All stories
Security Worldwide

GitHub adds an extra check for sensitive actions.

Eligible enterprise administrators can require a fresh sign-in or MFA before members create tokens or change security settings.

Source

What happened

GitHub has opened a public preview of Proof of Presence for some GitHub Enterprise Cloud customers. When enabled, it sends a member to the company's identity provider for re-authentication before high-impact actions such as creating a token, editing webhooks or changing organization security settings.

SIGNAL / SIGNAL analysis

What changes for you

A stolen browser session alone may no longer be enough to make those changes in an eligible enterprise. Administrators can choose a fresh sign-in or an MFA challenge according to their identity-provider policy.

What to keep in mind

This is a public preview, not a default protection for every GitHub account. GitHub says it is currently limited to Enterprise Managed Users enterprises on github.com or GHEC-DR using Microsoft Entra ID SSO via SAML or OIDC. A successful challenge lasts for the two-hour sudo-mode session; protection for pull-request merges is still planned, not available now.

What you can do

If you administer an eligible enterprise, review the Proof of Presence setting and your Entra ID authentication policy before enabling it. Other users should not assume this preview protects their account.

Source

github.blog

Public preview. Company claims are not independent test results.

No correction recorded for this article.

Report an error