代码之家  ›  专栏  ›  技术社区  ›  Jinesh

如何在Azure AD用户中重置密码?

  •  1
  • Jinesh  · 技术社区  · 8 年前

    我正在使用azure AD进行应用程序身份验证。用户已在Azure AD中成功装箱。用户可以使用密码登录。我的要求是如何用户可以重置自己的密码。当用户忘记密码时,他们如何在我的应用程序中重置自己的密码。有任何图形api可用吗?

    1 回复  |  直到 8 年前
        1
  •  1
  •   Joey Cai    8 年前

    Resetting a user's password 是更新用户操作的特例。指定 密码配置文件 User . 请求包含有效的 PasswordProfile PasswordProfile

    可以通过修补用户对象重置用户密码:

    PATCH https://graph.windows.net/myorganization/users/{user_id}?api-version=1.6
    
    {
        "passwordProfile": {
            "password": "{password}",
            "forceChangePasswordNextLogin": false
        },
        "passwordPolicies": "DisablePasswordExpiration"
    }
    

    :

    1.切换你的管理目录authority.Add 在Azure广告中。获取用户名和密码。

    :设置username时,@后面是整个目录名。第一次登录时,需要更改密码。

    enter image description here

    2.转到已注册的本机应用,添加权限 以登录用户身份访问目录 到应用程序。 enter image description here :委托范围 User.ReadWrite.All 或 Directory.AccessAsUser.All 重置用户密码时需要。除了正确的范围之外 signed-in 用户需要足够的权限来重置另一个用户的密码。

    var graphResourceId = "https://graph.windows.net/";
    var tenantId = "xxxxxxxxxxxxxxxxxxxxx";
    var clientId = "xxxxxxxxxxxxxxxxxxxxxxx";
    var username = "xxxxxxxxxxxxxxxxxxxx";
    var password = "xxxxxxxxx";
    var servicePointUri = new Uri(graphResourceId);
    var serviceRoot = new Uri(servicePointUri, tenantId);
    string aadInstance = "https://login.microsoftonline.com/" + tenantId + "/oauth2/token";
    AuthenticationContext authenticationContext = new AuthenticationContext(aadInstance, false);
    
    UserPasswordCredential credential = new UserPasswordCredential(username, password);
    AuthenticationResult authenticationResult = authenticationContext.AcquireTokenAsync(graphResourceId, clientId, credential).Result;
    var accessToken = authenticationResult.AccessToken;
    HttpClient http = new HttpClient();
    string url = "https://graph.windows.net/" + tenantId + "/users/" + username + "?api-version=1.6";
    var method = new HttpMethod("PATCH");
    HttpRequestMessage request = new HttpRequestMessage(method, url);
    request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", authenticationResult.AccessToken);
    var body = "{\"passwordProfile\": {\"password\": \"YourNewPassword\",\"forceChangePasswordNextLogin\": false},\"passwordPolicies\":\"DisablePasswordExpiration\"}";
    request.Content = new StringContent(body, Encoding.UTF8, "application/json");
    HttpResponseMessage response = http.SendAsync(request).Result;
    

    4.输出如下: enter image description here