Set-AdfsAzureMfaTenant
Set-AdfsAzureMfaTenant is accessible with the help of adfs module. To install adfs on your system please refer to this adfs.
Synopsis
Enables an AD FS farm to use MFA.
Description
The Set-AdfsAzureMfaTenant cmdlet enables an Active Directory Federation Services (AD FS) farm to use Azure Multi-Factor Authentication (MFA) after a certificate has been created and registered in the Azure Active Directory (AD) tenant.
Parameters
-ClientId
Specifies the well-known ID of the Azure MFA application in Azure AD.
Required? true
Position? named
Default value none
Accept pipeline input? false
Accept wildcard characters? false
-TenantId <String>
Specifies the GUID representation of an Azure AD tenant ID. This can be found in the URL bar of the Azure AD portal, as in this example:
https://manage.windowsazure.com/TOSSolution.onmicrosoft.com#Workspaces/ActiveDirectoryExtension/Directory/<tenantID_GUID>/directoryQuickStart
Required? true
Position? named
Default value none
Accept pipeline input? false
Accept wildcard characters? false
-Confirm <SwitchParameter>
Prompts you for confirmation before running the cmdlet.Prompts you for confirmation before running the cmdlet.
Required? false
Position? named
Default value false
Accept pipeline input? false
Accept wildcard characters? false
-WhatIf <SwitchParameter>
Shows what would happen if the cmdlet runs. The cmdlet is not run.Shows what would happen if the cmdlet runs. The cmdlet is not run.
Required? false
Position? named
Default value false
Accept pipeline input? false
Accept wildcard characters? false
Syntax
Set-AdfsAzureMfaTenant -TenantId <String> -ClientId <String> [-WhatIf] [-Confirm] [<CommonParameters>]
—————Example 1—————
Enable Azure MFA
PS C:>$certbase64 = New-AdfsAzureMfaTenantCertificate -TenantID
PS C:>New-MsolServicePrincipalCredential -AppPrincipalId <your Principal ID> -Type asymmetric -Usage verify -Value $certBase64
PS C:>Set-AdfsAzureMfaTenant -TenantId -ClientId <your Principal ID>
This command creates a certificate for Azure MFA, registers it in the tenant, and enables Azure MFA on the AD FS farm.
You can check the Version, CommandType and Source of this cmdlet by giving below command.
Get-Command Set-AdfsAzureMfaTenant
You can also read about
- New-AdfsAzureMfaTenantCertificate