microsoftgraph / microsoftgraph/entra-powershell

🚀 Token binding + Web Account Manager support in Entra PowerShell

Open
#1,385 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Feature Graph PowerShell Dependency P0 ToTriage
Dominant language
PowerShell
Stars
213
Forks
46
PR merge metrics
No merged PRs in 30d

Description

What is Access token proof of possession?

Access Token Proof of Possession (AT PoP) adds security by requiring the client to prove it holds a specific cryptographic key linked to the access token. This prevents stolen tokens from being used without the matching private key, reducing the risk of token theft and misuse.

Current Challenge:

Feature is not currently supported in Entra PowerShell and Microsoft Graph PowerShell SDK.

Why it matters:

Access Token Proof of Possession (AT PoP) strengthens security by preventing token misuse without the matching private key. It adds extra protection to MFA scenarios and increases trust in the authentication process by making token-related attacks harder to carry out.

Roadmap tracker:

This issue serves as a roadmap tracker.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the Microsoft Graph project 69 roadmap linked in the issue and compare its scope with the Entra PowerShell and Microsoft Graph PowerShell SDK support gap described here. Done would mean defining and implementing token binding and Web Account Manager support, but the issue does not identify files, tests, or a concrete implementation path.

Written by the indexing model from the issue text.

Assessment

Tech stack
powershell
Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.