GitHub adds a proof-of-presence check before high-impact account actions
2026-09-25 · that day's edition · one of the five
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
GitHub Enterprise Cloud admins can now require an interactive re-authentication or a multi-factor challenge before members take high-impact actions on their accounts. Covered actions include creating a token, editing webhooks, changing organization security settings and viewing recovery codes, with support for pull request merges coming soon. When a policy applies, GitHub redirects the member to their identity provider to satisfy it, such as through multi-factor authentication or a fresh sign-in. The public preview is scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider, via SAML or OIDC.