A valid GitHub session may no longer be sufficient for a critical operation. The new proof of presence control can send a user back to Microsoft Entra ID for fresh authentication or a multi-factor challenge.

The short answer

QuestionAnswer
Why add this control?A stolen session cookie or long-lived token does not prove that the legitimate user is still acting.
Which actions are covered?Token creation, webhooks, security settings and access to recovery codes, among others.
Who can use it?The public preview is limited to EMU enterprises using Entra ID on GitHub Enterprise Cloud.

A valid session is no longer enough

Software supply-chain attacks often exploit stolen cookies or credentials that have already been authorised. Proof of presence inserts a check at the exact moment an action becomes dangerous. GitHub redirects to the identity provider, which can require a password, second factor, compliant device or another conditional-access policy.

A two-hour elevated window

After a successful check, GitHub permits sensitive actions in that browser for two hours, following its sudo-mode model. This compromise avoids a challenge on every click while reducing the period during which a hijacked session can change critical resources.

Start with durable, high-impact operations

Administrators should first inventory actions that can create lasting access: new tokens, webhooks, policy changes and account recovery. They should then test Entra rules with a pilot group and design a recovery procedure that does not silently bypass MFA.

A useful barrier, not a complete defence

The control does not replace short-lived tokens, event monitoring or endpoint protection. It does address a common weakness: treating possession of a session as proof that an authorised person is present. GitHub says support before pull-request merges is coming later.