github / github/roadmap

Proof of Presence (PoP) – Interactive re-authentication for high-impact actions (Entra IdP) [Public Preview]

オープン
#1,319 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
Enterprise GHES 3.23 Public Preview
主要言語
言語のデータがありません
スター
8.9k
フォーク
1.8k
PR マージ指標
30日以内にマージされた PR はありません

説明

### Value Prop
Enterprises using Microsoft Entra ID can now require users to complete a fresh, interactive MFA challenge through their own identity provider before performing sensitive actions on GitHub. Re-authentication is driven by your existing Entra ID configuration—whether SAML or OIDC—so there's no new tooling to set up and no changes to how your teams authenticate day-to-day. This gives security and compliance teams stronger assurance that a real, authorized person is behind every high-impact operation.

### Expected Outcome
Long-lived session tokens are a known vector for supply-chain attacks, and organizations subject to strict compliance requirements need more than a valid session cookie to authorize consequential actions. By tying re-authentication directly to the moment of action—and routing the challenge through the customer's own IdP—GitHub helps enterprises reduce exposure from compromised credentials while satisfying regulatory and internal security mandates. The result is a tighter, verifiable link between identity and action across your GitHub environment.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

The issue describes Proof of Presence re-authentication through Microsoft Entra ID using SAML or OIDC, but names no repository files, tests, or entry points. Start by identifying where high-impact actions and enterprise identity-provider authentication are implemented; done means supporting a fresh interactive MFA challenge before sensitive actions.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
azure
領域
authentication, security
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
静か
明瞭さ
説明が足りない
初心者へのやさしさ
20/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。