Tooling25 Sep 2026Lead storyThat day's edition
GitHub adds a proof-of-presence check before high-impact account actions
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
Check our sources · 1 source, 3 claimsGitHub Enterprise Cloud admins can now require an interactive re-authentication or a multi-factor challenge before members take high-impact actions on their accounts.
Covered actions include creating a token, editing webhooks, changing organization security settings and viewing recovery codes, with support for pull request merges coming soon.
When a policy applies, GitHub redirects the member to their identity provider to satisfy it, such as through multi-factor authentication or a fresh sign-in. The public preview is scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider, via SAML or OIDC.
Your reaction
One press adds one. We count a number for each notice and day, never who pressed it.
Check our sources
1 source, 3 claims. We opened the source and checked every sentence above against it.
1 Require proof of presence for high-impact actions
Open the source-
GitHub Enterprise Cloud admins can now require an interactive re-authentication or a multi-factor challenge before members take high-impact actions on their accounts
Re-authentication: The member authenticates again with your IdP. MFA: The member authenticates again and satisfies an additional multi-factor challenge. (changelog dated September 24, 2026)
-
Covered high-impact actions include creating a token, editing webhooks, changing organization security settings and viewing recovery codes, with support for pull request merges coming soon
creating a token, editing webhooks, changing organization security settings, viewing recovery codes ... Support for proof of presence before pull request merges is coming soon.
-
The public preview is scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider, via SAML or OIDC
This public preview is only scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider (IdP), via SAML or OIDC.
Nothing appears on this site that we have not opened and linked.