethods for accurate, up-to-date data.
  • Token Validation: Ensure your access token is valid and issued for the Microsoft Graph endpoint (https://graph.microsoft.com) with the correct audience for your Azure AD B2C tenant.

内容的提问来源于stack exchange,提问作者Frank Houweling

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 19:47:42