A cloud-based identity and access management service for securing user authentication and resource access
Common Auth API to collect MFA phone number
Hello MS Team,
We are exploring the possibility of leveraging the MFA phone number stored in Azure AD B2C as an additional authentication factor within our application.
Could you please help us understand how the Common Auth API works in this scenario? Specifically:
- How does the API retrieve or access the MFA phone number information?
- Are there any prerequisites, limitations, or security considerations that we should be aware of?
We previously evaluated retrieving the MFA phone number directly from Azure AD B2C and concluded that the number used for MFA is not externally accessible without significant changes to the existing implementation. Given that understanding, we would appreciate any additional details on how the Common Auth API addresses this challenge and what level of effort would be required from our side.