NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #18 most downloaded on NuGet
Provides APIs for authenticating to Microsoft Entra ID
Last release 5 months ago
15 Apr 2026
Release timing varies
gaps range from 1 weeks to 4 months
Nearly every release is documented
notes for 42 of 44 stable releases
1 version withdrawn
withdrawn after publishing
127 years old
45 releases · first in 1900
…TypeForwardedTo attributes. This is a non-breaking change — existing code continues to work transparently. The library's version number now aligns wit…
Azure.Identity types have been moved to Azure.Core and are now available through TypeForwardedTo attributes. This is a non-breaking change — existing code continues to work transparently. The library's version number now aligns with that of Azure.Core. See the Migration Guide for details.One column per quarter.
Added a JSON schema segment to the NuGet package that provides IntelliSense and validation for Azure.Identity credential configuration in appsettings.
appsettings.json.AddAzureClient, AddKeyedAzureClient, and WithAzureCredential return type changed from IHostApplicationBuilder to IClientBuilder to align with the IClientBuilder composition change in System.ClientModel.Added support in ClientCertificateCredential to specify a path in the form of cert:/StoreLocation/StoreName/Thumbprint to refer to a certificate in th
ClientCertificateCredential to specify a path in the form of cert:/StoreLocation/StoreName/Thumbprint to refer to a certificate in the platform certificate store - such as the Windows Certificate Store on Windows, and the KeyChain on MacOS - instead of a file on disk. For example to load a certificate from the "My" store in the "CurrentUser" location use the path cert:/CurrentUser/My/E661583E8FABEF4C0BEF694CBC41C28FB81CD870 (A community contribution, courtesy of fowl2).Microsoft.Identity.Client and Microsoft.Identity.Client.Extensions.Msal dependencies to version 4.83.1.Added experimental Microsoft.Extensions.Configuration and Microsoft.Extensions.DependencyInjection integration for Azure SDK clients. For details, see
Added experimental Microsoft.Extensions.Configuration and Microsoft.Extensions.DependencyInjection integration for Azure SDK clients. For details, see the Configuration and Dependency Injection documentation.
The WorkloadIdentityCredentialOptions.IsAzureProxyEnabled property, which enables Azure Kubernetes token proxy mode, is only available in beta releases of this package.
AzureDeveloperCliCredential now parses JSON error output from azd auth token to extract clean error messages instead of including raw JSON in exceptions. Error messages like {"type":"consoleMessage","data":{"message":"ERROR: fetching token: ..."}} are now displayed as ERROR: fetching token: ....
Nothing published for this version
Updated Microsoft.Identity.Client and Microsoft.Identity.Client.Extensions.Msal dependencies to version 4.78.0.
Microsoft.Identity.Client and Microsoft.Identity.Client.Extensions.Msal dependencies to version 4.78.0.Deprecated BrowserCustomizationOptions.UseEmbeddedWebView property. This option requires additional dependencies on Microsoft.Identity.Client.Desktop…
WithTenantId instead of WithTenantIdFromAuthority to prevent malformed Uris to the authority.BrowserCustomizationOptions.UseEmbeddedWebView property. This option requires additional dependencies on Microsoft.Identity.Client.Desktop and is no longer supported. Consider using brokered authentication instead.Added a new DefaultAzureCredential constructor that accepts a custom environment variable name for credential configuration. This provides flexibility
DefaultAzureCredential constructor that accepts a custom environment variable name for credential configuration. This provides flexibility beyond the default AZURE_TOKEN_CREDENTIALS environment variable. The constructor accepts any environment variable name and uses the same credential selection logic as the existing AZURE_TOKEN_CREDENTIALS processing.DefaultAzureCredential.DefaultEnvironmentVariableName constant property that returns "AZURE_TOKEN_CREDENTIALS" for convenience when referencing the default environment variable name.AzureCliCredential, AzurePowerShellCredential, and AzureDeveloperCliCredential now throw an AuthenticationFailedException when the TokenRequestContext includes claims, as these credentials do not support claims challenges. The exception message includes guidance for handling such scenarios.AZURE_TOKEN_CREDENTIALS or the equivalent custom environment variable is configured to ManagedIdentityCredential, the DefaultAzureCredential does not issue a probe request and performs retries with exponential backoff.AzureDeveloperCliCredential hanging when the AZD_DEBUG environment variable is set by adding the --no-prompt flag to prevent interactive prompts (#52005).BrokerCredential is now included in the chain when AZURE_TOKEN_CREDENTIALS is set to dev.DefaultAzureCredential that caused the credential chain to be constructed incorrectly when using AZURE_TOKEN_CREDENTIALS in combination with DefaultAzureCredentialOptions.BrokerCredential is now always included in the DefaultAzureCredential chain. If the Azure.Identity.Broker package is not referenced, an exception will be thrown when GetToken is called, making its behavior consistent with the rest of the credentials in the chain.Microsoft.Identity.Client dependency to version 4.76.0.Microsoft.Identity.Client.Extensions.Msal dependency to version 4.76.0.Deprecated SharedTokenCacheCredential. The supporting credential (SharedTokenCacheCredential) was a legacy mechanism for authenticating clients using…
SharedTokenCacheCredential. The supporting credential (SharedTokenCacheCredential) was a legacy mechanism for authenticating clients using credentials provided to Visual Studio. For brokered authentication, consider using InteractiveBrowserCredential instead. The following changes have been made:
SharedTokenCacheCredential class is marked as [Obsolete] and [EditorBrowsable(EditorBrowsableState.Never)]SharedTokenCacheCredentialOptions class is marked as [Obsolete] and [EditorBrowsable(EditorBrowsableState.Never)]DefaultAzureCredentialOptions.ExcludeSharedTokenCacheCredential property is marked as [Obsolete] and [EditorBrowsable(EditorBrowsableState.Never)]SharedTokenCacheUsername property is marked as [Obsolete] and [EditorBrowsable(EditorBrowsableState.Never)]SharedTokenCacheCredential is no longer included in the DefaultAzureCredential authentication flowAdditionallyAllowedTenants values which will now be matched against tenant IDs without case sensitivity, making the authentication more resilient to case differences in tenant IDs returned from WWW-Authenticate challenges (#51693).BrokerAuthenticationCredential has been renamed as BrokerCredential.
Added the EditorBrowsable(Never) attribute to property VisualStudioCodeTenantId as TenantId is preferred. The VisualStudioCodeTenantId property exists only to provide backwards compatibility.
Updated Microsoft.Identity.Client dependency to version 4.73.1 to take a security fix.
Microsoft.Identity.Client dependency to version 4.73.1 to take a security fix.Added support in AzurePowerShellCredential for the Az.Accounts 5.0.0+ (Az 14.0.0+) breaking change where Get-AzAccessToken returns PSSecureAccessToken…
AzurePowerShellCredential for the Az.Accounts 5.0.0+ (Az 14.0.0+) breaking change where Get-AzAccessToken returns PSSecureAccessToken with a SecureString Token property instead of plaintext.Removed references to Username, Password, AZURE_USERNAME, and AZURE_PASSWORD in XML comments from EnvironmentCredentialOptions and EnvironmentCredenti
Username, Password, AZURE_USERNAME, and AZURE_PASSWORD in XML comments from EnvironmentCredentialOptions and EnvironmentCredential due to lack of MFA support. See MFA enforcement details.AZURE_USERNAME and AZURE_PASSWORD as obsolete due to lack of MFA support. See MFA enforcement details.AZURE_TOKEN_CREDENTIALS environment variable to DefaultAzureCredential, which allows for choosing between 'deployed service' and 'developer tools' credentials. Valid values are 'dev' for developer tools and 'prod' for deployed service.Fixed an issue where setting DefaultAzureCredentialOptions.TenantId twice throws an InvalidOperationException
DefaultAzureCredentialOptions.TenantId twice throws an InvalidOperationException (#47035)ManagedIdentityCredential does not honor the CancellationToken passed to GetToken and GetTokenAsync. (#47156)DefaultAzureCredential would not fall through to the next credential in the chain under certain exception conditions.ManagedIdentityCredential when used in a ChainedTokenCredential where the invalid json responses do not fall through to the next credential in the chain. (#47470)Fixed a regression that prevented ManagedIdentityCredential from attempting to detect if Workload Identity is enabled in the current environment. #466
ManagedIdentityCredential from attempting to detect if Workload Identity is enabled in the current environment. #46653DefaultAzureCredential from progressing past ManagedIdentityCredential in some scenarios where the identity was not available. #46709Previously, if a clientID or ResourceID was specified for Cloud Shell managed identity, which is not supported, the clientID or resourceID would be si
ManagedIdentityCredential now supports specifying a user-assigned managed identity by object ID.DefaultAzureCredential attempts to authenticate with the MangagedIdentityCredential and it receives either a failed response that is not json, it will now fall through to the next credential in the chain. #45184AzurePipelinesCredential so it doesn't result in a redirect response when an invalid system access token is provided.AzureEventSourceListener. Previously, the log level was always set to Microsoft.Identity.Client.LogLevel.Info.AzurePowerShellCredential now utilizes the AsSecureString parameter to Get-AzAccessToken for version 2.17.0 and greater of the Az.Accounts module.AzurePipelinesCredential.Nothing published for this version
Added AzurePipelinesCredential for authenticating with Azure Pipelines service connections.
AzurePipelinesCredential for authenticating with Azure Pipelines service connections.OnBehalfOfCredential now supports client assertion callbacks for acquiring tokens on behalf of a user.ClientAssertionCredentialOptions now supports TokenCachePersistenceOptions for configuring token cache persistence.### Bugs Fixed - Managed identity bug fixes.
Fixed a regression in DefaultAzureCredential probe request behavior for IMDS managed identity environments. #43796
DefaultAzureCredential probe request behavior for IMDS managed identity environments. #43796Fixed an issue which caused claims to be incorrectly added to confidential client credentials such as DeviceCodeCredential #43468
DeviceCodeCredential #43468Updated Microsoft.Identity.Client and related dependencies to version 4.60.3
AzurePowerShellCredential now handles the case where it falls back to legacy PowerShell without relying on the error message string.
AzurePowerShellCredential now handles the case where it falls back to legacy PowerShell without relying on the error message string.DefaultAzureCredential now sends a probe request with no retries for IMDS managed identity environments to avoid excessive retry delays when the IMDS endpoint is not available. This should improve credential chain resolution for local development scenarios. See BREAKING_CHANGES.md.Code | Docs
Support: Active
App Configuration Provider
Microsoft.Extensions.Configuration.AzureAppConfiguration
One of Azure.Identity's dependencies, Microsoft.Identity.Client, inadvertently added a dependency to WindowsForms when targeting netX.0-windows instea
WindowsForms when targeting netX.0-windows instead of netX.0 in version 4.56.0. An additional installation of .NET Desktop Runtime may be necessary. Manually adding a reference to the latest Microsoft.Identity.Client will remove the need for the .NET Desktop Runtime. #44232ActivitySource is stable and no longer requires the Experimental feature-flag.ManagedIdentityCredential will now correctly retry when the instance metadata endpoint returns a 410 response. #28568
ManagedIdentityCredential will now correctly retry when the instance metadata endpoint returns a 410 response. #28568Bug fixes for development time credentials.
ManagedIdentityCredential will fall through to the next credential in the chain in the case that Docker Desktop returns a 403 response when attempting
ManagedIdentityCredential will fall through to the next credential in the chain in the case that Docker Desktop returns a 403 response when attempting to access the IMDS endpoint. #38218Added BrowserCustomization property to InteractiveBrowserCredential to enable web view customization for interactive authentication.
BrowserCustomization property to InteractiveBrowserCredential to enable web view customization for interactive authentication.Changed visibility of all environment variable based properties on EnvironmentCredentialOptions to internal. These options are again only configurable
EnvironmentCredentialOptions to internal. These options are again only configurable via environment variables.Fixed error message parsing in AzurePowerShellCredential which would misinterpret Microsoft Entra ID errors with the need to install PowerShell. #3199
AzurePowerShellCredential which would misinterpret Microsoft Entra ID errors with the need to install PowerShell. #31998ManagedIdentityCredential. [#32498])(https://github.com/Azure/azure-sdk-for-net/issues/32498)Fixed an issue when using ManagedIdentityCredential in combination with authorities other than Azure public cloud that resulted in a incorrect instanc
ManagedIdentityCredential in combination with authorities other than Azure public cloud that resulted in a incorrect instance metadata validation error. #32498Fixed error message parsing in AzureCliCredential which would misinterpret Microsoft Entra ID errors with the need to login with az login. #26894, #29
AzureCliCredential which would misinterpret Microsoft Entra ID errors with the need to login with az login. #26894, #29109ManagedIdentityCredential will no longer fail when a response received from the endpoint is invalid JSON. It now treats this scenario as if the credential is unavailable. #30467, #32061Added AdditionallyAllowedTenants to the following credential options to force explicit opt-in behavior for multi-tenant authentication:
AdditionallyAllowedTenants to the following credential options to force explicit opt-in behavior for multi-tenant authentication:
AuthorizationCodeCredentialOptionsAzureCliCredentialOptionsAzurePowerShellCredentialOptionsClientAssertionCredentialOptionsClientCertificateCredentialOptionsClientSecretCredentialOptionsDefaultAzureCredentialOptionsOnBehalfOfCredentialOptionsUsernamePasswordCredentialOptionsVisualStudioCodeCredentialOptionsVisualStudioCredentialOptionsTenantId to DefaultAzureCredentialOptions to avoid having to set InteractiveBrowserTenantId, SharedTokenCacheTenantId, VisualStudioCodeTenantId, and VisualStudioTenantId individually.user_impersonation #30647AuthenticationFailedException if the requested tenant ID doesn't match the credential's tenant ID, and is not included in the AdditionallyAllowedTenants option. Applications must now explicitly add additional tenants to the AdditionallyAllowedTenants list, or add '*' to list, to enable acquiring tokens from tenants other than the originally specified tenant ID. See BREAKING_CHANGES.md.ManagedIdentityCredential token caching added in 1.7.0-beta.1 has been removed from this release and will be added back in 1.8.0-beta.1Fixed AZURE_REGIONAL_AUTHORITY_NAME support in ClientCertificateCredential #29112
AZURE_REGIONAL_AUTHORITY_NAME support in ClientCertificateCredential #29112SharedTokenCacheCredential default behavior #28029TokenCacheRefreshArgs and EnvironmentCredential (Community contributions, courtesy of pmaytak and goenning)Thank you to our developer community members who helped to make Azure Identity better with their contributions to this release:
Added a new property under the Diagnostics options available on TokenCredentialOptions and all sub-types. If set to true, we try to log the account id
Diagnostics options available on TokenCredentialOptions and all sub-types. If set to true, we try to log the account identifiers by parsing the received access token. The account identifiers we try to log are the:
ManagedIdentityCredential now attempts to use the newest "2019-08-01" api version for App Service Managed Identity sources. The newer API version will be used if the IDENTITY_ENDPOINT and IDENTITY_HEADER environment variables are set.OnBehalfOfCredential when the SendCertificateChain option is set. #27679The AllowMultiTenantAuthentication option has been removed and the default behavior is now as if it were true. The multi-tenant discovery feature can
AllowMultiTenantAuthentication option has been removed and the default behavior is now as if it were true. The multi-tenant discovery feature can be totally disabled by either setting an AppContext switch named "Azure.Identity.DisableTenantDiscovery" to true or by setting the environment variable "AZURE_IDENTITY_DISABLE_MULTITENANTAUTH" to "true".IsPIILoggingEnabled property from TokenCredentialOptions, similar functionality is planned to be added to TokenCredentialOptions.Diagnostics in a later release.RegionalAuthority from ClientCertificateCredentialOptions and ClientSecretCredentialOptions, along with the RegionalAuthority type.TokenCacheDetails to TokenCacheData.TokenCacheNotificationDetails to TokenCacheRefreshArgs.CacheBytes property on TokenCacheData to be readonly and a required constructor parameter.AuthorizationCodeCredential not specifying correct redirectUrl (Issue #24183)Fixed issue resulting in duplicate event source names when executing in Azure Functions
By default, the MSAL Public Client Client Capabilities are populated with "CP1" to enable support for Continuous Access Evaluation (CAE). This indicat
AppContext switch named "Azure.Identity.DisableCP1" to true or by setting the environment variable;
"AZURE_IDENTITY_DISABLE_CP1" to "true". Note: AppContext switches can also be configured via configuration like below:<ItemGroup>
<RuntimeHostConfigurationOption Include="Azure.Identity.DisableCP1" Value="true" />
</ItemGroup>
Code | Docs
Support: Active
Communication Common
Azure.Communication.Common
Added support for Service Fabric managed identity authentication to ManagedIdentityCredential.
ManagedIdentityCredential.ManagedIdentityCredential.ProcessRunner causing VisualStudioCredential and AzureCliCredential to fail intermittently (#16211)VisualStudioCodeCredential to raise CredentialUnavailableException when reading from VS Code's stored secret (#16795)VisualStudioCodeCredential using invalid authentication data when no user is signed in to Visual Studio Code (#15870)ProcessRunner causing AzureCliCredential and VisualStudioCredential to fail due to timeout (#14691, 14207)AzureCliCredential incorrectly parsing expires on property returned from az account get-access-token (#15801)DeviceCodeCredential and InteractiveBrowserCredential to improperly authenticate to the home tenant for silent authentication calls after initial authentication (#13801)SharedTokenCacheCredential on Linux (#12939)IncludeX5CCliamHeader on ClientCertificateCredentialOptions to SendCertificateChainAuthenticationRecordAuthenticationRequiredExceptionClientSecretCredentialOptions and ClientSecretCredential constructor overloads accepting this typeUsernamePasswordCredentialOptions and UsernamePasswordCredential constructor overloads accepting this typeEnablePersistentCache and AllowUnprotectedCache from ClientCertificateCredentialOptions, DeviceCodeCredentialOptions and InteractiveBrowserCredentialOptionsAuthenticationRecord and DisableAutomaticAuthentication from DeviceCodeCredentialOptions and InteractiveBrowserCredentialOptionsAllowUnencryptedCacheand AuthenticationRecord from SharedTokenCacheCredentialOptionsAuthenticate and AuthenticateAsync from DeviceCodeCredential, InteractiveBrowserCredential and UsernamePasswordCredentialFixed issue with DefaultAzureCredential incorrectly catching AuthenticationFailedException (Issue #14974)
Fixed issue with InteractiveBrowserCredential not specifying correct redirectUrl (Issue #13940)
InteractiveBrowserCredential not specifying correct redirectUrl (Issue #13940)Bug in TaskExtensions.EnsureCompleted method that causes it to unconditionally throw an exception in the environments with synchronization context
Removing Application Authentication APIs for GA release. These will be reintroduced in 1.3.0-preview.
AuthenticationRecordAuthenticationRequiredExceptionClientCertificateCredentialOptions and ClientCertificateCredential constructor overloads accepting this typeClientSecretCredentialOptions and ClientSecretCredential constructor overloads accepting this typeDeviceCodeCredentialOptions and DeviceCodeCredential constructor overloads accepting this typeInteractiveBrowserCredentialOptions and InteractiveBrowserCredential constructor overloads accepting this typeUsernamePasswordCredentialOptions and UsernamePasswordCredential constructor overloads accepting this typeAuthenticate and AuthenticateAsync from DeviceCodeCredentialAuthenticate and AuthenticateAsync from InteractiveBrowserCredentialAuthenticate and AuthenticateAsync from UsernamePasswordCredentialAllowUnencryptedCacheand AuthenticationRecord from SharedTokenCacheCredentialOptionsFixed UsernamePasswordCredential constructor parameter mishandling
UsernamePasswordCredential constructor parameter mishandlingManagedIdentityCredential endpoint discovery to avoid throwingManagedIdentityCredential to raise CredentialUnavailableException on 400 return from the service where no identity has been assignedDefaultAzureCredential to more easily root cause failuresUpdate SharedTokenCacheCredential to filter accounts by tenant id
SharedTokenCacheCredential to filter accounts by tenant id
SharedTokenCacheCredentialOptions class with properties TenantId and UsernameSharedTokenCacheCredential which accepts SharedTokenCacheCredentialOptionsSharedTokenCacheTenantId to DefaultAzureCredentialOptionsDefaultAzureCredential, InteractiveBrowserCredential, and SharedTokenCacheCredentialInteractiveBrowserTenantId to DefaultAzureCredentialOptionsManagedIdentityCredential authentication with user assigned identitiesFirst stable release of Azure.Identity package.
AzureCredentialOptions -> TokenCredentialOptions
VerificationUrl -> VerificationUri and changed type from string to UriClientSecretCredential class
ClientIdClientSecretTenantIdClientCertificateCredential class
ClientIdClientCertificateTenantIdDefaultAzureCredential class to derive directly from TokenCredential rather than ChainedTokenCredentialDefaultAzureCredentialOptions class
PreferredAccountUsername -> SharedTokenCacheUsernameIncludeEnvironmentCredential -> ExcludeEnvironmentCredentialIncludeManagedIdentityCredential -> ExcludeManagedIdentityCredentialIncludeSharedTokenCacheCredential -> ExcludeSharedTokenCacheCredentialIncludeInteractiveBrowserCredential -> ExcludeInteractiveBrowserCredentialDeviceCodeInfo class
IntervalVerificationUrl -> VerificationUri and changed type from string to UriInteractiveBrowserCredential class
tenantId and clientId to be consistent with other credential typesSharedTokenCacheCredential class
TokenCredentialOptionsclientId constructor parameterSharedTokenCacheCredentialOptionsTokenCredential implementations in the Azure.Identity library now throw exceptions rather than returning default(AccessToken) when no token is obtainedCredentialUnavailableExcpetion exception type to distinguish cases when failure to obtain an AccessToken was expectedManagedIdentityCredential IMDS availability check to handle immediate network failuresDefaultAzureCredential constructor overload to enable interactive credential types by defaultYour coding agent can read these notes before it upgrades. Set up the MCP server →