You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Microsoft Graph及AD OAuth2认证中区分学校与工作账户及师生与企业用户

Great questions—these are super common when building apps that integrate with Microsoft's identity platform. Let's break down each scenario clearly:

Distinguishing Enterprise Users from Students/Teachers (After Tenant ID Check)

Once you've used the tenant ID to separate work/school accounts from personal ones, here's how to narrow it down further:

  • Microsoft Graph's Education User Endpoint: The most reliable method is to call GET /users/{user-id}/educationUser. If this returns a valid educationUser object, the user is either a student or teacher—you can check the primaryRole field in the response to tell them apart (values like student, teacher, or staff). If the call returns a 404, the user is an enterprise employee.
  • Tenant-Level Industry Check: Fetch the tenant's details with GET /organization and look at the industry property. If it's set to Education, you’re dealing with an educational institution tenant. Note: While rare, some orgs might have mixed user types, so always pair this with the user-specific check above.
  • UPN Suffix Hint: Many schools use .edu (or country-specific variants like .ac.uk) for user principal names, but this isn't 100% reliable—some enterprises might use similar suffixes. Treat this as a secondary clue, not a definitive identifier.
Differentiating School vs. Work Accounts in Microsoft AD OAuth 2.0

Absolutely—you can use identity token claims and Microsoft Graph queries to tell these apart:

  • Tenant ID + Tenant Details:
    • The tid claim in your OAuth 2.0 ID token gives you the tenant ID. Use this to call GET /organization and check the industry field:
      • Education = School/educational tenant
      • Values like Corporate, FinancialServices, etc. = Work/enterprise tenant
    • You can also glance at the tenant's displayName (often includes a school/university name), but again, use this as a supplement to the industry check.
  • Identity Token Claims:
    • Some educational tenants include custom extension claims in the ID token (e.g., extension_<unique-guid>_Education_StudentId or extension_<unique-guid>_Education_TeacherId) if they’re using Microsoft Education tools. To access these, ensure your app has permissions like User.ReadBasic.All and request the relevant claims in your auth scope.
    • The roles claim might include education-specific roles (e.g., Teacher, Student) if the tenant has assigned them, but this depends on the org's setup.
  • User-Specific Graph Check:
    • As mentioned earlier, calling GET /users/{user-id}/educationUser will confirm if the user is part of an educational system. A successful response means it's a school account; a 404 means it's a work account.
Quick Tips
  • Always prioritize Graph API checks over UPN suffixes or tenant names—those can lead to false positives.
  • Ensure your app has the necessary permissions (like User.Read, Education.ReadBasic.All) to fetch these properties.
  • If using the v2.0 auth endpoint, you can use the claims parameter in your auth request to pull education-specific data directly into the ID token, cutting down on extra API calls.

内容的提问来源于stack exchange,提问作者Yordana Dekova

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 03:51:58