A valid GitHub session may no longer be sufficient for a critical operation. The new proof of presence control can send a user back to Microsoft Entra ID for fresh authentication or a multi-factor challenge.
The short answer
| Question | Answer |
|---|---|
| Why add this control? | A stolen session cookie or long-lived token does not prove that the legitimate user is still acting. |
| Which actions are covered? | Token creation, webhooks, security settings and access to recovery codes, among others. |
| Who can use it? | The public preview is limited to EMU enterprises using Entra ID on GitHub Enterprise Cloud. |
A valid session is no longer enough
Software supply-chain attacks often exploit stolen cookies or credentials that have already been authorised. Proof of presence inserts a check at the exact moment an action becomes dangerous. GitHub redirects to the identity provider, which can require a password, second factor, compliant device or another conditional-access policy.
A two-hour elevated window
After a successful check, GitHub permits sensitive actions in that browser for two hours, following its sudo-mode model. This compromise avoids a challenge on every click while reducing the period during which a hijacked session can change critical resources.
Start with durable, high-impact operations
Administrators should first inventory actions that can create lasting access: new tokens, webhooks, policy changes and account recovery. They should then test Entra rules with a pilot group and design a recovery procedure that does not silently bypass MFA.
A useful barrier, not a complete defence
The control does not replace short-lived tokens, event monitoring or endpoint protection. It does address a common weakness: treating possession of a session as proof that an authorised person is present. GitHub says support before pull-request merges is coming later.




Join the discussion
Comments
Loading comments…