The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will change the default rule for federatedTokenValidationPolicy to block logins where internalDomainFederation does not match UPN domain. This internalDomainFederation object is typically created automatically during federation setup with AD federation server or other IdPs.
Roadmap › 566869
Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings
- General availability
- 2026-08
- Preview
- —
- Added
- 01 Jul 2026
- Last modified
- 01 Jul 2026 23:03 UTC
- First archived
- 25 Aug 2026
- Release rings
- General Availability
- Clouds
- Worldwide (Standard Multi-Tenant), GCC, GCC High, DoD