我已经通过电子邮件发送邀请函在此链接https://learn.microsoft.com/en-us/azure/active-directory/external-identities/b2b-quickstart-add-guest-users-门户。
一旦接受邀请,访客用户就会将其添加到我的房客中。
现在,我已将一些应用程序分配给了他们可以访问的用户。
为了增强安全性,我想在访问应用程序访问应用程序时为访客用户启用两因素身份验证。
是否可以为客人用户启用MFA?如果是,任何人都可以指导我采取步骤
I have created guest users in my Azure AD tenant by sending invitations via email following this link https://learn.microsoft.com/en-us/azure/active-directory/external-identities/b2b-quickstart-add-guest-users-portal.
The guest users are added to my tenant once they accept the invitation.
Now I have assigned some applications to the guest users that they can access.
To enhance the security, I want to enable two-factor authentication for the guest users when they are accessing the application.
Is it possible to enable MFA for the guest users? If yes, can anyone guide me with the steps
发布评论
评论(1)
是的,可以为客人用户启用MFA。
要达到您的要求,请按照以下步骤:
Azure AD Premium P1
或p2许可
创建条件访问策略所必需的。转到Azure Portal - > Azure Active Directory->安全 - >有条件访问 - >政策 - >新策略。
在授予选项卡中,选择“授予访问” 和Check Mark “必需的多因素身份验证“。通过在上选择和创建来启用策略。
我在环境中尝试了它提示了两个因素身份验证如下:
Yes, it is possible to enable MFA for guest users.
To achieve your requirement, please follow the below steps:
Azure AD premium P1
orP2 license
which is necessary to create conditional access policy.Go to Azure portal -> Azure Active directory -> Security -> Conditional access -> Policies -> New policy.
In Grant tab, Select "Grant access" and Check mark "Required Multi factor authentication". Enable policy by selecting it On and Create.
I have tried in my environment, after creating policy I signed in as a guest user from Incognito window and it prompted for two factor authentication like below: