github / github/roadmap

Proof of Presence (PoP) – Interactive re-authentication for high-impact actions (Entra IdP) [Public Preview]

未关闭
#1,319 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Enterprise GHES 3.23 Public Preview
主要语言
没有语言数据
星标
8.9k
派生
1.8k
PR 合并指标
30 天内没有已合并 PR

描述

### Value Prop
Enterprises using Microsoft Entra ID can now require users to complete a fresh, interactive MFA challenge through their own identity provider before performing sensitive actions on GitHub. Re-authentication is driven by your existing Entra ID configuration—whether SAML or OIDC—so there's no new tooling to set up and no changes to how your teams authenticate day-to-day. This gives security and compliance teams stronger assurance that a real, authorized person is behind every high-impact operation.

### Expected Outcome
Long-lived session tokens are a known vector for supply-chain attacks, and organizations subject to strict compliance requirements need more than a valid session cookie to authorize consequential actions. By tying re-authentication directly to the moment of action—and routing the challenge through the customer's own IdP—GitHub helps enterprises reduce exposure from compromised credentials while satisfying regulatory and internal security mandates. The result is a tighter, verifiable link between identity and action across your GitHub environment.

贡献指南

打开贡献指南

调研方向

该 issue 描述了通过 Microsoft Entra ID 使用 SAML 或 OIDC 进行 Proof of Presence 重新认证,但没有指出任何仓库文件、测试或入口点。首先确定高影响操作和企业身份提供商认证的实现位置;在敏感操作之前支持新的交互式 MFA challenge,即表示完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
azure
领域
authentication, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
冷清
描述清晰度
需要澄清
新手友好度
20/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。