Note
Access to this page requires authorization. You can try signing in or .
Access to this page requires authorization. You can try .
Update-MgBetaPolicyAuthenticationMethodPolicy
Update the properties of an authenticationMethodsPolicy object.
Note
To view the v1.0 release of this cmdlet, view Update-MgPolicyAuthenticationMethodPolicy
Syntax
UpdateExpanded (Default)
Update-MgBetaPolicyAuthenticationMethodPolicy
[-ResponseHeadersVariable <string>]
[-AdditionalProperties <hashtable>]
[-AuthenticationMethodConfigurations <IMicrosoftGraphAuthenticationMethodConfiguration[]>]
[-Description <string>]
[-DisplayName <string>]
[-Id <string>]
[-LastModifiedDateTime <datetime>]
[-MicrosoftAuthenticatorPlatformSettings <IMicrosoftGraphMicrosoftAuthenticatorPlatformSettings>]
[-PolicyMigrationState <string>]
[-PolicyVersion <string>]
[-ReconfirmationInDays <int>]
[-RegistrationEnforcement <IMicrosoftGraphRegistrationEnforcement>]
[-ReportSuspiciousActivitySettings <IMicrosoftGraphReportSuspiciousActivitySettings>]
[-SystemCredentialPreferences <IMicrosoftGraphSystemCredentialPreferences>]
[-Break]
[-Headers <IDictionary>]
[-HttpPipelineAppend <SendAsyncStep[]>]
[-HttpPipelinePrepend <SendAsyncStep[]>]
[-Proxy <uri>]
[-ProxyCredential <pscredential>]
[-ProxyUseDefaultCredentials]
[-WhatIf]
[-Confirm]
[<CommonParameters>]
Update
Update-MgBetaPolicyAuthenticationMethodPolicy
-BodyParameter <IMicrosoftGraphAuthenticationMethodsPolicy>
[-ResponseHeadersVariable <string>]
[-Break]
[-Headers <IDictionary>]
[-HttpPipelineAppend <SendAsyncStep[]>]
[-HttpPipelinePrepend <SendAsyncStep[]>]
[-Proxy <uri>]
[-ProxyCredential <pscredential>]
[-ProxyUseDefaultCredentials]
[-WhatIf]
[-Confirm]
[<CommonParameters>]
Description
Update the properties of an authenticationMethodsPolicy object.
Permissions
| Permission type | Permissions (from least to most privileged) |
|---|---|
| Delegated (work or school account) | Policy.ReadWrite.AuthenticationMethod, |
| Delegated (personal Microsoft account) | Not supported |
| Application | Policy.ReadWrite.AuthenticationMethod, |
Examples
Example 1: Code snippet
Import-Module Microsoft.Graph.Beta.Identity.SignIns
$params = @{
registrationEnforcement = @{
authenticationMethodsRegistrationCampaign = @{
snoozeDurationInDays = 1
enforceRegistrationAfterAllowedSnoozes = $true
state = "enabled"
excludeTargets = @(
)
includeTargets = @(
@{
id = "3ee3a9de-0a86-4e12-a287-9769accf1ba2"
targetType = "group"
targetedAuthenticationMethod = "microsoftAuthenticator"
}
)
}
}
reportSuspiciousActivitySettings = @{
state = "enabled"
includeTarget = @{
targetType = "group"
id = "all_users"
}
voiceReportingCode = 0
}
}
Update-MgBetaPolicyAuthenticationMethodPolicy -BodyParameter $params
This example shows how to use the Update-MgBetaPolicyAuthenticationMethodPolicy Cmdlet.
Parameters
-AdditionalProperties
Additional Parameters
Parameter properties
| Type: | System.Collections.Hashtable |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-AuthenticationMethodConfigurations
Represents the settings for each authentication method. Automatically expanded on GET /policies/authenticationMethodsPolicy. To construct, see NOTES section for AUTHENTICATIONMETHODCONFIGURATIONS properties and create a hash table.
Parameter properties
| Type: | Microsoft.Graph.Beta.PowerShell.Models.IMicrosoftGraphAuthenticationMethodConfiguration[] |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-BodyParameter
authenticationMethodsPolicy To construct, see NOTES section for BODYPARAMETER properties and create a hash table.
Parameter properties
| Type: | Microsoft.Graph.Beta.PowerShell.Models.IMicrosoftGraphAuthenticationMethodsPolicy |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-Break
Wait for .NET debugger to attach
Parameter properties
| Type: | System.Management.Automation.SwitchParameter |
| Default value: | False |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-Confirm
Prompts you for confirmation before running the cmdlet.
Parameter properties
| Type: | System.Management.Automation.SwitchParameter |
| Supports wildcards: | False |
| DontShow: | False |
| Aliases: | cf |
Parameter sets
-Description
A description of the policy.
Parameter properties
| Type: | System.String |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-DisplayName
The name of the policy.
Parameter properties
| Type: | System.String |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-Headers
Optional headers that will be added to the request.
Parameter properties
| Type: | System.Collections.IDictionary |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-HttpPipelineAppend
SendAsync Pipeline Steps to be appended to the front of the pipeline
Parameter properties
| Type: | Microsoft.Graph.Beta.PowerShell.Runtime.SendAsyncStep[] |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-HttpPipelinePrepend
SendAsync Pipeline Steps to be prepended to the front of the pipeline
Parameter properties
| Type: | Microsoft.Graph.Beta.PowerShell.Runtime.SendAsyncStep[] |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-Id
The unique identifier for an entity. Read-only.
Parameter properties
| Type: | System.String |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-LastModifiedDateTime
The date and time of the last update to the policy.
Parameter properties
| Type: | System.DateTime |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-MicrosoftAuthenticatorPlatformSettings
microsoftAuthenticatorPlatformSettings To construct, see NOTES section for MICROSOFTAUTHENTICATORPLATFORMSETTINGS properties and create a hash table.
Parameter properties
| Type: | Microsoft.Graph.Beta.PowerShell.Models.IMicrosoftGraphMicrosoftAuthenticatorPlatformSettings |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-PolicyMigrationState
authenticationMethodsPolicyMigrationState
Parameter properties
| Type: | System.String |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-PolicyVersion
The version of the policy in use.
Parameter properties
| Type: | System.String |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-Proxy
The URI for the proxy server to use
Parameter properties
| Type: | System.Uri |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-ProxyCredential
Credentials for a proxy server to use for the remote call
Parameter properties
| Type: | System.Management.Automation.PSCredential |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-ProxyUseDefaultCredentials
Use the default credentials for the proxy
Parameter properties
| Type: | System.Management.Automation.SwitchParameter |
| Default value: | False |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-ReconfirmationInDays
Days before the user will be asked to reconfirm their method.
Parameter properties
| Type: | System.Int32 |
| Default value: | 0 |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-RegistrationEnforcement
registrationEnforcement To construct, see NOTES section for REGISTRATIONENFORCEMENT properties and create a hash table.
Parameter properties
| Type: | Microsoft.Graph.Beta.PowerShell.Models.IMicrosoftGraphRegistrationEnforcement |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-ReportSuspiciousActivitySettings
reportSuspiciousActivitySettings To construct, see NOTES section for REPORTSUSPICIOUSACTIVITYSETTINGS properties and create a hash table.
Parameter properties
| Type: | Microsoft.Graph.Beta.PowerShell.Models.IMicrosoftGraphReportSuspiciousActivitySettings |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-ResponseHeadersVariable
Optional Response Headers Variable.
Parameter properties
| Type: | System.String |
| Supports wildcards: | False |
| DontShow: | False |
| Aliases: | RHV |
Parameter sets
-SystemCredentialPreferences
systemCredentialPreferences To construct, see NOTES section for SYSTEMCREDENTIALPREFERENCES properties and create a hash table.
Parameter properties
| Type: | Microsoft.Graph.Beta.PowerShell.Models.IMicrosoftGraphSystemCredentialPreferences |
| Supports wildcards: | False |
| DontShow: | False |
Parameter sets
-WhatIf
Runs the command in a mode that only reports what would happen without performing the actions.
Parameter properties
| Type: | System.Management.Automation.SwitchParameter |
| Supports wildcards: | False |
| DontShow: | False |
| Aliases: | wi |
Parameter sets
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutBuffer, -OutVariable, -PipelineVariable, -ProgressAction, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
Inputs
Microsoft.Graph.Beta.PowerShell.Models.IMicrosoftGraphAuthenticationMethodsPolicy
{{ Fill in the Description }}
System.Collections.IDictionary
{{ Fill in the Description }}
Outputs
Microsoft.Graph.Beta.PowerShell.Models.IMicrosoftGraphAuthenticationMethodsPolicy
{{ Fill in the Description }}
Notes
COMPLEX PARAMETER PROPERTIES
To create the parameters described below, construct a hash table containing the appropriate properties. For information on hash tables, run Get-Help about_Hash_Tables.
AUTHENTICATIONMETHODCONFIGURATIONS <IMicrosoftGraphAuthenticationMethodConfiguration[]>: Represents the settings for each authentication method. Automatically expanded on GET /policies/authenticationMethodsPolicy. [Id <String>]: The unique identifier for an entity. Read-only. [ExcludeTargets <IMicrosoftGraphExcludeTarget[]>]: Groups of users that are excluded from a policy. [Id <String>]: The object identifier of a Microsoft Entra group. [TargetType <String>]: authenticationMethodTargetType [State <String>]: authenticationMethodState
BODYPARAMETER <IMicrosoftGraphAuthenticationMethodsPolicy>: authenticationMethodsPolicy
[(Any) <Object>]: This indicates any property can be added to this object.
[Id <String>]: The unique identifier for an entity.
Read-only.
[AuthenticationMethodConfigurations <IMicrosoftGraphAuthenticationMethodConfiguration[]>]: Represents the settings for each authentication method.
Automatically expanded on GET /policies/authenticationMethodsPolicy.
[Id <String>]: The unique identifier for an entity.
Read-only.
[ExcludeTargets <IMicrosoftGraphExcludeTarget[]>]: Groups of users that are excluded from a policy.
[Id <String>]: The object identifier of a Microsoft Entra group.
[TargetType <String>]: authenticationMethodTargetType
[State <String>]: authenticationMethodState
[Description <String>]: A description of the policy.
[DisplayName <String>]: The name of the policy.
[LastModifiedDateTime <DateTime?>]: The date and time of the last update to the policy.
[MicrosoftAuthenticatorPlatformSettings <IMicrosoftGraphMicrosoftAuthenticatorPlatformSettings>]: microsoftAuthenticatorPlatformSettings
[(Any) <Object>]: This indicates any property can be added to this object.
[EnforceAppPin <IMicrosoftGraphEnforceAppPin>]: enforceAppPIN
[(Any) <Object>]: This indicates any property can be added to this object.
[ExcludeTargets <IMicrosoftGraphExcludeTarget[]>]:
[IncludeTargets <IMicrosoftGraphIncludeTarget[]>]:
[Id <String>]: The ID of the entity targeted.
[TargetType <String>]: authenticationMethodTargetType
[PolicyMigrationState <String>]: authenticationMethodsPolicyMigrationState
[PolicyVersion <String>]: The version of the policy in use.
[ReconfirmationInDays <Int32?>]: Days before the user will be asked to reconfirm their method.
[RegistrationEnforcement <IMicrosoftGraphRegistrationEnforcement>]: registrationEnforcement
[(Any) <Object>]: This indicates any property can be added to this object.
[AuthenticationMethodsRegistrationCampaign <IMicrosoftGraphAuthenticationMethodsRegistrationCampaign>]: authenticationMethodsRegistrationCampaign
[(Any) <Object>]: This indicates any property can be added to this object.
[EnforceRegistrationAfterAllowedSnoozes <Boolean?>]: Specifies whether a user is required to perform registration after snoozing 3 times.
If true, the user is required to register after 3 snoozes.
If false, the user can snooze indefinitely.
The default value is true.
[ExcludeTargets <IMicrosoftGraphExcludeTarget[]>]: Users and groups of users that are excluded from being prompted to set up the authentication method.
[IncludeTargets <IMicrosoftGraphAuthenticationMethodsRegistrationCampaignIncludeTarget[]>]: Users and groups of users that are prompted to set up the authentication method.
[Id <String>]: The object identifier of a Microsoft Entra user or group.
[TargetType <String>]: authenticationMethodTargetType
[TargetedAuthenticationMethod <String>]: The authentication method that the user is prompted to register.
The value must be microsoftAuthenticator.
[SnoozeDurationInDays <Int32?>]: Specifies the number of days that the user sees a prompt again if they select 'Not now' and snoozes the prompt.
Minimum 0 days.
Maximum: 14 days.
If the value is 0 – The user is prompted during every MFA attempt.
[State <String>]: advancedConfigState
[ReportSuspiciousActivitySettings <IMicrosoftGraphReportSuspiciousActivitySettings>]: reportSuspiciousActivitySettings
[(Any) <Object>]: This indicates any property can be added to this object.
[IncludeTarget <IMicrosoftGraphIncludeTarget>]: includeTarget
[State <String>]: advancedConfigState
[VoiceReportingCode <Int32?>]: Specifies the number the user enters on their phone to report the MFA prompt as suspicious.
[SystemCredentialPreferences <IMicrosoftGraphSystemCredentialPreferences>]: systemCredentialPreferences
[(Any) <Object>]: This indicates any property can be added to this object.
[ExcludeTargets <IMicrosoftGraphExcludeTarget[]>]: Users and groups excluded from the preferred authentication method experience of the system.
[IncludeTargets <IMicrosoftGraphIncludeTarget[]>]: Users and groups included in the preferred authentication method experience of the system.
[State <String>]: advancedConfigState
MICROSOFTAUTHENTICATORPLATFORMSETTINGS <IMicrosoftGraphMicrosoftAuthenticatorPlatformSettings>: microsoftAuthenticatorPlatformSettings
[(Any) <Object>]: This indicates any property can be added to this object.
[EnforceAppPin <IMicrosoftGraphEnforceAppPin>]: enforceAppPIN
[(Any) <Object>]: This indicates any property can be added to this object.
[ExcludeTargets <IMicrosoftGraphExcludeTarget[]>]:
[Id <String>]: The object identifier of a Microsoft Entra group.
[TargetType <String>]: authenticationMethodTargetType
[IncludeTargets <IMicrosoftGraphIncludeTarget[]>]:
[Id <String>]: The ID of the entity targeted.
[TargetType <String>]: authenticationMethodTargetType
REGISTRATIONENFORCEMENT <IMicrosoftGraphRegistrationEnforcement>: registrationEnforcement
[(Any) <Object>]: This indicates any property can be added to this object.
[AuthenticationMethodsRegistrationCampaign <IMicrosoftGraphAuthenticationMethodsRegistrationCampaign>]: authenticationMethodsRegistrationCampaign
[(Any) <Object>]: This indicates any property can be added to this object.
[EnforceRegistrationAfterAllowedSnoozes <Boolean?>]: Specifies whether a user is required to perform registration after snoozing 3 times.
If true, the user is required to register after 3 snoozes.
If false, the user can snooze indefinitely.
The default value is true.
[ExcludeTargets <IMicrosoftGraphExcludeTarget[]>]: Users and groups of users that are excluded from being prompted to set up the authentication method.
[Id <String>]: The object identifier of a Microsoft Entra group.
[TargetType <String>]: authenticationMethodTargetType
[IncludeTargets <IMicrosoftGraphAuthenticationMethodsRegistrationCampaignIncludeTarget[]>]: Users and groups of users that are prompted to set up the authentication method.
[Id <String>]: The object identifier of a Microsoft Entra user or group.
[TargetType <String>]: authenticationMethodTargetType
[TargetedAuthenticationMethod <String>]: The authentication method that the user is prompted to register.
The value must be microsoftAuthenticator.
[SnoozeDurationInDays <Int32?>]: Specifies the number of days that the user sees a prompt again if they select 'Not now' and snoozes the prompt.
Minimum 0 days.
Maximum: 14 days.
If the value is 0 – The user is prompted during every MFA attempt.
[State <String>]: advancedConfigState
REPORTSUSPICIOUSACTIVITYSETTINGS <IMicrosoftGraphReportSuspiciousActivitySettings>: reportSuspiciousActivitySettings
[(Any) <Object>]: This indicates any property can be added to this object.
[IncludeTarget <IMicrosoftGraphIncludeTarget>]: includeTarget
[(Any) <Object>]: This indicates any property can be added to this object.
[Id <String>]: The ID of the entity targeted.
[TargetType <String>]: authenticationMethodTargetType
[State <String>]: advancedConfigState
[VoiceReportingCode <Int32?>]: Specifies the number the user enters on their phone to report the MFA prompt as suspicious.
SYSTEMCREDENTIALPREFERENCES <IMicrosoftGraphSystemCredentialPreferences>: systemCredentialPreferences
[(Any) <Object>]: This indicates any property can be added to this object.
[ExcludeTargets <IMicrosoftGraphExcludeTarget[]>]: Users and groups excluded from the preferred authentication method experience of the system.
[Id <String>]: The object identifier of a Microsoft Entra group.
[TargetType <String>]: authenticationMethodTargetType
[IncludeTargets <IMicrosoftGraphIncludeTarget[]>]: Users and groups included in the preferred authentication method experience of the system.
[Id <String>]: The ID of the entity targeted.
[TargetType <String>]: authenticationMethodTargetType
[State <String>]: advancedConfigState
