如何通过Azure AD B2C Graph API查询用户是否已配置MFA?
Absolutely, you can verify whether a specific Azure AD B2C user has set up MFA using the Microsoft Graph API (note that Azure AD B2C now uses the unified Microsoft Graph instead of the legacy Azure AD Graph). Let me walk you through the exact steps to make this work.
Key Background
Azure AD B2C stores MFA configuration details for users in specific user properties exposed via Microsoft Graph. The most reliable way to check for configured MFA methods is by looking at the strongAuthenticationMethods property.
Step 1: Required Permissions
First, ensure your registered application in Azure AD B2C has the right API permissions. For read-only access to user MFA data, you’ll need:
- User.Read.All (application permission) if you’re querying users in bulk or without a user context
- User.Read (delegated permission) if you’re querying the authenticated user’s own MFA status
Don’t forget to grant admin consent for application permissions after adding them.
Step 2: Query the User’s MFA Status
Use a GET request to fetch the user’s profile, specifically requesting the strongAuthenticationMethods property (along with any other user details you need).
Example API Call
GET https://graph.microsoft.com/v1.0/users/{user-object-id}?$select=id,displayName,strongAuthenticationMethods
Replace {user-object-id} with the target user’s object ID (you can find this in the Azure AD B2C portal under Users).
Step 3: Interpret the Response
The strongAuthenticationMethods array in the response will list all MFA methods the user has configured. If this array is non-empty, the user has set up MFA. Each entry includes a methodType field that specifies the type of MFA method, such as:
phoneOneTimePassword: SMS or voice call verificationmicrosoftAuthenticatorPush: Microsoft Authenticator app push notificationsfido2SecurityKey: FIDO2 security keysoftwareOneTimePassword: Third-party authenticator app (like Google Authenticator)
Sample Response Snippet
{ "id": "12345678-1234-1234-1234-1234567890ab", "displayName": "John Doe", "strongAuthenticationMethods": [ { "methodType": "microsoftAuthenticatorPush", "isDefault": true, "id": "abc123..." }, { "methodType": "phoneOneTimePassword", "isDefault": false, "id": "def456..." } ] }
Important Notes
- Distinguish "Configured" vs. "Required": A user might be required to set up MFA via a B2C policy but haven’t completed the setup yet. In this case,
strongAuthenticationMethodswill be empty. - Legacy Property: You might see references to
strongAuthenticationPhoneNumberin older docs—this is a deprecated property, so stick tostrongAuthenticationMethodsfor accurate, up-to-date data. - Token Validation: Ensure your access token is valid and issued for the Microsoft Graph endpoint (
https://graph.microsoft.com) with the correct audience for your Azure AD B2C tenant.
内容的提问来源于stack exchange,提问作者Frank Houweling

