Today ainotis

Tooling25 Sep 2026Lead storyThat day's edition

GitHub adds a proof-of-presence check before high-impact account actions

The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.

Check our sources · 1 source, 3 claims
Quoted from github.blog on 2026-09-25: Re-authentication: The member authenticates again with your IdP. MFA: The member authenticates… Quoted from github.blog, checked 2026-09-25. “ Re-authentication: The member authenticates again with your IdP. MFA: The member authenticates again and satisfies an additional multi-factor challenge. (changelog dated September 24, 2026)” quoted from github.blog · checked 2026-09-25
github.blog, quoted / Require proof of presence for high-impact actions · source · Quoted under the quotation exception; no licence granted

GitHub Enterprise Cloud admins can now require an interactive re-authentication or a multi-factor challenge before members take high-impact actions on their accounts.

Covered actions include creating a token, editing webhooks, changing organization security settings and viewing recovery codes, with support for pull request merges coming soon.

When a policy applies, GitHub redirects the member to their identity provider to satisfy it, such as through multi-factor authentication or a fresh sign-in. The public preview is scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider, via SAML or OIDC.

Your reaction

One press adds one. We count a number for each notice and day, never who pressed it.

Check our sources

1 source, 3 claims. We opened the source and checked every sentence above against it.

1 Require proof of presence for high-impact actionsGitHub · 24 Sep 2026 · 3 claims Open the source
  1. GitHub Enterprise Cloud admins can now require an interactive re-authentication or a multi-factor challenge before members take high-impact actions on their accounts

    Re-authentication: The member authenticates again with your IdP. MFA: The member authenticates again and satisfies an additional multi-factor challenge. (changelog dated September 24, 2026)
  2. Covered high-impact actions include creating a token, editing webhooks, changing organization security settings and viewing recovery codes, with support for pull request merges coming soon

    creating a token, editing webhooks, changing organization security settings, viewing recovery codes ... Support for proof of presence before pull request merges is coming soon.
  3. The public preview is scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider, via SAML or OIDC

    This public preview is only scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider (IdP), via SAML or OIDC.

Nothing appears on this site that we have not opened and linked.

Filed under