Proof of Presence (PoP) – Interactive re-authentication for high-impact actions (Entra IdP) [Public Preview]
- Ngôn ngữ chính
- Không có dữ liệu ngôn ngữ
- Star
- 8.9k
- Fork
- 1.8k
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
### Value Prop
Enterprises using Microsoft Entra ID can now require users to complete a fresh, interactive MFA challenge through their own identity provider before performing sensitive actions on GitHub. Re-authentication is driven by your existing Entra ID configuration—whether SAML or OIDC—so there's no new tooling to set up and no changes to how your teams authenticate day-to-day. This gives security and compliance teams stronger assurance that a real, authorized person is behind every high-impact operation.
### Expected Outcome
Long-lived session tokens are a known vector for supply-chain attacks, and organizations subject to strict compliance requirements need more than a valid session cookie to authorize consequential actions. By tying re-authentication directly to the moment of action—and routing the challenge through the customer's own IdP—GitHub helps enterprises reduce exposure from compromised credentials while satisfying regulatory and internal security mandates. The result is a tighter, verifiable link between identity and action across your GitHub environment.
Hướng dẫn đóng góp
Hướng nghiên cứu
The issue describes Proof of Presence re-authentication through Microsoft Entra ID using SAML or OIDC, but names no repository files, tests, or entry points. Start by identifying where high-impact actions and enterprise identity-provider authentication are implemented; done means supporting a fresh interactive MFA challenge before sensitive actions.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- azure
- Lĩnh vực
- authentication, security
- Loại issue
- Tính năng
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Cần làm rõ
- Mức phù hợp với người mới
- 20/100