Proof of Presence (PoP) – Interactive re-authentication for high-impact actions (Entra IdP) [Public Preview]
- 主要言語
- 言語のデータがありません
- スター
- 8.9k
- フォーク
- 1.8k
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
### Value Prop
Enterprises using Microsoft Entra ID can now require users to complete a fresh, interactive MFA challenge through their own identity provider before performing sensitive actions on GitHub. Re-authentication is driven by your existing Entra ID configuration—whether SAML or OIDC—so there's no new tooling to set up and no changes to how your teams authenticate day-to-day. This gives security and compliance teams stronger assurance that a real, authorized person is behind every high-impact operation.
### Expected Outcome
Long-lived session tokens are a known vector for supply-chain attacks, and organizations subject to strict compliance requirements need more than a valid session cookie to authorize consequential actions. By tying re-authentication directly to the moment of action—and routing the challenge through the customer's own IdP—GitHub helps enterprises reduce exposure from compromised credentials while satisfying regulatory and internal security mandates. The result is a tighter, verifiable link between identity and action across your GitHub environment.
コントリビューションガイド
調査の方向性
The issue describes Proof of Presence re-authentication through Microsoft Entra ID using SAML or OIDC, but names no repository files, tests, or entry points. Start by identifying where high-impact actions and enterprise identity-provider authentication are implemented; done means supporting a fresh interactive MFA challenge before sensitive actions.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- azure
- 領域
- authentication, security
- issue の種類
- 機能追加
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 静か
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 20/100