Queries the global multi-factor authentication (MFA) configuration.
Operation description
When username-password logon is enabled, you can retrieve the global MFA verification policy for user logon.
This topic provides an example on how to query the global MFA verification policy for CloudSSO users in the directory u-00q8wbq42wiltcrk****.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
cloudsso:GetMFAAuthenticationSettingInfo |
get |
*Directory
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| DirectoryId |
string |
Yes |
The directory ID. |
u-00q8wbq42wiltcrk**** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID. |
95D3B107-DA80-5B34-A3D0-9E82F8F0DA0E |
| MFAAuthenticationSettingInfo |
object |
The global MFA verification configuration. |
|
| MfaAuthenticationAdvanceSettings |
string |
The global MFA verification policy. Valid values:
|
OnlyRiskyLogin |
| OperationForRiskLogin |
string |
The MFA verification policy for unusual logon attempts. Valid values:
Note
This parameter is displayed only when MfaAuthenticationAdvanceSettings is set to Byuser or OnlyRiskyLogin. |
EnforceVerify |
| AllowedVerificationTypes |
array |
||
|
string |
Examples
Success response
JSON format
{
"RequestId": "95D3B107-DA80-5B34-A3D0-9E82F8F0DA0E",
"MFAAuthenticationSettingInfo": {
"MfaAuthenticationAdvanceSettings": "OnlyRiskyLogin",
"OperationForRiskLogin": "EnforceVerify",
"AllowedVerificationTypes": [
""
]
}
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.