获取 authenticationMethodsPolicy

命名空间:microsoft.graph

读取 authenticationMethodsPolicy 对象的属性和关系。

此 API 可用于以下国家级云部署

全局服务 美国政府 L4 美国政府 L5 (DOD) 由世纪互联运营的中国

权限

为此 API 选择标记为最低特权的权限。 只有在应用需要它时,才使用更高的特权权限。 有关委派权限和应用程序权限的详细信息,请参阅权限类型。 要了解有关这些权限的详细信息,请参阅 权限参考

权限类型 最低特权权限 更高特权权限
委派(工作或学校帐户) Policy.Read.All Policy.ReadWrite.AuthenticationMethod
委派(个人 Microsoft 帐户) 不支持。 不支持。
应用程序 Policy.Read.All Policy.ReadWrite.AuthenticationMethod

重要

在具有工作或学校帐户的委托方案中,必须为登录用户分配受支持的Microsoft Entra角色或具有支持的角色权限的自定义角色。 此操作支持以下最低特权角色。

  • 全局读取者
  • 身份验证策略管理员

HTTP 请求

GET /policies/authenticationMethodsPolicy

可选的查询参数

此方法不支持任何可选的查询参数。

请求标头

名称 说明
Authorization 持有者 {token}。 必填。 详细了解 身份验证和授权

请求正文

请勿提供此方法的请求正文。

响应

如果成功,此方法在 200 OK 响应正文中返回响应代码和 authenticationMethodsPolicy 对象。

示例

请求

GET https://graph.microsoft.com/v1.0/policies/authenticationMethodsPolicy

响应

注意:为了提高可读性,可能缩短了此处显示的响应对象。

HTTP/1.1 200 OK
Content-Type: application/json

{
    "@odata.context": "https://graph.microsoft.com/beta/$metadata#authenticationMethodsPolicy",
    "@microsoft.graph.tips": "Use $select to choose only the properties your app needs, as this can lead to performance improvements. For example: GET policies/authenticationMethodsPolicy?$select=description,displayName",
    "id": "authenticationMethodsPolicy",
    "displayName": "Authentication Methods Policy",
    "description": "The tenant-wide policy that controls which authentication methods are allowed in the tenant, authentication method registration requirements, and self-service password reset settings",
    "lastModifiedDateTime": "2024-04-26T12:44:42.0858664Z",
    "policyVersion": "1.5",
    "policyMigrationState": "preMigration",
    "registrationEnforcement": {
        "authenticationMethodsRegistrationCampaign": {
            "snoozeDurationInDays": 1,
            "enforceRegistrationAfterAllowedSnoozes": true,
            "state": "disabled",
            "excludeTargets": [],
            "includeTargets": [
                {
                    "id": "all_users",
                    "targetType": "group",
                    "targetedAuthenticationMethod": "microsoftAuthenticator"
                }
            ]
        }
    },
    "systemCredentialPreferences": {
        "state": "disabled",
        "excludeTargets": [],
        "includeTargets": [
            {
                "id": "all_users",
                "targetType": "group"
            }
        ]
    },
    "reportSuspiciousActivitySettings": {
        "state": "disabled",
        "voiceReportingCode": 0,
        "includeTarget": {
            "id": "all_users",
            "targetType": "group"
        }
    },
    "authenticationMethodConfigurations@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations",
    "authenticationMethodConfigurations": [
        {
            "@odata.type": "#microsoft.graph.fido2AuthenticationMethodConfiguration",
            "id": "Fido2",
            "state": "enabled",
            "isSelfServiceRegistrationAllowed": true,
            "isAttestationEnforced": true,
            "defaultPasskeyProfile": null,
            "excludeTargets": [
                {
                    "id": "dad4ae4a-730c-4e52-826c-0d9094971f04",
                    "targetType": "group"
                }
            ],
            "keyRestrictions": {
                "isEnforced": false,
                "enforcementType": "block",
                "aaGuids": []
            },
            "includeTargets@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations('Fido2')/microsoft.graph.fido2AuthenticationMethodConfiguration/includeTargets",
            "includeTargets": [
                {
                    "targetType": "group",
                    "id": "all_users",
                    "isRegistrationRequired": false,
                    "allowedPasskeyProfiles": []
                }
            ],
            "passkeyProfiles": []
        },
        {
            "@odata.type": "#microsoft.graph.microsoftAuthenticatorAuthenticationMethodConfiguration",
            "id": "MicrosoftAuthenticator",
            "state": "enabled",
            "isSoftwareOathEnabled": false,
            "excludeTargets": [
                {
                    "id": "dad4ae4a-730c-4e52-826c-0d9094971f04",
                    "targetType": "group"
                }
            ],
            "featureSettings": {
                "companionAppAllowedState": {
                    "state": "default",
                    "includeTarget": {
                        "targetType": "group",
                        "id": "all_users"
                    },
                    "excludeTarget": {
                        "targetType": "group",
                        "id": "00000000-0000-0000-0000-000000000000"
                    }
                },
                "numberMatchingRequiredState": {
                    "state": "enabled",
                    "includeTarget": {
                        "targetType": "group",
                        "id": "all_users"
                    },
                    "excludeTarget": {
                        "targetType": "group",
                        "id": "00000000-0000-0000-0000-000000000000"
                    }
                },
                "displayAppInformationRequiredState": {
                    "state": "default",
                    "includeTarget": {
                        "targetType": "group",
                        "id": "all_users"
                    },
                    "excludeTarget": {
                        "targetType": "group",
                        "id": "00000000-0000-0000-0000-000000000000"
                    }
                },
                "displayLocationInformationRequiredState": {
                    "state": "default",
                    "includeTarget": {
                        "targetType": "group",
                        "id": "all_users"
                    },
                    "excludeTarget": {
                        "targetType": "group",
                        "id": "00000000-0000-0000-0000-000000000000"
                    }
                }
            },
            "includeTargets@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations('MicrosoftAuthenticator')/microsoft.graph.microsoftAuthenticatorAuthenticationMethodConfiguration/includeTargets",
            "includeTargets": [
                {
                    "targetType": "group",
                    "id": "all_users",
                    "isRegistrationRequired": false,
                    "authenticationMode": "any"
                }
            ]
        },
        {
            "@odata.type": "#microsoft.graph.smsAuthenticationMethodConfiguration",
            "id": "Sms",
            "state": "disabled",
            "excludeTargets": [],
            "includeTargets@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations('Sms')/microsoft.graph.smsAuthenticationMethodConfiguration/includeTargets",
            "includeTargets": [
                {
                    "targetType": "group",
                    "id": "all_users",
                    "isRegistrationRequired": false,
                    "isUsableForSignIn": false
                }
            ]
        },
        {
            "@odata.type": "#microsoft.graph.temporaryAccessPassAuthenticationMethodConfiguration",
            "id": "TemporaryAccessPass",
            "state": "enabled",
            "defaultLifetimeInMinutes": 60,
            "defaultLength": 8,
            "minimumLifetimeInMinutes": 60,
            "maximumLifetimeInMinutes": 480,
            "isUsableOnce": false,
            "excludeTargets": [
                {
                    "id": "dad4ae4a-730c-4e52-826c-0d9094971f04",
                    "targetType": "group"
                }
            ],
            "includeTargets@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations('TemporaryAccessPass')/microsoft.graph.temporaryAccessPassAuthenticationMethodConfiguration/includeTargets",
            "includeTargets": [
                {
                    "targetType": "group",
                    "id": "all_users",
                    "isRegistrationRequired": false
                }
            ]
        },
        {
            "@odata.type": "#microsoft.graph.hardwareOathAuthenticationMethodConfiguration",
            "id": "HardwareOath",
            "state": "enabled",
            "excludeTargets": [],
            "includeTargets@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations('HardwareOath')/microsoft.graph.hardwareOathAuthenticationMethodConfiguration/includeTargets",
            "includeTargets": [
                {
                    "targetType": "group",
                    "id": "all_users",
                    "isRegistrationRequired": false
                }
            ]
        },
        {
            "@odata.type": "#microsoft.graph.softwareOathAuthenticationMethodConfiguration",
            "id": "SoftwareOath",
            "state": "enabled",
            "excludeTargets": [],
            "includeTargets@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations('SoftwareOath')/microsoft.graph.softwareOathAuthenticationMethodConfiguration/includeTargets",
            "includeTargets": [
                {
                    "targetType": "group",
                    "id": "dad4ae4a-730c-4e52-826c-0d9094971f04",
                    "isRegistrationRequired": false
                }
            ]
        },
        {
            "@odata.type": "#microsoft.graph.voiceAuthenticationMethodConfiguration",
            "id": "Voice",
            "state": "disabled",
            "isOfficePhoneAllowed": false,
            "callerIdNumber": null,
            "isCustomGreetingEnabled": false,
            "excludeTargets": [],
            "includeTargets@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations('Voice')/microsoft.graph.voiceAuthenticationMethodConfiguration/includeTargets",
            "includeTargets": [
                {
                    "targetType": "group",
                    "id": "all_users",
                    "isRegistrationRequired": false
                }
            ]
        },
        {
            "@odata.type": "#microsoft.graph.emailAuthenticationMethodConfiguration",
            "id": "Email",
            "state": "disabled",
            "allowExternalIdToUseEmailOtp": "default",
            "excludeTargets": [],
            "includeTargets@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations('Email')/microsoft.graph.emailAuthenticationMethodConfiguration/includeTargets",
            "includeTargets": [
                {
                    "targetType": "group",
                    "id": "d2d5bae7-a7b7-4581-8d52-5a8d26f517b3",
                    "isRegistrationRequired": false
                }
            ]
        },
        {
            "@odata.type": "#microsoft.graph.x509CertificateAuthenticationMethodConfiguration",
            "id": "X509Certificate",
            "state": "enabled",
            "excludeTargets": [],
            "certificateUserBindings": [
                {
                    "x509CertificateField": "PrincipalName",
                    "userProperty": "userPrincipalName",
                    "priority": 1,
                    "trustAffinityLevel": "low"
                },
                {
                    "x509CertificateField": "RFC822Name",
                    "userProperty": "userPrincipalName",
                    "priority": 2,
                    "trustAffinityLevel": "low"
                }
            ],
            "authenticationModeConfiguration": {
                "x509CertificateAuthenticationDefaultMode": "x509CertificateSingleFactor",
                "x509CertificateDefaultRequiredAffinityLevel": "low",
                "rules": []
            },
            "issuerHintsConfiguration": {
                "state": "disabled"
            },
            "crlValidationConfiguration": {
                "state": "disabled",
                "exemptedCertificateAuthoritiesSubjectKeyIdentifiers": []
            },
            "includeTargets@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations('X509Certificate')/microsoft.graph.x509CertificateAuthenticationMethodConfiguration/includeTargets",
            "includeTargets": [
                {
                    "targetType": "group",
                    "id": "eb2aa918-770c-40b4-97b8-f58a0087f8b5",
                    "isRegistrationRequired": false
                },
                {
                    "targetType": "group",
                    "id": "d97d81ce-74be-46a4-ba6e-62eed46fabb9",
                    "isRegistrationRequired": false
                }
            ]
        },
        {
            "@odata.type": "#microsoft.graph.externalAuthenticationMethodConfiguration",
            "id": "fda55161-0d73-48ec-b29f-d29689e3d1b6",
            "state": "enabled",
            "displayName": "Adatum - Broken",
            "appId": "73f7c26a-7a24-4408-adfa-ff1ff19b5c10",
            "excludeTargets": [
                {
                    "id": "18c6ce0e-243f-4130-ad7d-d9049806df0e",
                    "targetType": "group"
                }
            ],
            "openIdConnectSetting": {
                "clientId": "966c7a17-8cb9-47a6-8504-c1e50b05f21d",
                "discoveryUrl": "https://Adatum.com/.well-known/openid-configurationx"
            },
            "includeTargets@odata.context": "https://graph.microsoft.com/beta/$metadata#policies/authenticationMethodsPolicy/authenticationMethodConfigurations('fda55161-0d73-48ec-b29f-d29689e3d1b6')/microsoft.graph.externalAuthenticationMethodConfiguration/includeTargets",
            "includeTargets": [
                {
                    "targetType": "group",
                    "id": "all_users",
                    "isRegistrationRequired": false
                }
            ]
        }
    ]
}