Microsoft Authenticator 图标

Microsoft Authenticator 数据 API:MFA、通行密钥与无密码会话

Microsoft Corporation · 身份

Microsoft Authenticator 是微软面向工作、学校与个人账户的移动登录伴侣。它把手机变成抗钓鱼凭证——带数字匹配的推送批准、TOTP 动态码、通行密钥与无密码手机登录——使其成为运行在 Microsoft Entra ID 上的组织默认的第二重验证。

作为数据源,应用开放的是这些批准背后的身份对象:返回 OathSecret 与 PhoneAppDetailId 的设备注册、携带 firstEntropyNumber 匹配数字与 richContextDetails 登录上下文的待处理质询、按用户的策略标记(如 numberMatchingRequiredState),以及带有 fidoChallenge 值的无密码会话。安全团队基于这些字段构建设备清单、策略核查与会话监控集成。

Microsoft Authenticator 是微软为工作、学校及个人微软账户打造的登录伴侣:带数字匹配的推送批准、TOTP 动态码、通行密钥与无密码手机登录,是部署最广泛的企业 MFA 应用之一。这些批准背后是一套丰富的身份数据集——携带 oath 密钥与租户路由提示的设备注册、含匹配数字与登录上下文的待处理登录质询、按用户的 Authenticator 策略标记,以及通行密钥凭证。安全团队用它清点已注册手机、核查数字匹配策略、监控无密码会话并自动化通行密钥生命周期。

应用截图

  • Microsoft Authenticator 应用截图 1
  • Microsoft Authenticator 应用截图 2
  • Microsoft Authenticator 应用截图 3
  • Microsoft Authenticator 应用截图 4
  • Microsoft Authenticator 应用截图 5
  • Microsoft Authenticator 应用截图 6
  • Microsoft Authenticator 应用截图 7
  • Microsoft Authenticator 应用截图 8

API 端点一览

以下端点与请求/响应示例均依据应用界面推导重构,为示意说明,并非实际抓包。

  • 签发 OAuth 2.0 访问令牌

    POST /v1/oauth/token osint

    将授权码或 refresh_token 兑换为 Bearer access_token,随后附加到策略、通行密钥、会话与设备注册调用。

    认证方式: 公共客户端令牌请求。请求体携带 grant_type(authorization_code、refresh_token 或 srv_challenge)、client_id 与 scope。返回的 access_token 以 Authorization: Bearer 形式发送到策略、通行密钥与会话调用。

    • grant_type
    • client_id
    • code
    • redirect_uri
    • scope
    • token_type
    • expires_in
    • ext_expires_in
    • access_token
    • refresh_token
    • id_token
    POST /v1/oauth/token HTTP/1.1
    Content-Type: application/x-www-form-urlencoded
    
    grant_type=authorization_code&client_id=11112222-3333-4444-5555-666677778888&code=0.AXEA...&redirect_uri=msauth://com.example.mfaapp/callback&scope=https://directory.example.net/.default offline_access
    {
      "token_type": "Bearer",
      "scope": "https://directory.example.net/.default",
      "expires_in": 3599,
      "ext_expires_in": 3599,
      "access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example",
      "refresh_token": "0.AXEA.example",
      "id_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example"
    }
    • 依据应用的登录与令牌交换流程重构
    • 与策略、通行密钥及会话调用所附带的 Bearer 凭证一致
  • 将 Authenticator 注册为 MFA 方法

    POST /v1/mfa/devices/register osint

    将这台 Android 手机登记为 Microsoft Authenticator MFA 方法,返回账户名、TOTP oath 密钥、phoneAppDetailId 及后续调用使用的租户路由提示。

    认证方式: Authorization: Bearer 工作或学校账户的访问令牌。同时发送应用与设备请求头(应用名称与版本、设备平台及一个操作头),以及推送注册令牌的哈希。

    • AccountName
    • GroupKey
    • OathSecret
    • PhoneAppDetailId
    • MfaServerInUse
    • IsDeviceTokenValidationSuccessful
    • IsOathTokenEnabled
    • ReplicationScope
    • RoutingHint
    • TenantCountryCode
    • CurrentDefaultMethod
    • UserCredentialPolicyProto
    • DeviceName
    • DeviceToken
    • NotificationType
    • AppPackageName
    POST /v1/mfa/devices/register HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    Content-Type: application/xml
    X-App-Name: Authenticator
    X-App-Version: 6.2609.6214
    X-Device-Platform: Android
    
    <RegisterDeviceRequest>
      <Version>1.0</Version>
      <AppPackageName>com.example.mfaapp</AppPackageName>
      <AuthenticatorFlavor>Authenticator</AuthenticatorFlavor>
      <DeviceName>Pixel 8</DeviceName>
      <DeviceTag>Android</DeviceTag>
      <DeviceToken>fcm-registration-token</DeviceToken>
      <NotificationType>FCM</NotificationType>
      <PhoneAppVersion>6.2609.6214</PhoneAppVersion>
      <RequestId>9c2e1a44-7b11-4d90-9e3a-2f0c8b1d4e55</RequestId>
      <UpdateDefaultMethod>true</UpdateDefaultMethod>
      <Uses>Notification Oath</Uses>
    </RegisterDeviceRequest>
    {
      "AccountName": "[email protected]",
      "GroupKey": "g-7f2c91aa",
      "OathSecret": "JBSWY3DPEHPK3PXP",
      "PhoneAppDetailId": "pad-8e21c0",
      "MfaServerInUse": false,
      "IsDeviceTokenValidationSuccessful": true,
      "IsOathTokenEnabled": true,
      "ReplicationScope": "NAM",
      "RoutingHint": "contoso.example",
      "TenantCountryCode": "US",
      "CurrentDefaultMethod": "PhoneAppNotification",
      "UserCredentialPolicyProto": "CgNhcHA="
    }
    • 依据应用的工作账户注册流程重构
    • 与添加设备时返回的 oath 密钥及租户路由提示一致
  • 发现 MFA 服务端点

    POST /v1/mfa/endpoints/resolve opendata

    返回手机应用后续 MFA 轮询与批准调用应使用的区域 MFA 中继 URL 与 replicationScopes。

    认证方式: 设备绑定的 MFA 请求头:XML 内容类型、应用名称与版本、设备平台、设备令牌头,以及选择端点发现请求的操作头。

    • version
    • defaultUrl
    • url
    • endpoints
    • replicationScopes
    POST /v1/mfa/endpoints/resolve HTTP/1.1
    Content-Type: application/xml
    X-MFA-Action: getEndpoints
    X-App-Name: Authenticator
    X-Device-Platform: Android
    
    <mfaMessage version="1.6">
      <request request-id="b41c0e22-11aa-4c01-9f10-88c0aa11bb22" async="0" language="en">
        <getEndpointsRequest/>
      </request>
    </mfaMessage>
    {
      "version": "1.6",
      "defaultUrl": "https://mfa.example.net/v1/mfa/relay",
      "url": "https://mfa.example.net/v1/mfa/relay",
      "endpoints": {
        "NAM": "https://mfa-nam.example.net/v1/mfa/relay",
        "EUR": "https://mfa-eur.example.net/v1/mfa/relay"
      },
      "replicationScopes": "NAM,EUR"
    }
    • 依据应用的区域端点发现步骤重构
    • 与手机后续轮询及批准调用使用的复制范围一致
  • 轮询待处理的 MFA 通知

    POST /v1/mfa/challenges/poll osint

    向 MFA 服务查询是否有登录正在等待此设备,并返回待处理质询的 username、groupKey、oathCounter 与 phoneAppDetailId。

    认证方式: 设备绑定的 MFA 请求头,外加来自已注册账户的可选租户路由头(租户 id、复制范围、路由提示与租户国家/地区)。操作头选择待处理质询检查。

    • result
    • groupKey
    • username
    • oathCounter
    • padUrl
    • phoneAppDetailId
    • dosPreventer
    • deviceToken
    • previousDeviceToken
    • AuthenticatorFlavor
    POST /v1/mfa/challenges/poll HTTP/1.1
    Content-Type: application/xml
    X-MFA-Action: checkPendingChallenge
    X-MFA-Interactive: true
    X-Tenant-Id: 72f988bf-86f1-41af-91ab-2d7cd011db47
    X-Routing-Hint: contoso.example
    
    <checkPendingChallengeRequest>
      <dosPreventer>dp-9f31</dosPreventer>
      <deviceToken notificationType="fcm">fcm-registration-token</deviceToken>
      <previousDeviceToken>fcm-registration-token-old</previousDeviceToken>
      <version>6.2609.6214</version>
      <osVersion>14</osVersion>
      <AuthenticatorFlavor>Authenticator</AuthenticatorFlavor>
    </checkPendingChallengeRequest>
    {
      "result": "NotificationWaiting",
      "groupKey": "g-7f2c91aa",
      "username": "[email protected]",
      "oathCounter": 48211,
      "padUrl": "https://mfa.example.net/v1/mfa/relay",
      "phoneAppDetailId": "pad-8e21c0"
    }
    • 依据应用的待处理登录检查重构
    • 与有质询等待时出现的批准通知一致
  • 获取 MFA 质询上下文

    POST /v1/mfa/challenges/context osint

    加载批准界面上展示的待处理 MFA 质询:数字匹配的熵值数字、登录上下文、用户 objectId、租户、欺诈标记以及是否需要应用锁。

    认证方式: 设备绑定的 MFA 请求头;操作头选择质询上下文请求。存在时附带来自已注册账户的租户路由头。

    • responseGuid
    • mode
    • fraudBlock
    • fraudAllowed
    • groupKey
    • phoneAppDetailId
    • username
    • tenantId
    • objectId
    • accountName
    • firstEntropyNumber
    • secondEntropyNumber
    • thirdEntropyNumber
    • sasSessionId
    • richContextDetails
    • returnLocationData
    • isAppLockRequired
    • pinChangeRequired
    • oathTokenEnabled
    • oathCounter
    • replicationScope
    • routingHint
    • tenantCountryCode
    • userCredentialPolicyProto
    POST /v1/mfa/challenges/context HTTP/1.1
    Content-Type: application/xml
    X-MFA-Action: getChallengeContext
    X-Tenant-Id: 72f988bf-86f1-41af-91ab-2d7cd011db47
    
    <challengeContextRequest>
      <challengeContext>
        <guid>3fa85f64-5717-4562-b3fc-2c963f66afa6</guid>
        <oathCode>483921</oathCode>
        <needDosPreventer>yes</needDosPreventer>
        <deviceToken>fcm-registration-token</deviceToken>
        <version>6.2609.6214</version>
        <osVersion>14</osVersion>
      </challengeContext>
    </challengeContextRequest>
    {
      "responseGuid": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "mode": "Push",
      "fraudBlock": false,
      "fraudAllowed": true,
      "groupKey": "g-7f2c91aa",
      "phoneAppDetailId": "pad-8e21c0",
      "username": "[email protected]",
      "tenantId": "72f988bf-86f1-41af-91ab-2d7cd011db47",
      "objectId": "84b12a9c-0e33-4d1a-9f44-11aa22bb33cc",
      "accountName": "[email protected]",
      "firstEntropyNumber": "14",
      "secondEntropyNumber": "67",
      "thirdEntropyNumber": "32",
      "sasSessionId": "sas-9c01",
      "richContextDetails": "Sign-in from Chrome on Windows",
      "returnLocationData": true,
      "isAppLockRequired": true,
      "oathTokenEnabled": true,
      "oathCounter": 48212,
      "replicationScope": "NAM",
      "routingHint": "contoso.example",
      "tenantCountryCode": "US",
      "userCredentialPolicyProto": "CgNhcHA="
    }
    • 依据应用的数字匹配批准界面重构
    • 与向用户展示的匹配数字及登录上下文一致
  • 提交 MFA 批准或拒绝

    POST /v1/mfa/challenges/result osint

    提交用户对待处理 MFA 质询的批准或拒绝决定,包括是否使用了应用锁以及当前 OATH 计数器。

    认证方式: 设备绑定的 MFA 请求头;操作头选择质询结果提交。当质询要求时可能附带 locationData。

    • guid
    • authenticationResult
    • oldDeviceToken
    • newDeviceToken
    • oathTokenCounter
    • isAppLockUsed
    • completedInteractively
    • locationData
    • result
    POST /v1/mfa/challenges/result HTTP/1.1
    Content-Type: application/xml
    X-MFA-Action: submitChallengeResult
    
    <challengeResultRequest>
      <challengeContext>
        <guid>3fa85f64-5717-4562-b3fc-2c963f66afa6</guid>
        <needDosPreventer>no</needDosPreventer>
        <deviceToken>fcm-registration-token</deviceToken>
        <version>6.2609.6214</version>
        <osVersion>14</osVersion>
      </challengeContext>
      <authenticationResult>0</authenticationResult>
      <oathTokenCounter>48212</oathTokenCounter>
      <isAppLockUsed>true</isAppLockUsed>
      <completedInteractively>true</completedInteractively>
    </challengeResultRequest>
    {
      "result": "Success",
      "guid": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
    }
    • 依据应用的批准与拒绝操作重构
    • 与用户响应质询后提交的决定一致
  • 批准时校验 MFA PIN

    POST /v1/mfa/challenges/pin osint

    当 MFA 质询要求在批准前校验 PIN 时,提交用户的应用 PIN(以及可选的数字匹配 digit)。

    认证方式: 设备绑定的 MFA 请求头;操作头选择 PIN 校验。请求体携带 pin(可选 stored=yes)、selectedEntropyNumber 与 isAppLockUsed。

    • guid
    • pin
    • stored
    • authenticate
    • oathCounter
    • completedInteractively
    • selectedEntropyNumber
    • isAppLockUsed
    • pinRetries
    • pinChangeRequired
    • result
    POST /v1/mfa/challenges/pin HTTP/1.1
    Content-Type: application/xml
    X-MFA-Action: validatePin
    
    <pinValidationRequest>
      <challengeContext>
        <guid>3fa85f64-5717-4562-b3fc-2c963f66afa6</guid>
        <needDosPreventer>no</needDosPreventer>
        <deviceToken>fcm-registration-token</deviceToken>
        <version>6.2609.6214</version>
        <osVersion>14</osVersion>
      </challengeContext>
      <pin stored="no">4821</pin>
      <authenticate>yes</authenticate>
      <oathCounter>48212</oathCounter>
      <completedInteractively>yes</completedInteractively>
      <selectedEntropyNumber>14</selectedEntropyNumber>
      <isAppLockUsed>yes</isAppLockUsed>
    </pinValidationRequest>
    {
      "result": "Success",
      "guid": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "pinRetries": 3,
      "pinChangeRequired": false
    }
    • 依据应用的批准时 PIN 校验步骤重构
    • 与 PIN 错误后返回的重试计数器一致
  • 轮换推送设备令牌

    POST /v1/devices/push-token opendata

    通知推送服务替换旧的推送注册令牌,使移动平台刷新令牌后推送 MFA 仍能正常工作。

    认证方式: 设备绑定的 MFA 请求头;操作头选择令牌更换请求,该调用标记为非交互式。

    • dosPreventer
    • oldDeviceToken
    • newDeviceToken
    • notificationType
    • replicationScopes
    • version
    • osVersion
    • result
    POST /v1/devices/push-token HTTP/1.1
    Content-Type: application/xml
    X-MFA-Action: changeDeviceToken
    X-MFA-Interactive: false
    
    <deviceTokenChangeRequest>
      <dosPreventer>dp-9f31</dosPreventer>
      <oldDeviceToken>fcm-registration-token-old</oldDeviceToken>
      <newDeviceToken notificationType="fcm">fcm-registration-token-new</newDeviceToken>
      <version>6.2609.6214</version>
      <osVersion>14</osVersion>
      <replicationScopes>NAM</replicationScopes>
    </deviceTokenChangeRequest>
    {
      "result": "Success",
      "newDeviceToken": "fcm-registration-token-new"
    }
    • 依据应用的推送注册刷新处理重构
    • 与平台令牌轮换后的重新注册一致
  • 读取 Authenticator 方法策略

    GET /v1/accounts/{id}/mfa-policy opendata

    读取用户的 Microsoft Authenticator 策略,包括驱动应用内 MFA 体验的数字匹配、位置显示、软件 TOTP 与配套应用标记。

    认证方式: Authorization: Bearer 为已登录工作账户获取的目录访问令牌。

    • authenticationMethod
    • isEnabled
    • isRequired
    • settings
    • authenticationMode
    • companionAppAllowedState
    • numberMatchingRequiredState
    • displayAppInformationRequiredState
    • displayLocationInformationRequiredState
    • isSoftwareTotpEnabled
    • isAttestationEnforced
    • isEnforceApprovalPinEnabled
    • isSelfServiceRegistrationAllowed
    • passkeyProfiles
    GET /v1/accounts/84b12a9c-0e33-4d1a-9f44-11aa22bb33cc/mfa-policy HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    {
      "value": [
        {
          "authenticationMethod": "microsoftAuthenticator",
          "isEnabled": true,
          "isRequired": true,
          "settings": {
            "authenticationMode": "any",
            "companionAppAllowedState": "enabled",
            "numberMatchingRequiredState": "enabled",
            "displayAppInformationRequiredState": "enabled",
            "displayLocationInformationRequiredState": "enabled",
            "isSoftwareTotpEnabled": true,
            "isAttestationEnforced": false,
            "isEnforceApprovalPinEnabled": false,
            "isSelfServiceRegistrationAllowed": true,
            "passkeyProfiles": []
          }
        }
      ]
    }
    • 依据应用由策略驱动的 MFA 行为重构
    • 与批准界面背后的数字匹配及位置标记一致
  • 读取租户安全默认设置策略

    GET /v1/tenants/security-defaults opendata

    读取租户是否启用了身份安全默认设置,这会改变应用呈现 MFA 注册与批准流程的方式。

    认证方式: Authorization: Bearer 目录访问令牌。

    • id
    • displayName
    • description
    • isEnabled
    GET /v1/tenants/security-defaults HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    {
      "id": "00000000-0000-0000-0000-000000000005",
      "displayName": "Security Defaults",
      "description": "Security defaults provides preconfigured security settings.",
      "isEnabled": true
    }
    • 依据应用的租户策略检查重构
    • 与启用安全默认设置时展示的注册流程一致
  • 获取 FIDO2 通行密钥创建选项

    GET /v1/accounts/{id}/passkeys/creation-options osint

    获取 WebAuthn 凭证创建选项,使应用能为已登录的 Entra 用户生成平台通行密钥。

    认证方式: Authorization: Bearer 目录访问令牌。

    • publicKey
    • rp
    • user
    • challenge
    • pubKeyCredParams
    • timeout
    • authenticatorSelection
    • authenticatorAttachment
    • userVerification
    • requireResidentKey
    • attestation
    • hmacCreateSecret
    • credentialProtectionPolicy
    GET /v1/accounts/84b12a9c-0e33-4d1a-9f44-11aa22bb33cc/passkeys/creation-options?challengeTimeoutInMinutes=5 HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    {
      "publicKey": {
        "rp": {"id": "passkeys.example.net", "name": "Example IDP"},
        "user": {"id": "84b12a9c-0e33-4d1a-9f44-11aa22bb33cc", "name": "[email protected]", "displayName": "Alex Contoso"},
        "challenge": "dGhpc2lzYWNoYWxsZW5nZQ",
        "pubKeyCredParams": [{"type": "public-key", "alg": -7}],
        "timeout": 300000,
        "authenticatorSelection": {"authenticatorAttachment": "platform", "userVerification": "required", "requireResidentKey": true},
        "attestation": "direct",
        "extensions": {"hmacCreateSecret": true, "credentialProtectionPolicy": "userVerificationRequired"}
      }
    }
    • 依据应用的通行密钥设置流程重构
    • 与交给平台认证器的 WebAuthn 选项一致
  • 注册 FIDO2 通行密钥

    POST /v1/accounts/{id}/passkeys osint

    上传平台认证器的证明(attestation),让 Entra ID 在用户名下存储新的 FIDO2 方法。

    认证方式: Authorization: Bearer 目录访问令牌。

    • displayName
    • publicKeyCredential
    • id
    • rawId
    • type
    • attestationObject
    • clientDataJSON
    • createdDateTime
    • aaGuid
    • model
    • attestationLevel
    • passkeyType
    • attestationCertificates
    POST /v1/accounts/84b12a9c-0e33-4d1a-9f44-11aa22bb33cc/passkeys HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    Content-Type: application/json
    
    {
      "displayName": "Pixel 8",
      "publicKeyCredential": {
        "id": "cred-aa11",
        "rawId": "Y3JlZC1hYTEx",
        "type": "public-key",
        "response": {
          "attestationObject": "o2NmbXRkbm9uZWdhdHRTdG10",
          "clientDataJSON": "eyJ0eXBlIjoid2ViYXV0aG4uY3JlYXRlIn0"
        }
      }
    }
    {
      "id": "fido-method-01",
      "displayName": "Pixel 8",
      "createdDateTime": "2026-09-29T12:04:11Z",
      "aaGuid": "ea9b8d66-4d01-1d21-3ce4-b6b48cb575d4",
      "model": "Pixel 8",
      "attestationLevel": "attested",
      "passkeyType": "deviceBound",
      "attestationCertificates": []
    }
    • 依据应用的通行密钥注册步骤重构
    • 与设备密钥库生成的证明对象一致
  • 删除 Authenticator MFA 方法

    DELETE /v1/accounts/{id}/mfa-methods/{methodId} osint

    当账户被删除或设备在应用内注销时,从用户名下移除已注册的 Microsoft Authenticator 方法。

    认证方式: Authorization: Bearer 目录访问令牌。

    • id
    • methodId
    • status
    DELETE /v1/accounts/84b12a9c-0e33-4d1a-9f44-11aa22bb33cc/mfa-methods/pad-8e21c0 HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    {
      "status": 204
    }
    • 依据应用的账户移除流程重构
    • 与设备注销后的方法清理一致
  • 删除 FIDO2 通行密钥方法

    DELETE /v1/accounts/{id}/passkeys/{methodId} osint

    当通行密钥在应用内被删除时,从用户名下移除已注册的 FIDO2 / 通行密钥方法。

    认证方式: Authorization: Bearer 目录访问令牌。

    • id
    • methodId
    • status
    DELETE /v1/accounts/84b12a9c-0e33-4d1a-9f44-11aa22bb33cc/passkeys/fido-method-01 HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    {
      "status": 204
    }
    • 依据应用的通行密钥管理界面重构
    • 与移除通行密钥时发出的删除请求一致
  • 读取组织数据边界

    GET /v1/tenants/current opendata

    读取已登录租户的组织记录,使应用在上传诊断日志时遵守区域数据边界(dataBoundary)。

    认证方式: Authorization: Bearer 为已登录工作账户获取的目录访问令牌。

    • id
    • displayName
    • countryLetterCode
    • dataBoundary
    GET /v1/tenants/current HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    {
      "value": [
        {
          "id": "72f988bf-86f1-41af-91ab-2d7cd011db47",
          "displayName": "Contoso",
          "countryLetterCode": "US",
          "dataBoundary": "Global"
        }
      ]
    }
    • 依据应用的诊断上传设置重构
    • 与按区域路由日志的数据边界值一致
  • 列出无密码登录会话

    GET /v1/signin/sessions osint

    列出账户待处理的无密码手机登录会话,包括数字匹配 digit、FIDO 质询以及发起请求的客户端详情。

    认证方式: Authorization: Bearer 访问令牌。同时发送客户端关联头:请求 id 以及客户端 SKU 与客户端名称。

    • sessionsList
    • username
    • userObjectIdHash
    • code
    • sessionId
    • sessionType
    • requestTime
    • expirationTime
    • audience
    • entropy1
    • entropy2
    • entropy3
    • authDetails
    • tenantId
    • userCredentialPolicy
    • phoneAppDetails
    • fidoChallenge
    GET /v1/signin/sessions HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    client-request-id: 5e2a1c90-44bb-4d11-a0e1-77aa11bb22cc
    X-Client-SKU: authenticator.android
    X-Client-Name: AuthenticatorAndroid
    {
      "sessionsList": [
        {
          "session": {
            "username": "[email protected]",
            "userObjectIdHash": "a11c0e22",
            "code": "14",
            "sessionId": "sess-01",
            "sessionType": "Passwordless",
            "requestTime": 1759142400,
            "expirationTime": 1759142700,
            "audience": "https://idp.example.net",
            "entropy1": 14,
            "entropy2": 67,
            "entropy3": 32,
            "authDetails": "Chrome on Windows",
            "tenantId": "72f988bf-86f1-41af-91ab-2d7cd011db47",
            "userCredentialPolicy": "CgNhcHA=",
            "phoneAppDetails": "pad-8e21c0",
            "fidoChallenge": "dGhpc2lzYWNoYWxsZW5nZQ"
          }
        }
      ]
    }
    • 依据应用的无密码登录列表重构
    • 与连同匹配码一起展示的待处理会话一致
  • 批准无密码登录会话

    POST /v1/signin/sessions/approve osint

    在用户确认数字匹配或提供 FIDO 断言后,批准或拒绝待处理的无密码手机登录会话。

    认证方式: Authorization: Bearer 访问令牌。表单请求体携带密钥断言或 FIDO 断言(fidoassertion),以及 sessionid、sessionstate、sessiontype 与 userobjectid。

    • sessionid
    • sessionstate
    • sessiontype
    • userobjectid
    • assertion
    • fidoassertion
    • entropy
    • oathcounter
    • app_state
    • deviceid
    • success
    POST /v1/signin/sessions/approve HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    Content-Type: application/x-www-form-urlencoded
    client-request-id: 5e2a1c90-44bb-4d11-a0e1-77aa11bb22cc
    
    sessionid=sess-01&sessionstate=approve&sessiontype=Passwordless&userobjectid=84b12a9c-0e33-4d1a-9f44-11aa22bb33cc&assertion=eyJhbGciOiJFUzI1NiJ9.example&entropy=14&oathcounter=48212
    {
      "success": true
    }
    • 依据应用的数字匹配确认重构
    • 与为完成手机登录而提交的签名断言一致
  • 注册设备登录密钥

    POST /v1/devices/keys osint

    向设备注册服务注册设备的公共登录密钥,使手机之后能够批准无密码会话。

    认证方式: Authorization: Bearer 限定设备注册作用域的令牌。发送 api-version 查询参数以及客户端名称与 SKU 头。

    • publicKeyCredential
    • credentialDisplayName
    • attributes
    • supports_notification
    • message
    • time
    • requestId
    • serverKeyId
    POST /v1/devices/keys?api-version=1.1 HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    Content-Type: application/json
    X-Client-Name: AuthenticatorAndroid
    X-Client-SKU: authenticator.android
    
    {
      "publicKeyCredential": {
        "id": "cred-aa11",
        "rawId": "Y3JlZC1hYTEx",
        "type": "public-key",
        "response": {
          "attestationObject": "o2NmbXRkbm9uZWdhdHRTdG10",
          "clientDataJSON": "eyJ0eXBlIjoid2ViYXV0aG4uY3JlYXRlIn0"
        }
      },
      "credentialDisplayName": "Pixel 8",
      "attributes": {
        "supports_notification": "true"
      }
    }
    {
      "message": "Key registered",
      "time": "2026-09-29T12:05:01Z",
      "requestId": "drs-req-01",
      "serverKeyId": "key-8e21c0"
    }
    • 依据应用的无密码设置流程重构
    • 与设备密钥注册期间上传的公钥及证明一致
  • 删除设备登录密钥

    DELETE /v1/devices/keys/{keyId} osint

    当工作账户被删除或关闭无密码手机登录时,从注册服务中移除设备登录密钥。

    认证方式: Authorization: Bearer 设备注册令牌。应用从发现元数据解析删除路由,并附加 api-version 查询参数。

    • keyId
    • upn
    • krctx
    DELETE /v1/devices/keys/key-8e21c0?api-version=1.0 HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.example
    X-Client-Name: AuthenticatorAndroid
    X-Client-SKU: authenticator.android
    {
      "keyId": "key-8e21c0",
      "upn": "[email protected]",
      "krctx": "ctx-01"
    }
    • 依据应用的工作账户移除流程重构
    • 与停用无密码登录时发出的密钥清理一致

数据类别

  • MFA 注册
  • 推送批准
  • TOTP 密钥
  • 通行密钥
  • 无密码会话
  • 设备令牌
  • 认证方法策略
  • 组织数据边界

数据使用场景与案例

  • 企业 MFA 设备清单

    读取每次设备注册返回的 AccountName、PhoneAppDetailId、DeviceName 与 TenantCountryCode,再结合 DeviceToken 轮换事件,核对哪些手机已登记为 Microsoft Authenticator 方法。

  • 数字匹配与位置策略核查

    从按用户的 Authenticator 策略中拉取 numberMatchingRequiredState、displayLocationInformationRequiredState 与 isSoftwareTotpEnabled,并与实时 MFA 质询上的 firstEntropyNumber 和 returnLocationData 比对。

  • 无密码会话监控

    监视待处理会话列表中的无密码登录(username、sessionType、authDetails、fidoChallenge),并在用户确认匹配码后以签名断言完成登录。

  • Entra ID 上的通行密钥生命周期

    读取通行密钥创建选项,根据其证明为用户存储平台通行密钥,并在设备退役时移除 Authenticator 或通行密钥方法。

常见问题

Microsoft Authenticator 如何注册工作或学校账户?

应用向 /v1/mfa/devices/register 提交设备注册:携带 Bearer 令牌、应用与设备请求头,以及包含 DeviceName、DeviceToken 与 NotificationType 的 XML 请求体。响应返回 AccountName、GroupKey、OathSecret 与 PhoneAppDetailId,以及后续调用使用的租户路由提示。

推送 MFA 批准如何请求与提交?

手机轮询 /v1/mfa/challenges/poll 查询是否有等待中的登录,从 /v1/mfa/challenges/context 加载质询(firstEntropyNumber 数字、sasSessionId、richContextDetails),然后向 /v1/mfa/challenges/result 提交决定,携带 authenticationResult、isAppLockUsed 与 oathTokenCounter。当策略要求时,先由 /v1/mfa/challenges/pin 校验应用 PIN。

Authenticator 策略数据包含哪些内容?

GET /v1/accounts/{id}/mfa-policy 返回按用户的 Authenticator 设置:authenticationMode、numberMatchingRequiredState、displayLocationInformationRequiredState、isSoftwareTotpEnabled 与 companionAppAllowedState。另一个租户调用 /v1/tenants/security-defaults 报告是否启用了身份安全默认设置。

应用中的通行密钥与无密码登录如何工作?

待处理的无密码会话在 /v1/signin/sessions 列出(sessionId、熵值数字、fidoChallenge),并在 /v1/signin/sessions/approve 以签名断言完成。通行密钥设置从 /v1/accounts/{id}/passkeys/creation-options 读取选项,并以 POST /v1/accounts/{id}/passkeys 存储凭证;对同一资源的 DELETE 将其退役。

与 Microsoft Authenticator 相似的应用

  • Google Authenticator — Google 出品的免费验证器应用,为 Google 及第三方账户生成基于时间(TOTP)和计数器(HOTP)的一次性验证码,可选择同步到 Google 账户。
  • Twilio Authy — Twilio 的双重验证应用,提供加密云备份与多设备同步,更换手机后验证码仍可保留。
  • Duo Mobile — 思科的企业级 MFA 应用,处理推送批准,并可与 Duo 的基于风险的认证、单点登录和设备可见性平台配合使用。
  • Okta Verify — Okta 的企业身份应用,为 Okta 管理的账户发送推送批准,被列为 Microsoft Authenticator 的直接竞品之一。
  • Aegis Authenticator — 一款免费开源的 Android 验证器,将令牌存放在加密的本地保险库中,不收集用户数据。
  • 2FAS Auth — 一款开源验证器,无需注册账户即可离线使用,并提供可选的浏览器扩展以加快登录。
  • Ente Auth — Ente 推出的开源验证器,提供端到端加密备份,可在手机与桌面端之间同步验证码。

相关主题

  • Microsoft Authenticator API
  • MFA 推送批准 API
  • Authenticator 设备注册
  • 数字匹配 MFA
  • 无密码手机登录
  • FIDO2 通行密钥注册 API
  • OathSecret PhoneAppDetailId
  • Authenticator 策略 API

需要集成这个 App 的数据 API?

我们可为任意指定 App 交付定制集成——源码交付 USD 500 起,或托管 API 按调用计费。告诉我们您需要的数据即可。

  • 每个项目均签 NDA 与 SOW
  • 3–7 天交付
  • 验收通过后才付款
  • 仅在授权范围内作业

获取报价