NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #123 most downloaded on NuGet
This is the Microsoft Azure Key Vault Certificates client library
Last release 6 days ago
03 Oct 2026
Ships fairly regularly
a new release about every 8 months
Nearly every release is documented
notes for 16 of 16 stable releases
1 version withdrawn
withdrawn after publishing
127 years old
17 releases · first in 1900
Fixed handling of claims challenges when the authentication challenge cache is empty or cleared while a request is in flight.
Fixed an issue in the challenge-based authentication policy where a cached authentication challenge, and the access token acquired for it, could be re
One column per quarter.
Code | Docs Support: Active
Code | Docs
Support: Active
Code | Docs
Code | Docs
Thank you to our developer community members who helped to make the Key Vault client libraries better with their contributions to this release:
RestoreCertificateBackup and RestoreCertificateBackupAsync.Support for Continuous Access Evaluation (CAE).
Changes from both the last release and the last beta include:
Changes from both the last release and the last beta include:
CertificateProperties.X509ThumbprintString to return the hexadecimal string representation of the SHA-1 hash of the certificate.
CertificateProperties.X509Thumbprint has been hidden but is still available.CertificateClient activities to following OpenTelemetry attribute naming conventions:
certificate to az.keyvault.certificate.nameversion to az.keyvault.certificate.versionissuer to az.keyvault.certificate.issuer.nameActivitySource is stable and no longer requires the Experimental feature-flag.Correctly serialize CertificateIssuer.OrganizationId property
CertificateIssuer.OrganizationId property (#35245)Service version "7.4-preview.1" is not supported.
Verify the challenge resource matches the vault domain. This should affect few customers who can set CertificateClientOptions.DisableChallengeResource
CertificateClientOptions.DisableChallengeResourceVerification to true to disable.
See https://aka.ms/azsdk/blog/vault-uri for more information.Changes from both the last release and the last beta include:
Changes from both the last release and the last beta include:
KeyVaultCertificateIdentifier.TryCreate to parse certificate URIs without throwing an exception when invalid. (#23146)DownloadCertificateOptions to pass X509KeyStorageFlags appropriate for different host applications. (#23016)X509KeyStorageFlags you must now pass a single required DownloadCertificateOptions with a required certificateName.Changed default service version to "7.2".
KeyVaultCertificateIdentifier to parse certificate URIs.CertificateClient.DownloadCertificate and DownloadCertificateAsync to download an X509Certificate2 with private key.### Changed - Updated dependency versions
Functions Extensions - WebPubSub
Code | Docs
Support: Active
Functions Extensions - WebPubSub
Microsoft.Azure.Functions.Worker.Extensions.WebPubSub
RecoverableDays property to CertificateProperties.Fixed an issue where the issuer name was always null
Fixed concurrency issue in our challenge-based authentication policy
Fixed issue that prevented certificate contacts from being created, enumerated, or deleted.
MergeCertificateOptions in CertificateClient.MergeCertificate. (#9986)Challenge-based authentication requests are only sent over HTTPS.
Your coding agent can read these notes before it upgrades. Set up the MCP server →