ESC
Type to search...

UserAuthMethod-Email.ReadWrite

Export JSON
Export CSV
Copy URL
Print
Delegated Read/Write User Scope

Allows the app to read and write the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.

In short

UserAuthMethod-Email.ReadWrite is a delegated permission in the Microsoft Graph API, grouped under the UserAuthMethod-Email category. Allows the app to read and write the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods. It grants read and write access to resources. This delegated permission requires admin consent.

Permission data: September 15, 2026 at 3:10 AM UTC
Delegated Access App-Only Access

Permission Details

Delegated Permission Admin consent required

Read and write the signed-in user's email authentication methods

Allows the app to read and write the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.

Properties

Microsoft Graph v1.0 endpoint-derived-docs

Properties is shown from stable Microsoft Graph v1.0 metadata.

Property Type Description
id String Unique identifier. Read-only.
emailMethods emailAuthenticationMethod collection The email address registered to a user for authentication.
externalAuthenticationMethods externalAuthenticationMethod collection Represents the external MFA registered to a user for authentication using an external identity provider.
fido2Methods fido2AuthenticationMethod collection Represents the FIDO2 security keys registered to a user for authentication.
methods authenticationMethod collection Represents all authentication methods registered to a user.
microsoftAuthenticatorMethods microsoftAuthenticatorAuthenticationMethod collection The details of the Microsoft Authenticator app registered to a user for authentication.
operations longRunningOperation collection Represents the status of a long-running operation, such as a password reset operation.
passwordMethods passwordAuthenticationMethod collection Represents the password registered to a user for authentication. For security, the password itself is never returned in the object, but action can be taken to reset a password.
phoneMethods phoneAuthenticationMethod collection The phone numbers registered to a user for authentication.
platformCredentialMethods platformCredentialAuthenticationMethod collection Represents a platform credential instance registered to a user on Mac OS.
softwareOathMethods softwareOathAuthenticationMethod collection The software OATH time-based one-time password (TOTP) applications registered to a user for authentication.
temporaryAccessPassMethods temporaryAccessPassAuthenticationMethod collection Represents a Temporary Access Pass registered to a user for authentication through time-limited passcodes.
windowsHelloForBusinessMethods windowsHelloForBusinessAuthenticationMethod collection Represents the Windows Hello for Business authentication method registered to a user for authentication.

JSON Representation

Microsoft Graph v1.0 endpoint-derived-docs

JSON representation is shown from stable Microsoft Graph v1.0 metadata.

JSON representation
{
  "@odata.type": "#microsoft.graph.authentication"
}

Relationships

Microsoft Graph v1.0 endpoint-derived-docs

Relationships is shown from stable Microsoft Graph v1.0 metadata.

Relationship Type Description
emailMethods emailAuthenticationMethod collection The email address registered to a user for authentication.
externalAuthenticationMethods externalAuthenticationMethod collection Represents the external MFA registered to a user for authentication using an external identity provider.
fido2Methods fido2AuthenticationMethod collection Represents the FIDO2 security keys registered to a user for authentication.
methods authenticationMethod collection Represents all authentication methods registered to a user.
microsoftAuthenticatorMethods microsoftAuthenticatorAuthenticationMethod collection The details of the Microsoft Authenticator app registered to a user for authentication.
operations longRunningOperation collection Represents the status of a long-running operation, such as a password reset operation.
passwordMethods passwordAuthenticationMethod collection Represents the password registered to a user for authentication. For security, the password itself is never returned in the object, but action can be taken to reset a password.
platformCredentialMethods platformCredentialAuthenticationMethod collection Represents a platform credential instance registered to a user on Mac OS.
phoneMethods phoneAuthenticationMethod collection The phone numbers registered to a user for authentication.
softwareOathMethods softwareOathAuthenticationMethod collection The software OATH time-based one-time password (TOTP) applications registered to a user for authentication.
temporaryAccessPassMethods temporaryAccessPassAuthenticationMethod collection Represents a Temporary Access Pass registered to a user for authentication through time-limited passcodes.
windowsHelloForBusinessMethods windowsHelloForBusinessAuthenticationMethod collection Represents the Windows Hello for Business authentication method registered to a user for authentication.
hardwareOathMethods hardwareOathAuthenticationMethod collection The hardware OATH time-based one-time password (TOTP) devices assigned to a user for authentication.
passwordlessMicrosoftAuthenticatorMethods passwordlessMicrosoftAuthenticatorAuthenticationMethod collection Represents the Microsoft Authenticator Passwordless Phone Sign-in methods registered to a user for authentication.
resourceAccountKeyAuthenticationMethods resourceAccountKeyAuthenticationMethod collection Represents the resource account key credentials registered to a user for authentication on shared devices.

Graph Methods

Delegated access App-only access
Exact Microsoft Learn match

Microsoft Graph v1.0 endpoints are mapped directly from refreshed Microsoft Learn permissions tables.

Methods
GET /me/authentication/emailMethods
GET /me/authentication/emailMethods/{emailMethods-id}
GET /users/{id | userPrincipalName}/authentication/emailMethods
GET /users/{id | userPrincipalName}/authentication/emailMethods/{emailMethods-id}
POST /users/{id | userPrincipalName}/authentication/emailMethods
PATCH /users/{id | userPrincipalName}/authentication/emailMethods/{emailMethods-id}
DELETE /me/authentication/emailMethods/{emailMethods-id}
DELETE /users/{id | userPrincipalName}/authentication/emailMethods/{emailMethods-id}
Exact Microsoft Learn match

Microsoft Graph beta endpoints are mapped directly from refreshed Microsoft Learn permissions tables.

Methods
GET /me/authentication/emailMethods
GET /me/authentication/emailMethods/{emailMethods-id}
GET /users/{id | userPrincipalName}/authentication/emailMethods
GET /users/{id | userPrincipalName}/authentication/emailMethods/{emailMethods-id}
POST /users/{id | userPrincipalName}/authentication/emailMethods
PATCH /users/{id | userPrincipalName}/authentication/emailMethods/{emailMethods-id}
DELETE /me/authentication/emailMethods/{emailMethods-id}
DELETE /users/{id | userPrincipalName}/authentication/emailMethods/{emailMethods-id}
Exact Microsoft Learn PowerShell match

Microsoft Graph PowerShell v1.0 commands are mapped directly from refreshed Microsoft Learn PowerShell snippets.

Commands
Get-MgUserAuthenticationEmailMethod /me/authentication/emailMethods
List emailMethods
Get-MgUserAuthenticationEmailMethod /me/authentication/emailMethods/{emailMethods-id}
Get emailAuthenticationMethod
New-MgUserAuthenticationEmailMethod /users/{id | userPrincipalName}/authentication/emailMethods
Create emailMethod
Remove-MgUserAuthenticationEmailMethod /me/authentication/emailMethods/{emailMethods-id}
Delete emailAuthenticationMethod
Update-MgUserAuthenticationEmailMethod /users/{id | userPrincipalName}/authentication/emailMethods/{emailMethods-id}
Update emailAuthenticationMethod
Exact Microsoft Learn PowerShell match

Microsoft Graph PowerShell beta commands are mapped directly from refreshed Microsoft Learn PowerShell snippets.

Commands
Get-MgBetaUserAuthenticationEmailMethod /me/authentication/emailMethods
List emailAuthenticationMethods
Get-MgBetaUserAuthenticationEmailMethod /me/authentication/emailMethods/{emailMethods-id}
Get emailAuthenticationMethod
New-MgBetaUserAuthenticationEmailMethod /users/{id | userPrincipalName}/authentication/emailMethods
Create emailAuthenticationMethod
Remove-MgBetaUserAuthenticationEmailMethod /me/authentication/emailMethods/{emailMethods-id}
Delete emailAuthenticationMethod
Update-MgBetaUserAuthenticationEmailMethod /users/{id | userPrincipalName}/authentication/emailMethods/{emailMethods-id}
Update emailAuthenticationMethod

Code Examples

C# / .NET SDK
Create emailMethod
// Code snippets are only available for the latest version. Current version is 5.x

// Dependencies
using Microsoft.Graph.Models;

var requestBody = new EmailAuthenticationMethod
{
	EmailAddress = "[email protected]",
};

// To initialize your graphClient, see https://learn.microsoft.com/en-us/graph/sdks/create-client?from=snippets&tabs=csharp
var result = await graphClient.Users["{user-id}"].Authentication.EmailMethods.PostAsync(requestBody);
JavaScript
Create emailMethod
const options = {
	authProvider,
};

const client = Client.init(options);

const emailAuthenticationMethod = {
  emailAddress: '[email protected]'
};

await client.api('/users/[email protected]/authentication/emailMethods')
	.post(emailAuthenticationMethod);
PowerShell
Create emailMethod
Import-Module Microsoft.Graph.Identity.SignIns

$params = @{
	emailAddress = "[email protected]"
}

New-MgUserAuthenticationEmailMethod -UserId $userId -BodyParameter $params
Python
Create emailMethod
# Code snippets are only available for the latest version. Current version is 1.x
from msgraph import GraphServiceClient
from msgraph.generated.models.email_authentication_method import EmailAuthenticationMethod
# To initialize your graph_client, see https://learn.microsoft.com/en-us/graph/sdks/create-client?from=snippets&tabs=python
request_body = EmailAuthenticationMethod(
	email_address = "[email protected]",
)

result = await graph_client.users.by_user_id('user-id').authentication.email_methods.post(request_body)

App Registration

1

Navigate to Azure Portal

Go to App registrations in Microsoft Entra admin center

2

Add API Permission

Select your app → API permissions → Add a permission → Microsoft Graph

3

Select Permission Type

Choose Delegated permissions and search for UserAuthMethod-Email.ReadWrite

4

Grant Admin Consent

This delegated permission requires admin consent.

Frequently asked questions

What is the UserAuthMethod-Email.ReadWrite Microsoft Graph permission?

UserAuthMethod-Email.ReadWrite is a delegated permission in the Microsoft Graph API, grouped under the UserAuthMethod-Email category. Allows the app to read and write the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods. It grants read and write access to resources. This delegated permission requires admin consent. It is mapped to the Microsoft Graph authentication resource type. 16 documented Microsoft Graph REST methods require it. 10 Microsoft Graph PowerShell commands are documented for it.

Is UserAuthMethod-Email.ReadWrite an application or a delegated permission?

UserAuthMethod-Email.ReadWrite is a delegated permission only. It grants access on behalf of a signed-in user and cannot be used for app-only access.

Does UserAuthMethod-Email.ReadWrite require admin consent?

This delegated permission requires admin consent.

What is the permission ID (GUID) for UserAuthMethod-Email.ReadWrite?

For UserAuthMethod-Email.ReadWrite, the delegated (OAuth2 scope) ID is 696aa421-62dc-4c99-be16-015b23444089. These are the real Microsoft Graph identifiers and can be used directly in an app registration manifest.