github GitHub Changelog ·

GitHub Enterprise Cloud introduces proof of presence for high-impact actions

securitypreviewarchitect
feature

GitHub Enterprise Cloud now supports requiring interactive re-authentication or multi-factor challenges for high-impact actions, expanding sudo mode for enhanced enterprise security. This public preview feature helps prevent supply chain attacks stemming from stolen session cookies or tokens by verifying a real, authorized person is acting. It is currently scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider. The feature also assists regulated customers in meeting compliance requirements for fresh authentication.

Features (1) ›
  • Require proof of presence for high-impact actions

    GitHub Enterprise Cloud now allows administrators to mandate interactive re-authentication or a multi-factor challenge before members can perform high-impact actions such as creating tokens or changing security settings. This public preview feature enhances security by validating the user's presence at the moment of the action, utilizing the enterprise's configured IdP policies via SAML or OIDC.

Read the original announcement →

https://github.blog/changelog/2026-09-24-require-proof-of-presence-for-high-impact-actions

Related releases