Azure-Samples / active-directory-b2c-advanced-policies

Sample for use with Azure AD B2C with Custom Policies.
http://aka.ms/aadb2ccustom
MIT License
217 stars 145 forks source link

Can I use two email addresses for MFA using custom policies? #66

Open 1993Saurabh opened 4 years ago

1993Saurabh commented 4 years ago

I would just like to know, can we use two email addresses for Multi-factor authentication in custom policies just like two phone numbers. Is it possible to do that?

Any help would be appreciated in this regard.

xinaxu commented 4 years ago

Are the verification of those email addresses on the same page or different pages? If on the same page, should both pass verification or either one is fine?

1993Saurabh commented 4 years ago

Hi @xinaxu, Verification of those email addresses should be on different pages but if it is not possible then on the same page would also work and if on the same page then should both pass verification.

xinaxu commented 4 years ago

If on different pages, The traditional way is to add an email output claim in self-asserted technical profiles, i.e.

You can have several self-asserted technical profiles for different pages and you can use different email claim type for different emails to collect.

From: Saurabh Srivastava notifications@github.com Sent: Wednesday, March 4, 2020 8:51 PM To: Azure-Samples/active-directory-b2c-advanced-policies active-directory-b2c-advanced-policies@noreply.github.com Cc: Xinan Xu xinaxu@microsoft.com; Mention mention@noreply.github.com Subject: Re: [Azure-Samples/active-directory-b2c-advanced-policies] Can I use two email addresses for MFA using custom policies? (#66)

Hi @xinaxuhttps://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fxinaxu&data=02%7C01%7Cxinaxu%40microsoft.com%7C892a846e498e4be3adca08d7c0c0bde4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637189806362280706&sdata=LyjILvVZftbd%2FcyNhYGuy0dbsMOboIphxB5xWhVOqsI%3D&reserved=0, Verification of those email addresses should be on different pages but if it is not possible then on the same page would also work and if on the same page then should both pass verification.

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHubhttps://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2FAzure-Samples%2Factive-directory-b2c-advanced-policies%2Fissues%2F66%3Femail_source%3Dnotifications%26email_token%3DAJOMAERGAA4Y26BX7PHC53TRF4VRVA5CNFSM4LBFJXY2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOEN3WKYI%23issuecomment-595027297&data=02%7C01%7Cxinaxu%40microsoft.com%7C892a846e498e4be3adca08d7c0c0bde4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637189806362280706&sdata=z%2Fq6tyzz9GOqlV9lwMfIAICua2aNnKBr5SzzKi1%2FXGw%3D&reserved=0, or unsubscribehttps://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fnotifications%2Funsubscribe-auth%2FAJOMAEQO3VPIG5KUC6JQ5X3RF4VRVANCNFSM4LBFJXYQ&data=02%7C01%7Cxinaxu%40microsoft.com%7C892a846e498e4be3adca08d7c0c0bde4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637189806362280706&sdata=1QVs3BI2t9cuJDHjf9POdQ4Eh16evZJ9lS4N8OcI2kk%3D&reserved=0.

1993Saurabh commented 4 years ago

If on different pages, The traditional way is to add an email output claim in self-asserted technical profiles, i.e. You can have several self-asserted technical profiles for different pages and you can use different email claim type for different emails to collect. From: Saurabh Srivastava notifications@github.com Sent: Wednesday, March 4, 2020 8:51 PM To: Azure-Samples/active-directory-b2c-advanced-policies active-directory-b2c-advanced-policies@noreply.github.com Cc: Xinan Xu xinaxu@microsoft.com; Mention mention@noreply.github.com Subject: Re: [Azure-Samples/active-directory-b2c-advanced-policies] Can I use two email addresses for MFA using custom policies? (#66) Hi @xinaxuhttps://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fxinaxu&data=02%7C01%7Cxinaxu%40microsoft.com%7C892a846e498e4be3adca08d7c0c0bde4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637189806362280706&sdata=LyjILvVZftbd%2FcyNhYGuy0dbsMOboIphxB5xWhVOqsI%3D&reserved=0, Verification of those email addresses should be on different pages but if it is not possible then on the same page would also work and if on the same page then should both pass verification. — You are receiving this because you were mentioned. Reply to this email directly, view it on GitHubhttps://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2FAzure-Samples%2Factive-directory-b2c-advanced-policies%2Fissues%2F66%3Femail_source%3Dnotifications%26email_token%3DAJOMAERGAA4Y26BX7PHC53TRF4VRVA5CNFSM4LBFJXY2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOEN3WKYI%23issuecomment-595027297&data=02%7C01%7Cxinaxu%40microsoft.com%7C892a846e498e4be3adca08d7c0c0bde4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637189806362280706&sdata=z%2Fq6tyzz9GOqlV9lwMfIAICua2aNnKBr5SzzKi1%2FXGw%3D&reserved=0, or unsubscribehttps://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fnotifications%2Funsubscribe-auth%2FAJOMAEQO3VPIG5KUC6JQ5X3RF4VRVANCNFSM4LBFJXYQ&data=02%7C01%7Cxinaxu%40microsoft.com%7C892a846e498e4be3adca08d7c0c0bde4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637189806362280706&sdata=1QVs3BI2t9cuJDHjf9POdQ4Eh16evZJ9lS4N8OcI2kk%3D&reserved=0.

Hi @xinaxu Any sample would be really helpful. If possible could you please provide one.