Actions129
- Calendar Permission Actions
- CIPP Administration Actions
- Execute API Client (GET)
- Execute Auto Backup
- Execute Extension Mapping (GET)
- Execute Extension Mapping (POST)
- Execute Extension Sync
- Execute Extensions Config
- Execute Password Config (POST)
- Execute Restore Backup
- Execute Run Backup
- List Custom Roles
- List Extension Sync
- List Logs
- List Scheduled Items
- Remove Scheduled Item
- Execute API Client (POST)
- Execute Extension Test
- Execute Password Config (GET)
- List Backups
- List Function Parameters
- Group Actions
- Intune Actions
- Add MSP App
- Add Office App
- Add Policy
- Add Store App
- Assign App
- Assign Autopilot Device
- Device Action
- Get Recovery Key
- List Applications
- List Application Queue
- List Autopilot Config
- List Devices
- List Intune Scripts
- List Intune Templates
- Remove Autopilot Device
- Remove Policy
- Remove Queued App
- Add Choco App
- Add WinGet App
- Assign Policy
- Get Local Admin Password
- List Autopilot Devices
- List Intune Policies
- Remove App
- Remove Intune Script
- Sync Autopilot Devices
- License Actions
- Security & Compliance Actions
- Teams & SharePoint Actions
- Tenant Actions
- Add Alert
- Clear Tenant Cache
- Execute CA Exclusion
- Execute Named Location
- Get Tenant
- List Alerts Queue
- List Azure AD Connect Status
- List Conditional Access Policies
- List Named Locations
- List Shared Mailbox Statistics
- List Standards
- List Tenants
- Remove Standard Template
- Add Named Location
- Edit Tenant
- Execute Standards Run
- List Audit Logs
- List CSP Licenses
- List Roles
- List Standard Templates
- Tool Actions
- User Actions
- Add User
- Exec Restore Deleted User
- List User
- List User Conditional Access Policies
- List User Groups
- Clear Immutable ID
- Create Temporary Access Password
- Delete User Device
- Dismiss Risky User
- List Deleted Items
- List Inactive Accounts
- List Sign-Ins
- Remove User
- Reset MFA
- Restore Deleted Item
- Revoke Sessions
- Set Email Forward
- Set Per-User MFA
- List All Users
- List User Counts
- List User Devices
- Convert Mailbox
- Disable User
- Enable Archive
- List MFA Users
- Offboard User
- Reset Password
- Send MFA Push
- Set Out of Office
Overview
This node operation sets the per-user Multi-Factor Authentication (MFA) state for a specified user within a tenant. It is useful for administrators who need to enforce, enable, or disable MFA on individual user accounts to enhance security. For example, an admin can enforce MFA for a user who handles sensitive data or disable MFA temporarily for troubleshooting purposes.
Use Case Examples
- Enforce MFA for a user by setting MFA state to 'Enforced'.
- Enable MFA for a user without enforcing it, allowing optional MFA use.
- Disable MFA for a user who is unable to use MFA temporarily.
Properties
| Name | Meaning |
|---|---|
| User ID | The user ID or email address of the user for whom the MFA state is being set. |
| Tenant Filter | The tenant ID or domain name to specify the tenant context for the operation. |
| MFA State | The MFA state to set for the user. Options include 'Enforced', 'Enabled', and 'Disabled'. |
Output
JSON
userId- The ID or email of the user whose MFA state was set.tenantFilter- The tenant ID or domain name where the user resides.mfaState- The MFA state that was applied to the user.status- The result status of the MFA state update operation.
Dependencies
- Requires an API key credential for authentication to the CIPP API.
Troubleshooting
- Ensure the user ID and tenant filter are correctly specified; incorrect values may cause the operation to fail.
- Verify that the API credentials have sufficient permissions to modify user MFA settings.
- If SSL certificate validation errors occur, consider enabling the 'Ignore SSL Issues' option cautiously.
- Timeouts may occur if the server is slow to respond; adjust the timeout setting if necessary.