Workload Identities Flexible Federated Identity Credentials
In brief
The page now notes that, starting July 15, 2026, GitHub will automatically use immutable subject claims for newly created, renamed, or transferred repositories. Existing repositories will retain name-based claims unless opted in.
What Entra admins need to know
Review GitHub workload identity federation configurations to account for the different subject-claim format when repositories change.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Supported claims and operators per claim:
- Claim
subsupports operatorseqandmatches. - Claim
job_workflow_refsupports operatorseqandmatches. - Claim
repository_idsupportsoperatoroperatorseq. - Claim
repository_owner_idsupportsoperatoroperatorseq.
GitLab
@@ -83,10 +83,13 @@ These claims are required regardless of whether `sub` uses a name-based, customi Supported claims and operators per claim: -- Claim `sub` supports operators `eq` and `matches`.-- Claim `job_workflow_ref` supports operators `eq` and `matches`.-- Claim `repository_id` supports operator `eq`.-- Claim `repository_owner_id` supports operator `eq`.+- Claim `sub` supports operators `eq` and `matches` +- Claim `job_workflow_ref` supports operators `eq` and `matches`+- Claim `repository_id` supports operators `eq`+- Claim `repository_owner_id` supports operators `eq`++> [!NOTE]+> Starting July 15, 2026, GitHub applies the immutable format automatically to repositories that are created, renamed, or transferred. Existing repositories keep the name-based format until you opt in. For details, see [Immutable subject claims for GitHub Actions OIDC tokens](https://github.blog/changelog/2026-04-23-immutable-subject-claims-for-github-actions-oidc-tokens/) in the GitHub Changelog. ### [GitLab](#tab/gitlab) 