如何在Microsoft Graph及AD OAuth2认证中区分学校与工作账户及师生与企业用户
Great questions—these are super common when building apps that integrate with Microsoft's identity platform. Let's break down each scenario clearly:
Distinguishing Enterprise Users from Students/Teachers (After Tenant ID Check)
Once you've used the tenant ID to separate work/school accounts from personal ones, here's how to narrow it down further:
- Microsoft Graph's Education User Endpoint: The most reliable method is to call
GET /users/{user-id}/educationUser. If this returns a valideducationUserobject, the user is either a student or teacher—you can check theprimaryRolefield in the response to tell them apart (values likestudent,teacher, orstaff). If the call returns a 404, the user is an enterprise employee. - Tenant-Level Industry Check: Fetch the tenant's details with
GET /organizationand look at theindustryproperty. If it's set toEducation, you’re dealing with an educational institution tenant. Note: While rare, some orgs might have mixed user types, so always pair this with the user-specific check above. - UPN Suffix Hint: Many schools use
.edu(or country-specific variants like.ac.uk) for user principal names, but this isn't 100% reliable—some enterprises might use similar suffixes. Treat this as a secondary clue, not a definitive identifier.
Differentiating School vs. Work Accounts in Microsoft AD OAuth 2.0
Absolutely—you can use identity token claims and Microsoft Graph queries to tell these apart:
- Tenant ID + Tenant Details:
- The
tidclaim in your OAuth 2.0 ID token gives you the tenant ID. Use this to callGET /organizationand check theindustryfield:Education= School/educational tenant- Values like
Corporate,FinancialServices, etc. = Work/enterprise tenant
- You can also glance at the tenant's
displayName(often includes a school/university name), but again, use this as a supplement to the industry check.
- The
- Identity Token Claims:
- Some educational tenants include custom extension claims in the ID token (e.g.,
extension_<unique-guid>_Education_StudentIdorextension_<unique-guid>_Education_TeacherId) if they’re using Microsoft Education tools. To access these, ensure your app has permissions likeUser.ReadBasic.Alland request the relevant claims in your auth scope. - The
rolesclaim might include education-specific roles (e.g.,Teacher,Student) if the tenant has assigned them, but this depends on the org's setup.
- Some educational tenants include custom extension claims in the ID token (e.g.,
- User-Specific Graph Check:
- As mentioned earlier, calling
GET /users/{user-id}/educationUserwill confirm if the user is part of an educational system. A successful response means it's a school account; a 404 means it's a work account.
- As mentioned earlier, calling
Quick Tips
- Always prioritize Graph API checks over UPN suffixes or tenant names—those can lead to false positives.
- Ensure your app has the necessary permissions (like
User.Read,Education.ReadBasic.All) to fetch these properties. - If using the v2.0 auth endpoint, you can use the
claimsparameter in your auth request to pull education-specific data directly into the ID token, cutting down on extra API calls.
内容的提问来源于stack exchange,提问作者Yordana Dekova
相关产品推荐
相关产品推荐

