Roadmap › 566869

Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings

In development Microsoft Entra AndroidDesktopiOSMacWeb
General availability
2026-08
Preview
Added
01 Jul 2026
Last modified
01 Jul 2026 23:03 UTC
First archived
25 Aug 2026
Release rings
General Availability
Clouds
Worldwide (Standard Multi-Tenant), GCC, GCC High, DoD

Description

The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will change the default rule for federatedTokenValidationPolicy to block logins where internalDomainFederation does not match UPN domain. This internalDomainFederation object is typically created automatically during federation setup with AD federation server or other IdPs.

View on microsoft.com