SSPR via powershell?

%3CLINGO-SUB%20id%3D%22lingo-sub-16397%22%20slang%3D%22en-US%22%3ESSPR%20via%20powershell%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-16397%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20all%2C%3C%2FP%3E%3CP%3EI'm%20wondering%20if%20there%20is%20a%20location%20with%20commands%20to%20access%20info%20regarding%20SSPR%20in%20AAD%20via%20powershell.%26nbsp%3B%20Specifically%20I'm%20trying%20to%20find%20out%20if%20a%20user%20has%20registered%20and%20set%20up%20their%20security%20questions.%26nbsp%3B%20The%20reports%20in%20the%20web%20GUI%20only%20go%20back%20one%20month%2C%20but%20i'd%20like%20a)%20a%20running%20tally%20of%20how%20many%20users%20have%20registered%2C%20and%20b)%20the%20ability%20to%20determine%20if%20an%20individual%20has%20completed%20registration.%26nbsp%3B%20There%20doesn't%20seem%20to%20be%20a%20place%20to%20do%20that%20in%20the%20gui%2C%20and%20i%20cannot%20find%20any%20SSPR%20specific%20powershell%20commands%20for%20the%20msonline%20module.%20Can%20anyone%20shed%20any%20light%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-16397%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIdentity%20and%20Access%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-277371%22%20slang%3D%22en-US%22%3ERe%3A%20SSPR%20via%20powershell%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-277371%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EStrongAuth%20does%20NOT%20mean%20the%20user%20has%20registered%20for%20SSPR.%20It%20only%20means%20a%20user%20has%20one%20or%20more%20StrongAuth%20fields%20set%20like%20Phone%20Number.%3C%2FP%3E%3CP%3EJust%20setting%20any%20of%20these%20fields%20without%20ever%20going%20through%20the%20SSPR%20registration%20process%20will%20still%20tag%20them%20as%20StrongAuth.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-166158%22%20slang%3D%22en-US%22%3ERe%3A%20SSPR%20via%20powershell%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-166158%22%20slang%3D%22en-US%22%3E%3CP%3EHey%2C%3CBR%20%2F%3EI%20have%20recently%20made%20a%20riport%20about%20the%20sspr%20via%20powershell.%20I%20had%20the%20userprincipal%20names%20in%20a%20txt%20file.%3C%2FP%3E%0A%3CP%3E------------%3CBR%20%2F%3EConnect-MsolService%3CBR%20%2F%3E%24path%20%3D%20%22path%20of%20txt%22%3CBR%20%2F%3E%24Users%20%3D%20Get-Content%20%24path%20%3CBR%20%2F%3Eforeach%20(%24User%20in%20%24Users)%3CBR%20%2F%3E%7B%3CBR%20%2F%3EGet-MsolUser%20-UserPrincipalName%20%24User.ToLower()%20%7C%20select%20DisplayName%2C%20PhoneNumber%2C%20Email%7C%20Export-Csv%20%E2%80%93Append%20-Force%20-Path%20%22C%3A%5CUsers%5Cdmeszaros%5CDesktop%5CAzureAD%5Cuserprincipal_v4.csv%22%20-NoTypeInformation%3C%2FP%3E%0A%3CP%3EGet-MsolUser%20-UserPrincipalName%20%24User.ToLower()%20%7C%20select%20-Expand%20StrongAuthenticationUserDetails%20%7C%20select%20DisplayName%2C%20PhoneNumber%2C%20Email%20%7C%20Export-Csv%20%E2%80%93Append%20-Force%20-Path%20%22the%20path%20to%20save%22%20-NoTypeInformation%3CBR%20%2F%3E%7D%3C%2FP%3E%0A%3CP%3E----------------%3C%2FP%3E%0A%3CP%3EThe%20first%20is%20for%20initialize%20the%20columns%20in%20the%20csv%20and%20for%20the%20displayname%20to%20know%20the%20whom%20the%20authentication%20info%20belongs%20to%20because%20the%20next%20command%20wont%20get%20it%26nbsp%3Bso%20that%20gets%20the%20data%20from%20the%20authentication%20box.%3C%2FP%3E%0A%3CP%3EFor%20those%20who%20didn't%20registered%2C%20there%20won't%20be%20a%20second%20line%20so%20that%20they%20didn't%20registered.%3C%2FP%3E%0A%3CP%3EHope%20it%20helps.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-20859%22%20slang%3D%22en-US%22%3ERe%3A%20SSPR%20via%20powershell%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-20859%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20on%20the%20exact%20situation...%20I%20was%20able%20to%20create%20user%2C%20unifiedgroup%2C%20manage%20the%20membership%2C%20set%20the%20password%20and%20rules%20via%20PowerShell.%20but%20when%20I%20try%20to%20test%20the%20account%2C%20now%20SSPR%20is%20blocking%20the%20streamline%20of%20automation...%20I%20was%20hoping%20to%20see%20either%20PowerShell%20method%20to%20import%20predefined%20SSPR%20answers%20(e.g.%20Phone%20number%2C%20Questions%20and%20Answers)%20via%20CSV%20file%20or%20method%20to%20exempt%20them%20from%20SSPR%20for%20special%20account%20cases%20via%20UnifiedGroup%20or%20normal%20Security%20Group%20membership%20(or%20per%20individual%20user%20account...)%3C%2FP%3E%3C%2FLINGO-BODY%3E
Jeremy Pinquist
Visitor

Hey all,

I'm wondering if there is a location with commands to access info regarding SSPR in AAD via powershell.  Specifically I'm trying to find out if a user has registered and set up their security questions.  The reports in the web GUI only go back one month, but i'd like a) a running tally of how many users have registered, and b) the ability to determine if an individual has completed registration.  There doesn't seem to be a place to do that in the gui, and i cannot find any SSPR specific powershell commands for the msonline module. Can anyone shed any light?

3 Replies

I am on the exact situation... I was able to create user, unifiedgroup, manage the membership, set the password and rules via PowerShell. but when I try to test the account, now SSPR is blocking the streamline of automation... I was hoping to see either PowerShell method to import predefined SSPR answers (e.g. Phone number, Questions and Answers) via CSV file or method to exempt them from SSPR for special account cases via UnifiedGroup or normal Security Group membership (or per individual user account...)

Hey,
I have recently made a riport about the sspr via powershell. I had the userprincipal names in a txt file.

------------
Connect-MsolService
$path = "path of txt"
$Users = Get-Content $path
foreach ($User in $Users)
{
Get-MsolUser -UserPrincipalName $User.ToLower() | select DisplayName, PhoneNumber, Email| Export-Csv –Append -Force -Path "C:\Users\dmeszaros\Desktop\AzureAD\userprincipal_v4.csv" -NoTypeInformation

Get-MsolUser -UserPrincipalName $User.ToLower() | select -Expand StrongAuthenticationUserDetails | select DisplayName, PhoneNumber, Email | Export-Csv –Append -Force -Path "the path to save" -NoTypeInformation
}

----------------

The first is for initialize the columns in the csv and for the displayname to know the whom the authentication info belongs to because the next command wont get it so that gets the data from the authentication box.

For those who didn't registered, there won't be a second line so that they didn't registered.

Hope it helps.

Hi,

 

StrongAuth does NOT mean the user has registered for SSPR. It only means a user has one or more StrongAuth fields set like Phone Number.

Just setting any of these fields without ever going through the SSPR registration process will still tag them as StrongAuth.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies