Microsoft Authenticator 数据 API:MFA、通行密钥与无密码会话
Microsoft Authenticator 是微软面向工作、学校与个人账户的移动登录伴侣。它把手机变成抗钓鱼凭证——带数字匹配的推送批准、TOTP 动态码、通行密钥与无密码手机登录——使其成为运行在 Microsoft Entra ID 上的组织默认的第二重验证。
作为数据源,应用开放的是这些批准背后的身份对象:返回 OathSecret 与 PhoneAppDetailId 的设备注册、携带 firstEntropyNumber 匹配数字与 richContextDetails 登录上下文的待处理质询、按用户的策略标记(如 numberMatchingRequiredState),以及带有 fidoChallenge 值的无密码会话。安全团队基于这些字段构建设备清单、策略核查与会话监控集成。
Microsoft Authenticator 是微软为工作、学校及个人微软账户打造的登录伴侣:带数字匹配的推送批准、TOTP 动态码、通行密钥与无密码手机登录,是部署最广泛的企业 MFA 应用之一。这些批准背后是一套丰富的身份数据集——携带 oath 密钥与租户路由提示的设备注册、含匹配数字与登录上下文的待处理登录质询、按用户的 Authenticator 策略标记,以及通行密钥凭证。安全团队用它清点已注册手机、核查数字匹配策略、监控无密码会话并自动化通行密钥生命周期。
应用截图
API 端点一览
以下端点与请求/响应示例均依据应用界面推导重构,为示意说明,并非实际抓包。
签发 OAuth 2.0 访问令牌
POST
/v1/oauth/tokenosint将授权码或 refresh_token 兑换为 Bearer access_token,随后附加到策略、通行密钥、会话与设备注册调用。
认证方式: 公共客户端令牌请求。请求体携带 grant_type(authorization_code、refresh_token 或 srv_challenge)、client_id 与 scope。返回的 access_token 以 Authorization: Bearer 形式发送到策略、通行密钥与会话调用。
- grant_type
- client_id
- code
- redirect_uri
- scope
- token_type
- expires_in
- ext_expires_in
- access_token
- refresh_token
- id_token
POST /v1/oauth/token HTTP/1.1 Content-Type: application/x-www-form-urlencoded grant_type=authorization_code&client_id=11112222-3333-4444-5555-666677778888&code=0.AXEA...&redirect_uri=msauth://com.example.mfaapp/callback&scope=https://directory.example.net/.default offline_access{ "token_type": "Bearer", "scope": "https://directory.example.net/.default", "expires_in": 3599, "ext_expires_in": 3599, "access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example", "refresh_token": "0.AXEA.example", "id_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example" }依据应用的登录与令牌交换流程重构与策略、通行密钥及会话调用所附带的 Bearer 凭证一致
将 Authenticator 注册为 MFA 方法
POST
/v1/mfa/devices/registerosint将这台 Android 手机登记为 Microsoft Authenticator MFA 方法,返回账户名、TOTP oath 密钥、phoneAppDetailId 及后续调用使用的租户路由提示。
认证方式: Authorization: Bearer 工作或学校账户的访问令牌。同时发送应用与设备请求头(应用名称与版本、设备平台及一个操作头),以及推送注册令牌的哈希。
- AccountName
- GroupKey
- OathSecret
- PhoneAppDetailId
- MfaServerInUse
- IsDeviceTokenValidationSuccessful
- IsOathTokenEnabled
- ReplicationScope
- RoutingHint
- TenantCountryCode
- CurrentDefaultMethod
- UserCredentialPolicyProto
- DeviceName
- DeviceToken
- NotificationType
- AppPackageName
POST /v1/mfa/devices/register HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example Content-Type: application/xml X-App-Name: Authenticator X-App-Version: 6.2609.6214 X-Device-Platform: Android <RegisterDeviceRequest> <Version>1.0</Version> <AppPackageName>com.example.mfaapp</AppPackageName> <AuthenticatorFlavor>Authenticator</AuthenticatorFlavor> <DeviceName>Pixel 8</DeviceName> <DeviceTag>Android</DeviceTag> <DeviceToken>fcm-registration-token</DeviceToken> <NotificationType>FCM</NotificationType> <PhoneAppVersion>6.2609.6214</PhoneAppVersion> <RequestId>9c2e1a44-7b11-4d90-9e3a-2f0c8b1d4e55</RequestId> <UpdateDefaultMethod>true</UpdateDefaultMethod> <Uses>Notification Oath</Uses> </RegisterDeviceRequest>{ "AccountName": "[email protected]", "GroupKey": "g-7f2c91aa", "OathSecret": "JBSWY3DPEHPK3PXP", "PhoneAppDetailId": "pad-8e21c0", "MfaServerInUse": false, "IsDeviceTokenValidationSuccessful": true, "IsOathTokenEnabled": true, "ReplicationScope": "NAM", "RoutingHint": "contoso.example", "TenantCountryCode": "US", "CurrentDefaultMethod": "PhoneAppNotification", "UserCredentialPolicyProto": "CgNhcHA=" }依据应用的工作账户注册流程重构与添加设备时返回的 oath 密钥及租户路由提示一致
发现 MFA 服务端点
POST
/v1/mfa/endpoints/resolveopendata返回手机应用后续 MFA 轮询与批准调用应使用的区域 MFA 中继 URL 与 replicationScopes。
认证方式: 设备绑定的 MFA 请求头:XML 内容类型、应用名称与版本、设备平台、设备令牌头,以及选择端点发现请求的操作头。
- version
- defaultUrl
- url
- endpoints
- replicationScopes
POST /v1/mfa/endpoints/resolve HTTP/1.1 Content-Type: application/xml X-MFA-Action: getEndpoints X-App-Name: Authenticator X-Device-Platform: Android <mfaMessage version="1.6"> <request request-id="b41c0e22-11aa-4c01-9f10-88c0aa11bb22" async="0" language="en"> <getEndpointsRequest/> </request> </mfaMessage>{ "version": "1.6", "defaultUrl": "https://mfa.example.net/v1/mfa/relay", "url": "https://mfa.example.net/v1/mfa/relay", "endpoints": { "NAM": "https://mfa-nam.example.net/v1/mfa/relay", "EUR": "https://mfa-eur.example.net/v1/mfa/relay" }, "replicationScopes": "NAM,EUR" }依据应用的区域端点发现步骤重构与手机后续轮询及批准调用使用的复制范围一致
轮询待处理的 MFA 通知
POST
/v1/mfa/challenges/pollosint向 MFA 服务查询是否有登录正在等待此设备,并返回待处理质询的 username、groupKey、oathCounter 与 phoneAppDetailId。
认证方式: 设备绑定的 MFA 请求头,外加来自已注册账户的可选租户路由头(租户 id、复制范围、路由提示与租户国家/地区)。操作头选择待处理质询检查。
- result
- groupKey
- username
- oathCounter
- padUrl
- phoneAppDetailId
- dosPreventer
- deviceToken
- previousDeviceToken
- AuthenticatorFlavor
POST /v1/mfa/challenges/poll HTTP/1.1 Content-Type: application/xml X-MFA-Action: checkPendingChallenge X-MFA-Interactive: true X-Tenant-Id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-Routing-Hint: contoso.example <checkPendingChallengeRequest> <dosPreventer>dp-9f31</dosPreventer> <deviceToken notificationType="fcm">fcm-registration-token</deviceToken> <previousDeviceToken>fcm-registration-token-old</previousDeviceToken> <version>6.2609.6214</version> <osVersion>14</osVersion> <AuthenticatorFlavor>Authenticator</AuthenticatorFlavor> </checkPendingChallengeRequest>{ "result": "NotificationWaiting", "groupKey": "g-7f2c91aa", "username": "[email protected]", "oathCounter": 48211, "padUrl": "https://mfa.example.net/v1/mfa/relay", "phoneAppDetailId": "pad-8e21c0" }依据应用的待处理登录检查重构与有质询等待时出现的批准通知一致
获取 MFA 质询上下文
POST
/v1/mfa/challenges/contextosint加载批准界面上展示的待处理 MFA 质询:数字匹配的熵值数字、登录上下文、用户 objectId、租户、欺诈标记以及是否需要应用锁。
认证方式: 设备绑定的 MFA 请求头;操作头选择质询上下文请求。存在时附带来自已注册账户的租户路由头。
- responseGuid
- mode
- fraudBlock
- fraudAllowed
- groupKey
- phoneAppDetailId
- username
- tenantId
- objectId
- accountName
- firstEntropyNumber
- secondEntropyNumber
- thirdEntropyNumber
- sasSessionId
- richContextDetails
- returnLocationData
- isAppLockRequired
- pinChangeRequired
- oathTokenEnabled
- oathCounter
- replicationScope
- routingHint
- tenantCountryCode
- userCredentialPolicyProto
POST /v1/mfa/challenges/context HTTP/1.1 Content-Type: application/xml X-MFA-Action: getChallengeContext X-Tenant-Id: 72f988bf-86f1-41af-91ab-2d7cd011db47 <challengeContextRequest> <challengeContext> <guid>3fa85f64-5717-4562-b3fc-2c963f66afa6</guid> <oathCode>483921</oathCode> <needDosPreventer>yes</needDosPreventer> <deviceToken>fcm-registration-token</deviceToken> <version>6.2609.6214</version> <osVersion>14</osVersion> </challengeContext> </challengeContextRequest>{ "responseGuid": "3fa85f64-5717-4562-b3fc-2c963f66afa6", "mode": "Push", "fraudBlock": false, "fraudAllowed": true, "groupKey": "g-7f2c91aa", "phoneAppDetailId": "pad-8e21c0", "username": "[email protected]", "tenantId": "72f988bf-86f1-41af-91ab-2d7cd011db47", "objectId": "84b12a9c-0e33-4d1a-9f44-11aa22bb33cc", "accountName": "[email protected]", "firstEntropyNumber": "14", "secondEntropyNumber": "67", "thirdEntropyNumber": "32", "sasSessionId": "sas-9c01", "richContextDetails": "Sign-in from Chrome on Windows", "returnLocationData": true, "isAppLockRequired": true, "oathTokenEnabled": true, "oathCounter": 48212, "replicationScope": "NAM", "routingHint": "contoso.example", "tenantCountryCode": "US", "userCredentialPolicyProto": "CgNhcHA=" }依据应用的数字匹配批准界面重构与向用户展示的匹配数字及登录上下文一致
提交 MFA 批准或拒绝
POST
/v1/mfa/challenges/resultosint提交用户对待处理 MFA 质询的批准或拒绝决定,包括是否使用了应用锁以及当前 OATH 计数器。
认证方式: 设备绑定的 MFA 请求头;操作头选择质询结果提交。当质询要求时可能附带 locationData。
- guid
- authenticationResult
- oldDeviceToken
- newDeviceToken
- oathTokenCounter
- isAppLockUsed
- completedInteractively
- locationData
- result
POST /v1/mfa/challenges/result HTTP/1.1 Content-Type: application/xml X-MFA-Action: submitChallengeResult <challengeResultRequest> <challengeContext> <guid>3fa85f64-5717-4562-b3fc-2c963f66afa6</guid> <needDosPreventer>no</needDosPreventer> <deviceToken>fcm-registration-token</deviceToken> <version>6.2609.6214</version> <osVersion>14</osVersion> </challengeContext> <authenticationResult>0</authenticationResult> <oathTokenCounter>48212</oathTokenCounter> <isAppLockUsed>true</isAppLockUsed> <completedInteractively>true</completedInteractively> </challengeResultRequest>{ "result": "Success", "guid": "3fa85f64-5717-4562-b3fc-2c963f66afa6" }依据应用的批准与拒绝操作重构与用户响应质询后提交的决定一致
批准时校验 MFA PIN
POST
/v1/mfa/challenges/pinosint当 MFA 质询要求在批准前校验 PIN 时,提交用户的应用 PIN(以及可选的数字匹配 digit)。
认证方式: 设备绑定的 MFA 请求头;操作头选择 PIN 校验。请求体携带 pin(可选 stored=yes)、selectedEntropyNumber 与 isAppLockUsed。
- guid
- pin
- stored
- authenticate
- oathCounter
- completedInteractively
- selectedEntropyNumber
- isAppLockUsed
- pinRetries
- pinChangeRequired
- result
POST /v1/mfa/challenges/pin HTTP/1.1 Content-Type: application/xml X-MFA-Action: validatePin <pinValidationRequest> <challengeContext> <guid>3fa85f64-5717-4562-b3fc-2c963f66afa6</guid> <needDosPreventer>no</needDosPreventer> <deviceToken>fcm-registration-token</deviceToken> <version>6.2609.6214</version> <osVersion>14</osVersion> </challengeContext> <pin stored="no">4821</pin> <authenticate>yes</authenticate> <oathCounter>48212</oathCounter> <completedInteractively>yes</completedInteractively> <selectedEntropyNumber>14</selectedEntropyNumber> <isAppLockUsed>yes</isAppLockUsed> </pinValidationRequest>{ "result": "Success", "guid": "3fa85f64-5717-4562-b3fc-2c963f66afa6", "pinRetries": 3, "pinChangeRequired": false }依据应用的批准时 PIN 校验步骤重构与 PIN 错误后返回的重试计数器一致
轮换推送设备令牌
POST
/v1/devices/push-tokenopendata通知推送服务替换旧的推送注册令牌,使移动平台刷新令牌后推送 MFA 仍能正常工作。
认证方式: 设备绑定的 MFA 请求头;操作头选择令牌更换请求,该调用标记为非交互式。
- dosPreventer
- oldDeviceToken
- newDeviceToken
- notificationType
- replicationScopes
- version
- osVersion
- result
POST /v1/devices/push-token HTTP/1.1 Content-Type: application/xml X-MFA-Action: changeDeviceToken X-MFA-Interactive: false <deviceTokenChangeRequest> <dosPreventer>dp-9f31</dosPreventer> <oldDeviceToken>fcm-registration-token-old</oldDeviceToken> <newDeviceToken notificationType="fcm">fcm-registration-token-new</newDeviceToken> <version>6.2609.6214</version> <osVersion>14</osVersion> <replicationScopes>NAM</replicationScopes> </deviceTokenChangeRequest>{ "result": "Success", "newDeviceToken": "fcm-registration-token-new" }依据应用的推送注册刷新处理重构与平台令牌轮换后的重新注册一致
读取 Authenticator 方法策略
GET
/v1/accounts/{id}/mfa-policyopendata读取用户的 Microsoft Authenticator 策略,包括驱动应用内 MFA 体验的数字匹配、位置显示、软件 TOTP 与配套应用标记。
认证方式: Authorization: Bearer 为已登录工作账户获取的目录访问令牌。
- authenticationMethod
- isEnabled
- isRequired
- settings
- authenticationMode
- companionAppAllowedState
- numberMatchingRequiredState
- displayAppInformationRequiredState
- displayLocationInformationRequiredState
- isSoftwareTotpEnabled
- isAttestationEnforced
- isEnforceApprovalPinEnabled
- isSelfServiceRegistrationAllowed
- passkeyProfiles
GET /v1/accounts/84b12a9c-0e33-4d1a-9f44-11aa22bb33cc/mfa-policy HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example{ "value": [ { "authenticationMethod": "microsoftAuthenticator", "isEnabled": true, "isRequired": true, "settings": { "authenticationMode": "any", "companionAppAllowedState": "enabled", "numberMatchingRequiredState": "enabled", "displayAppInformationRequiredState": "enabled", "displayLocationInformationRequiredState": "enabled", "isSoftwareTotpEnabled": true, "isAttestationEnforced": false, "isEnforceApprovalPinEnabled": false, "isSelfServiceRegistrationAllowed": true, "passkeyProfiles": [] } } ] }依据应用由策略驱动的 MFA 行为重构与批准界面背后的数字匹配及位置标记一致
读取租户安全默认设置策略
GET
/v1/tenants/security-defaultsopendata读取租户是否启用了身份安全默认设置,这会改变应用呈现 MFA 注册与批准流程的方式。
认证方式: Authorization: Bearer 目录访问令牌。
- id
- displayName
- description
- isEnabled
GET /v1/tenants/security-defaults HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example{ "id": "00000000-0000-0000-0000-000000000005", "displayName": "Security Defaults", "description": "Security defaults provides preconfigured security settings.", "isEnabled": true }依据应用的租户策略检查重构与启用安全默认设置时展示的注册流程一致
获取 FIDO2 通行密钥创建选项
GET
/v1/accounts/{id}/passkeys/creation-optionsosint获取 WebAuthn 凭证创建选项,使应用能为已登录的 Entra 用户生成平台通行密钥。
认证方式: Authorization: Bearer 目录访问令牌。
- publicKey
- rp
- user
- challenge
- pubKeyCredParams
- timeout
- authenticatorSelection
- authenticatorAttachment
- userVerification
- requireResidentKey
- attestation
- hmacCreateSecret
- credentialProtectionPolicy
GET /v1/accounts/84b12a9c-0e33-4d1a-9f44-11aa22bb33cc/passkeys/creation-options?challengeTimeoutInMinutes=5 HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example{ "publicKey": { "rp": {"id": "passkeys.example.net", "name": "Example IDP"}, "user": {"id": "84b12a9c-0e33-4d1a-9f44-11aa22bb33cc", "name": "[email protected]", "displayName": "Alex Contoso"}, "challenge": "dGhpc2lzYWNoYWxsZW5nZQ", "pubKeyCredParams": [{"type": "public-key", "alg": -7}], "timeout": 300000, "authenticatorSelection": {"authenticatorAttachment": "platform", "userVerification": "required", "requireResidentKey": true}, "attestation": "direct", "extensions": {"hmacCreateSecret": true, "credentialProtectionPolicy": "userVerificationRequired"} } }依据应用的通行密钥设置流程重构与交给平台认证器的 WebAuthn 选项一致
注册 FIDO2 通行密钥
POST
/v1/accounts/{id}/passkeysosint上传平台认证器的证明(attestation),让 Entra ID 在用户名下存储新的 FIDO2 方法。
认证方式: Authorization: Bearer 目录访问令牌。
- displayName
- publicKeyCredential
- id
- rawId
- type
- attestationObject
- clientDataJSON
- createdDateTime
- aaGuid
- model
- attestationLevel
- passkeyType
- attestationCertificates
POST /v1/accounts/84b12a9c-0e33-4d1a-9f44-11aa22bb33cc/passkeys HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example Content-Type: application/json { "displayName": "Pixel 8", "publicKeyCredential": { "id": "cred-aa11", "rawId": "Y3JlZC1hYTEx", "type": "public-key", "response": { "attestationObject": "o2NmbXRkbm9uZWdhdHRTdG10", "clientDataJSON": "eyJ0eXBlIjoid2ViYXV0aG4uY3JlYXRlIn0" } } }{ "id": "fido-method-01", "displayName": "Pixel 8", "createdDateTime": "2026-09-29T12:04:11Z", "aaGuid": "ea9b8d66-4d01-1d21-3ce4-b6b48cb575d4", "model": "Pixel 8", "attestationLevel": "attested", "passkeyType": "deviceBound", "attestationCertificates": [] }依据应用的通行密钥注册步骤重构与设备密钥库生成的证明对象一致
删除 Authenticator MFA 方法
DELETE
/v1/accounts/{id}/mfa-methods/{methodId}osint当账户被删除或设备在应用内注销时,从用户名下移除已注册的 Microsoft Authenticator 方法。
认证方式: Authorization: Bearer 目录访问令牌。
- id
- methodId
- status
DELETE /v1/accounts/84b12a9c-0e33-4d1a-9f44-11aa22bb33cc/mfa-methods/pad-8e21c0 HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example{ "status": 204 }依据应用的账户移除流程重构与设备注销后的方法清理一致
删除 FIDO2 通行密钥方法
DELETE
/v1/accounts/{id}/passkeys/{methodId}osint当通行密钥在应用内被删除时,从用户名下移除已注册的 FIDO2 / 通行密钥方法。
认证方式: Authorization: Bearer 目录访问令牌。
- id
- methodId
- status
DELETE /v1/accounts/84b12a9c-0e33-4d1a-9f44-11aa22bb33cc/passkeys/fido-method-01 HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example{ "status": 204 }依据应用的通行密钥管理界面重构与移除通行密钥时发出的删除请求一致
读取组织数据边界
GET
/v1/tenants/currentopendata读取已登录租户的组织记录,使应用在上传诊断日志时遵守区域数据边界(dataBoundary)。
认证方式: Authorization: Bearer 为已登录工作账户获取的目录访问令牌。
- id
- displayName
- countryLetterCode
- dataBoundary
GET /v1/tenants/current HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example{ "value": [ { "id": "72f988bf-86f1-41af-91ab-2d7cd011db47", "displayName": "Contoso", "countryLetterCode": "US", "dataBoundary": "Global" } ] }依据应用的诊断上传设置重构与按区域路由日志的数据边界值一致
列出无密码登录会话
GET
/v1/signin/sessionsosint列出账户待处理的无密码手机登录会话,包括数字匹配 digit、FIDO 质询以及发起请求的客户端详情。
认证方式: Authorization: Bearer 访问令牌。同时发送客户端关联头:请求 id 以及客户端 SKU 与客户端名称。
- sessionsList
- username
- userObjectIdHash
- code
- sessionId
- sessionType
- requestTime
- expirationTime
- audience
- entropy1
- entropy2
- entropy3
- authDetails
- tenantId
- userCredentialPolicy
- phoneAppDetails
- fidoChallenge
GET /v1/signin/sessions HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example client-request-id: 5e2a1c90-44bb-4d11-a0e1-77aa11bb22cc X-Client-SKU: authenticator.android X-Client-Name: AuthenticatorAndroid{ "sessionsList": [ { "session": { "username": "[email protected]", "userObjectIdHash": "a11c0e22", "code": "14", "sessionId": "sess-01", "sessionType": "Passwordless", "requestTime": 1759142400, "expirationTime": 1759142700, "audience": "https://idp.example.net", "entropy1": 14, "entropy2": 67, "entropy3": 32, "authDetails": "Chrome on Windows", "tenantId": "72f988bf-86f1-41af-91ab-2d7cd011db47", "userCredentialPolicy": "CgNhcHA=", "phoneAppDetails": "pad-8e21c0", "fidoChallenge": "dGhpc2lzYWNoYWxsZW5nZQ" } } ] }依据应用的无密码登录列表重构与连同匹配码一起展示的待处理会话一致
批准无密码登录会话
POST
/v1/signin/sessions/approveosint在用户确认数字匹配或提供 FIDO 断言后,批准或拒绝待处理的无密码手机登录会话。
认证方式: Authorization: Bearer 访问令牌。表单请求体携带密钥断言或 FIDO 断言(fidoassertion),以及 sessionid、sessionstate、sessiontype 与 userobjectid。
- sessionid
- sessionstate
- sessiontype
- userobjectid
- assertion
- fidoassertion
- entropy
- oathcounter
- app_state
- deviceid
- success
POST /v1/signin/sessions/approve HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example Content-Type: application/x-www-form-urlencoded client-request-id: 5e2a1c90-44bb-4d11-a0e1-77aa11bb22cc sessionid=sess-01&sessionstate=approve&sessiontype=Passwordless&userobjectid=84b12a9c-0e33-4d1a-9f44-11aa22bb33cc&assertion=eyJhbGciOiJFUzI1NiJ9.example&entropy=14&oathcounter=48212{ "success": true }依据应用的数字匹配确认重构与为完成手机登录而提交的签名断言一致
注册设备登录密钥
POST
/v1/devices/keysosint向设备注册服务注册设备的公共登录密钥,使手机之后能够批准无密码会话。
认证方式: Authorization: Bearer 限定设备注册作用域的令牌。发送 api-version 查询参数以及客户端名称与 SKU 头。
- publicKeyCredential
- credentialDisplayName
- attributes
- supports_notification
- message
- time
- requestId
- serverKeyId
POST /v1/devices/keys?api-version=1.1 HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example Content-Type: application/json X-Client-Name: AuthenticatorAndroid X-Client-SKU: authenticator.android { "publicKeyCredential": { "id": "cred-aa11", "rawId": "Y3JlZC1hYTEx", "type": "public-key", "response": { "attestationObject": "o2NmbXRkbm9uZWdhdHRTdG10", "clientDataJSON": "eyJ0eXBlIjoid2ViYXV0aG4uY3JlYXRlIn0" } }, "credentialDisplayName": "Pixel 8", "attributes": { "supports_notification": "true" } }{ "message": "Key registered", "time": "2026-09-29T12:05:01Z", "requestId": "drs-req-01", "serverKeyId": "key-8e21c0" }依据应用的无密码设置流程重构与设备密钥注册期间上传的公钥及证明一致
删除设备登录密钥
DELETE
/v1/devices/keys/{keyId}osint当工作账户被删除或关闭无密码手机登录时,从注册服务中移除设备登录密钥。
认证方式: Authorization: Bearer 设备注册令牌。应用从发现元数据解析删除路由,并附加 api-version 查询参数。
- keyId
- upn
- krctx
DELETE /v1/devices/keys/key-8e21c0?api-version=1.0 HTTP/1.1 Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example X-Client-Name: AuthenticatorAndroid X-Client-SKU: authenticator.android{ "keyId": "key-8e21c0", "upn": "[email protected]", "krctx": "ctx-01" }依据应用的工作账户移除流程重构与停用无密码登录时发出的密钥清理一致
数据类别
- MFA 注册
- 推送批准
- TOTP 密钥
- 通行密钥
- 无密码会话
- 设备令牌
- 认证方法策略
- 组织数据边界
数据使用场景与案例
企业 MFA 设备清单
读取每次设备注册返回的 AccountName、PhoneAppDetailId、DeviceName 与 TenantCountryCode,再结合 DeviceToken 轮换事件,核对哪些手机已登记为 Microsoft Authenticator 方法。
数字匹配与位置策略核查
从按用户的 Authenticator 策略中拉取 numberMatchingRequiredState、displayLocationInformationRequiredState 与 isSoftwareTotpEnabled,并与实时 MFA 质询上的 firstEntropyNumber 和 returnLocationData 比对。
无密码会话监控
监视待处理会话列表中的无密码登录(username、sessionType、authDetails、fidoChallenge),并在用户确认匹配码后以签名断言完成登录。
Entra ID 上的通行密钥生命周期
读取通行密钥创建选项,根据其证明为用户存储平台通行密钥,并在设备退役时移除 Authenticator 或通行密钥方法。
常见问题
Microsoft Authenticator 如何注册工作或学校账户?
应用向 /v1/mfa/devices/register 提交设备注册:携带 Bearer 令牌、应用与设备请求头,以及包含 DeviceName、DeviceToken 与 NotificationType 的 XML 请求体。响应返回 AccountName、GroupKey、OathSecret 与 PhoneAppDetailId,以及后续调用使用的租户路由提示。
推送 MFA 批准如何请求与提交?
手机轮询 /v1/mfa/challenges/poll 查询是否有等待中的登录,从 /v1/mfa/challenges/context 加载质询(firstEntropyNumber 数字、sasSessionId、richContextDetails),然后向 /v1/mfa/challenges/result 提交决定,携带 authenticationResult、isAppLockUsed 与 oathTokenCounter。当策略要求时,先由 /v1/mfa/challenges/pin 校验应用 PIN。
Authenticator 策略数据包含哪些内容?
GET /v1/accounts/{id}/mfa-policy 返回按用户的 Authenticator 设置:authenticationMode、numberMatchingRequiredState、displayLocationInformationRequiredState、isSoftwareTotpEnabled 与 companionAppAllowedState。另一个租户调用 /v1/tenants/security-defaults 报告是否启用了身份安全默认设置。
应用中的通行密钥与无密码登录如何工作?
待处理的无密码会话在 /v1/signin/sessions 列出(sessionId、熵值数字、fidoChallenge),并在 /v1/signin/sessions/approve 以签名断言完成。通行密钥设置从 /v1/accounts/{id}/passkeys/creation-options 读取选项,并以 POST /v1/accounts/{id}/passkeys 存储凭证;对同一资源的 DELETE 将其退役。
与 Microsoft Authenticator 相似的应用
- Google Authenticator — Google 出品的免费验证器应用,为 Google 及第三方账户生成基于时间(TOTP)和计数器(HOTP)的一次性验证码,可选择同步到 Google 账户。
- Twilio Authy — Twilio 的双重验证应用,提供加密云备份与多设备同步,更换手机后验证码仍可保留。
- Duo Mobile — 思科的企业级 MFA 应用,处理推送批准,并可与 Duo 的基于风险的认证、单点登录和设备可见性平台配合使用。
- Okta Verify — Okta 的企业身份应用,为 Okta 管理的账户发送推送批准,被列为 Microsoft Authenticator 的直接竞品之一。
- Aegis Authenticator — 一款免费开源的 Android 验证器,将令牌存放在加密的本地保险库中,不收集用户数据。
- 2FAS Auth — 一款开源验证器,无需注册账户即可离线使用,并提供可选的浏览器扩展以加快登录。
- Ente Auth — Ente 推出的开源验证器,提供端到端加密备份,可在手机与桌面端之间同步验证码。
相关主题
- Microsoft Authenticator API
- MFA 推送批准 API
- Authenticator 设备注册
- 数字匹配 MFA
- 无密码手机登录
- FIDO2 通行密钥注册 API
- OathSecret PhoneAppDetailId
- Authenticator 策略 API
需要集成这个 App 的数据 API?
我们可为任意指定 App 交付定制集成——源码交付 USD 500 起,或托管 API 按调用计费。告诉我们您需要的数据即可。
- 每个项目均签 NDA 与 SOW
- 3–7 天交付
- 验收通过后才付款
- 仅在授权范围内作业