NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #25 most downloaded on NuGet
The current data provider for SQL Server and Azure SQL databases. This has replaced System.Data.SqlClient. These classes provide access to SQL and encapsulate database-specific protocols, including tabular data stream (TDS). Commonly Used Types: Microsoft.Data.SqlClient.SqlConnection Microsoft.Data.SqlClient.SqlException Microsoft.Data.SqlClient.SqlParameter Microsoft.Data.SqlClient.SqlDataReader Microsoft.Data.SqlClient.SqlCommand Microsoft.Data.SqlClient.SqlTransaction Microsoft.Data.SqlClient.SqlParameterCollection Microsoft.Data.SqlClient.SqlClientFactory When using NuGet 3.x this package requires at least version 3.4.
Last release 8 days ago
29 Sep 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
127 years old
78 releases · first in 1900
This servicing release fixes decimal parameter validation, token expiry handling in connection pool V2, and connection opens that are in progress when
This servicing release fixes decimal parameter validation, token expiry handling in connection pool V2, and connection opens that are in progress when a pool is cleared.
Package version alignment: The SqlClient family packages share the
7.1.1version:
Microsoft.Data.SqlClientMicrosoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProviderMicrosoft.Data.SqlClient.Extensions.AzureMicrosoft.Data.SqlClient.Extensions.AbstractionsMicrosoft.Data.SqlClient.Internal.Logging
Microsoft.SqlServer.Serveris versioned independently and is not part of this release. Applications should use matching7.1.1versions of the driver and its companion packages. The aligned assemblies retainAssemblyVersion 7.0.0.0; upgrading from7.1.0does not require new .NET Framework strong-name binding redirects.
Fixed an ArgumentException when sending zero-valued decimal or SqlDecimal parameters whose precision equals their scale. Nonzero precision validation and support for large decimal values are unchanged. (#4715, #4721, #4732)
Fixed connection pool V2 handing out pooled connections with expired or nearly expired access tokens. The pool now checks token expiry before reuse, matching the default pool's behavior while preserving transaction-affine reuse. This affects only applications that opt in to connection pool V2. (#4734, #4739)
Fixed connection opens failing when ClearPool or ClearAllPools races with an in-flight open. Requests already admitted to the cleared pool can finish, and connections returned to the retired pool are discarded rather than reused. (#4714, #4718, #4740)
One column per quarter.
Fixed an ArgumentException when sending zero-valued decimal or SqlDecimal parameters whose precision equals their scale. Nonzero precision validation and support for large decimal values are unchanged.
(#4715, #4721, #4732)
Fixed connection pool V2 handing out pooled connections with expired or nearly expired access tokens. This affects only applications that opt in to connection pool V2. (#4734, #4739)
Fixed connection opens failing when ClearPool or ClearAllPools races with an in-flight open. Requests already admitted to the cleared pool can finish, and connections returned to the retired pool are discarded rather than reused.
(#4714, #4718, #4740)
Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider, Microsoft.Data.SqlClient.Extensions.Azure, Microsoft.Data.SqlClient.Extensions.Abstractions, and Microsoft.Data.SqlClient.Internal.Logging 7.1.1 with no functional or API changes. See the release notes.It closes out the 7.1 preview cycle with application identity reporting for telemetry, the deprecation of TransparentNetworkIPResolution , and a set o…
This is the general availability release of Microsoft.Data.SqlClient 7.1. It closes out the 7.1 preview cycle with application identity reporting for telemetry, the deprecation of TransparentNetworkIPResolution, and a set of connection, transaction, and Named Pipes fixes.
Important — package version alignment: Starting with the 7.0.2 release, the
Microsoft.Data.SqlClientdriver and its companion packages share a single aligned version. The7.1.0GA release continues this alignment; the following packages ship together as7.1.0:
Microsoft.Data.SqlClientMicrosoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProviderMicrosoft.Data.SqlClient.Extensions.AzureMicrosoft.Data.SqlClient.Extensions.AbstractionsMicrosoft.Data.SqlClient.Internal.Logging(
Microsoft.SqlServer.Servercontinues to version independently and remains at1.0.0.)Applications must reference the same versions of
Microsoft.Data.SqlClientand its extensions for best compatibility. In particular, applications that referenceMicrosoft.Data.SqlClient.Extensions.Azuremust upgrade it to7.1.0when upgradingMicrosoft.Data.SqlClientto7.1.0.Compatibility guarantee: All aligned assemblies ship with
FileVersion 7.1.0.xandAssemblyVersion 7.0.0.0. TheAssemblyVersionis unchanged from 7.0.2, so upgrading from7.0.2,7.0.3, or any7.1preview to7.1.0does not require any new .NET Framework strong-name binding redirects. Applications upgrading from7.0.0or7.0.1should note thatExtensions.Azure,Extensions.Abstractions, andInternal.Loggingraised theirAssemblyVersionfrom1.0.0.0to7.0.0.0in 7.0.2; see those release notes for the one-time .NET Framework impact.
What Changed:
RegisteredApplication enum and a matching SqlConnection.RegisteredApplication property that let a library or tool identify itself to SQL Server through version 2 of the TDS USERAGENT feature extension. The payload also carries a new driver-owned 64-bit Driver Properties flag field; bit 0 reports whether connection pool V2 is enabled for the process. Both fields are emitted as unpadded uppercase hexadecimal. (#3201, #4632)Who Benefits:
Impact:
RegisteredApplication is unset reports Unknown (0). On the wire the field itself is new — USERAGENT payload v1 carried no application identifier, while v2 always emits one.Open or OpenAsync. Assigning it while the connection is connecting or open throws InvalidOperationException.using var connection = new SqlConnection(connectionString);
connection.RegisteredApplication = RegisteredApplication.EntityFrameworkCore;
await connection.OpenAsync();ushort-backed and marked [CLSCompliant(false)]. Values are partitioned by range: 0x0001–0x7FFF for Microsoft-defined large-scale applications, 0x8000–0xBFFF for small-scale use, and 0xC000–0xFFFF for public/developer use. Applications that are not yet registered can cast an unassigned value from the appropriate range.Min Pool Size connections report Unknown. Cloned connections preserve the value.TransparentNetworkIPResolution Is Now ObsoleteWhat Changed:
SqlConnectionStringBuilder.TransparentNetworkIPResolution is now marked [Obsolete]. The obsoletion message directs callers to MultiSubnetFailover and notes that Transparent Network IP Resolution (TNIR) is a .NET Framework-only feature. (#4494, #4576)Who Benefits:
MultiSubnetFailover, which addresses the same "connect quickly across multiple DNS-resolved addresses" goal, works consistently on every supported target framework, and is the documented strategy for Always On availability group listeners.Impact:
true on .NET Framework, and MultiSubnetFailover still defaults to false. The property remains .NET Framework-only and is not exposed on modern .NET, where a connection string containing the Transparent Network IP Resolution keyword still throws NotSupportedException. No new AppContext switches were introduced.CS0618 build warning for code that references the property. Suppress it, or migrate to MultiSubnetFailover, at your own pace. Flipping the TNIR and MultiSubnetFailover defaults is deferred to a future major version.Microsoft.Data.SqlClient.SNI and Microsoft.Data.SqlClient.SNI.runtime to v7.1.0 (was v7.1.0-preview3.26226.3). (#4698)SqlConnection, and documented the complete set of properties that conflict with AccessToken. (#4629)SqlDataRecord and SqlMetaData documentation, which incorrectly described the SQL CLR-only SqlContext and SqlPipe types, and clarified whether SqlDataRecord instances can be reused. (#1805, #4440)English (United States). (#4646)TransactionScope rollback — for example, when distributed transaction promotion fails on .NET 8+ where implicit distributed transactions are disabled by default. A subsequent Open() succeeded but BeginTransaction() threw InvalidOperationException ("the connection has been broken"). Connection reset now preserves the transaction when the pooled connection is either a delegated transaction root or enlisted in a transaction, instead of only the latter. (#4001, #4557)GetSchema("DataTypes") never reporting the SQL Server 2025 json type against Azure SQL. The row was filtered by a string comparison against a minimum server version of 17.00.000.0, which Azure SQL can never satisfy because it always reports 12.00.xxxx. The decision now uses the json support flag negotiated through the TDS FEATUREEXTACK token, which is accurate on both Azure SQL and on-premises SQL Server 2025+. (#4592, #4682)Server=np:::1, Server=np:[::1], or Server=\\::1\pipe\sql\query). A UNC path component may not contain a colon, and handing such a path to the OS could trigger an access violation inside LSASS on Windows, forcing a reboot. IPv6 literals are now transcribed to their .ipv6-literal.net form as defined by MS-DTYP 2.2.57, and a colon-bearing host with no valid IPv6 interpretation now fails with the standard invalid-connection-string error. Colon-free host names, LocalDB, localhost, ., and IPv6 over TCP are unaffected. (net8.0/net9.0 only — this is the managed SNI counterpart to the native SNI fix) (#4523, #4558)AppContext.BaseDirectory instead of the current working directory. Place custom retry assemblies in the application base directory; dependencies loaded after provider construction must be resolvable through normal application dependency resolution or an application-supplied handler. (net8.0/net9.0 only — the .NET Framework path does not use AssemblyLoadContext) (#2214, #4547)Switch.Microsoft.Data.SqlClient.UseConnectionPoolV2). Acquiring an already-pooled connection no longer dispatches to the thread pool before attempting an inline, non-blocking acquisition, no longer allocates a timer-backed CancellationTokenSource before it is known that the caller will wait, and no longer allocates a Task on the synchronous completion path. The default pool is unaffected. (#4543)This section summarizes all changes across the 7.1 preview cycle for users upgrading from the latest 7.0 stable release. Changes that were also serviced into 7.0.1, 7.0.2, or 7.0.3 are omitted — they are already present for 7.0.x users.
SqlBatch Support on .NET Framework (net462 only)What Changed:
SqlBatch, SqlBatchCommand, and the related execution methods are now available on the .NET Framework target, so the batching API spans the full supported platform matrix. (#3926)Who Benefits:
Impact:
SqlCommand code is unchanged.SqlConnection.GetSchemaAsyncWhat Changed:
SqlConnection.GetSchema that mirror the existing synchronous shapes and honor a supplied CancellationToken. The .NET Framework schema code paths were unified with the .NET implementation in the process. (#3005)Who Benefits:
Impact:
GetSchema(...) calls are unchanged.What Changed:
virtual asynchronous counterparts to the synchronous methods on SqlColumnEncryptionKeyStoreProvider: DecryptColumnEncryptionKeyAsync, EncryptColumnEncryptionKeyAsync, SignColumnMasterKeyMetadataAsync, and VerifyColumnMasterKeyMetadataAsync. Each accepts an optional CancellationToken, and the default implementations delegate to the existing synchronous methods. (#3672, #3673)Who Benefits:
Impact:
SqlColumnEncryptionAzureKeyVaultProvider overrides all four methods. See the AzureKeyVaultProvider 7.1.0 release notes. (#4540)What Changed:
Connection Idle Timeout connection-string keyword and matching SqlConnectionStringBuilder.IdleTimeout property that let the pool evict connections whose idle time exceeds the configured value. The default is 300 seconds; 0 disables idle expiration and negative values throw ArgumentException. Enforcement is gated on Switch.Microsoft.Data.SqlClient.UseLegacyIdleTimeoutBehavior, which defaults to true to preserve historical pooling behavior. (#4295)Who Benefits:
Impact:
false.What Changed:
ChannelDbConnectionPool, the opt-in pool behind Switch.Microsoft.Data.SqlClient.UseConnectionPoolV2, bringing it to parity with the default WaitHandleDbConnectionPool: transaction support, broken-connection replacement, background warmup and replenishment to Min Pool Size, idle pruning derived from Connection Idle Timeout, optional connection-creation rate limiting, leaked-connection reclamation, and metrics/tracing parity. (#4395, #4396, #4429, #4452, #4463, #4487, #4504, #4529, #4543)SqlConnection.ClearPool(SqlConnection) and SqlConnection.ClearAllPools() now work correctly under pool V2. (#4194)Who Benefits:
Impact:
SqlConnection.RegisteredApplication and USERAGENT payload version 2 (see Changes Since 7.1.0-preview3 above). (#4632)SqlBulkCopy column mappings now accept the SQL Graph pseudo-column aliases $node_id, $edge_id, $from_id, and $to_id as destination column names. (#3677)SqlBatchCommand.CommandBehavior is now honored inside a SqlBatch, and SqlBatch.ExecuteReader respects the CommandBehavior passed to it. Batches that previously set the property and relied on it being ignored will now see it applied. (#4125)ColumnEncryption, ConnectTimeout, FailoverPartner, PacketSize, and WorkstationId. (#4192)json data type to the DataTypes collection returned by SqlConnection.GetSchema. (#3858)What Changed:
TimeSpan timeouts with a shared TimeoutTimer across SqlConnection.Open[Async], pool acquisition, and physical connection creation, so the Connect Timeout budget can be deducted while a request waits in the pool. Enforcement is gated on Switch.Microsoft.Data.SqlClient.UseOverallConnectTimeoutForPoolWait, which defaults to false. Introduces a dependency on Microsoft.Bcl.TimeProvider. (#4270)Who Benefits:
Connect Timeout respected end-to-end instead of the budget effectively restarting when a physical connection is eventually opened.Impact:
Open/OpenAsync under heavy pool contention may surface timeouts sooner than before; successful opens are unaffected.TransparentNetworkIPResolution Is Now ObsoleteLocalAppContextSwitches.UseManagedNetworking is substituted for a constant. The driver builds a single OS-agnostic assembly for all platforms; NuGet package structure and contents are unchanged. (#4207, #4239, #4465, #4474)PacketData linked-list nodes via a bounded free list on StateSnapshot, returning SqlCommand/ExecuteReaderAsync from +120.9% allocated against the 6.1.6 baseline to +0.1%. (#4536)SqlBulkCopy no longer builds SQL Graph column alias mapping tables when neither the source nor destination table contains graph pseudo-columns. (#4535)SqlErrorCollection counters with no errors present, and on expected null-return paths that previously materialized stack traces. (#4072, #4157, #4099, #4102)SqlConnection internal state transitions now use Interlocked.CompareExchange guards. (#4267)ForceNewConnection handling. (#4235, #4237, #4261, #4415)SqlVector<float> now serializes and deserializes little-endian multibyte values explicitly for consistent behavior across architectures. (#3861)EnclaveDiffieHellmanInfo.Size accuracy. (#4346)SqlDataRecord, SqlMetaData, server certificate configuration, and the LCID 1033 locale name. (#4408, #4440, #4646)Microsoft.Bcl.Cryptography, Microsoft.Extensions.Caching.Memory, System.Configuration.ConfigurationManager, and System.Security.Cryptography.Pkcs to v9.0.18 for the net9.0 target framework. Non-net9.0 targets keep their existing 8.0.x pins. (#4507)System.Threading.RateLimiting and Microsoft.Bcl.TimeProvider to the packaged dependency metadata. (#4270, #4507)Microsoft.Data.SqlClient.SNI and Microsoft.Data.SqlClient.SNI.runtime to v7.1.0 (was v6.0.3). (#4564, #4698)CekMdVersion and EkValueCount to align with the TDS specification. (#4240)OverflowException when sending large decimal values (for example decimal.MaxValue) as a parameter with explicit Precision and Scale. This primarily affected Always Encrypted scenarios, where both must always be set. (#1655, #4443)DateOnly value as a parameter with SqlDbType.Variant, and fixed DateOnly values written to a sql_variant column of a table-valued parameter being sent as datetime instead of date (which also caused overflows for values valid for date but out of range for datetime). Reading continues to return DateTime instances by default for backwards compatibility. (net8.0/net9.0 only — .NET Framework has no DateOnly type) (#3953, #3934, #4294, #4439)SqlConnectionFactory timer that woke the process every 30 seconds for the lifetime of the application even when no connection pools existed — including with Pooling=False and after ClearAllPools(). The pruning timer is now armed on demand and disarmed once there is nothing left to prune. A missing .NET Framework unload hook was also added. (#1881, #4479)active-soft-connects and number-of-active-connections could go negative after a failed connection activation, and active-soft-connects, active-hard-connections, and number-of-pooled-connections drifted upward permanently after a broken connection was replaced. (#4504)TransactionScope rollback, which caused a later BeginTransaction() to throw InvalidOperationException. (#4001, #4557)GetSchema("DataTypes") never reporting the json type against Azure SQL. (#4592, #4682)SqlBulkCopy, SqlDataReader.InvokeAsyncCall, SqlCommand.Reader, and SqlCommand.Xml that captured fatal exceptions such as OutOfMemoryException into faulted Tasks instead of letting them propagate. (#4437)SqlDataReader streaming bug where calling IsDBNull() before reading a streamed value could skip column data. (#4082)SqlConnection.TryOpenInner that could surface as InvalidCastException; the same race now returns a deterministic InvalidOperationException. (#4179)LoginWithFailover to validate parser state before continuing, preventing null-reference failures during failover login. (#4140)Protocol=None or Protocol=Admin is specified. (#4180)CancellationTokenSource leaks in SqlDataReader, SqlConnection, the SqlCommand reconnect paths, and the sequential-stream helpers. (#4009)What Changed:
SQL Server 2000 type-system compatibility option. The TypeSystem.SQLServer2000 enum value and the Type System Version=SQL Server 2000 connection-string branch are gone. (#4015)Who Benefits:
Latest, SQL Server 2005, SQL Server 2008, SQL Server 2012) now matches the implementation exactly.Impact:
Type System Version=SQL Server 2000 now throws ArgumentException when the connection is opened. Switch to a supported value such as Latest. There is no change to which servers the driver connects to — SQL Server 7.0 and 2000 were already rejected during login version negotiation.We thank the following public contributors. Their efforts toward this project are very much appreciated.
General availability of Microsoft.Data.SqlClient 7.1. The sections below list the changes since 7.1.0-preview3. See the 7.1.0 release notes for the cumulative list of changes since the 7.0.3 stable release.
RegisteredApplication enum and a matching SqlConnection.RegisteredApplication property that let a library or tool identify itself to SQL Server through version 2 of the TDS USERAGENT feature extension. The payload also carries a new driver-owned 64-bit Driver Properties flag field; bit 0 reports whether connection pool V2 is enabled for the process. Application identity is client-supplied telemetry and must never be used for authorization or any other security decision. The value must be set before Open/OpenAsync and is not part of the connection pool key.
(#3201, #4632)SqlConnectionStringBuilder.TransparentNetworkIPResolution is now marked [Obsolete], directing callers to MultiSubnetFailover. There is no runtime behavior change: connection string defaults are untouched and no new AppContext switches were introduced. The only visible effect is a CS0618 build warning for code that references the property.
(#4494, #4576)
Unified the exception message raised when conflicting token-based and SSPI authentication properties are set on the same SqlConnection, and documented the complete set of properties that conflict with AccessToken.
(#4629)
Documentation corrections for SqlDataRecord, SqlMetaData, and the LCID 1033 locale name.
(#1805,
#4440,
#4646)
Updated Microsoft.Data.SqlClient.SNI and Microsoft.Data.SqlClient.SNI.runtime to v7.1.0 (was v7.1.0-preview3.26226.3).
(#4698)
Fixed a pooled connection being returned to the pool in a broken state after a TransactionScope rollback — for example, when distributed transaction promotion fails on .NET 8+ where implicit distributed transactions are disabled by default. Connection reset now preserves the transaction when the pooled connection is either a delegated transaction root or enlisted in a transaction.
(#4001, #4557)
Fixed GetSchema("DataTypes") never reporting the SQL Server 2025 json type against Azure SQL. The decision now uses the json support flag negotiated through the TDS FEATUREEXTACK token instead of a server version string comparison.
(#4592, #4682)
Fixed a malformed UNC pipe path being composed for IPv6 literal server names over Named Pipes in managed SNI, which could trigger an access violation inside LSASS on Windows and force a reboot. IPv6 literals are now transcribed to their .ipv6-literal.net form. (net8.0/net9.0 only)
(#4523, #4558)
Fixed configurable retry logic installing a permanent, process-wide assembly-resolution handler that could interfere with unrelated assembly loading. The handler is now installed only while an explicitly configured custom retry provider is resolved and constructed, and probes AppContext.BaseDirectory instead of the current working directory. (net8.0/net9.0 only)
(#2214, #4547)
Fixed open/close throughput regressions in the opt-in connection pool V2 (Switch.Microsoft.Data.SqlClient.UseConnectionPoolV2). The default pool is unaffected.
(#4543)
Microsoft.Data.SqlClient.Extensions.Azure 7.1.0 with an internal Entra ID authority parsing clarification and no behavior change. See release notes.Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider, Microsoft.Data.SqlClient.Extensions.Abstractions, and Microsoft.Data.SqlClient.Internal.Logging 7.1.0 with no functional or API changes since preview3. See the Azure Key Vault provider, Abstractions, and Logging release notes.This update brings the following changes since the 7.0.2 release:
This update brings the following changes since the 7.0.2 release:
The core driver and its companion packages ship together as version 7.0.3. Update the companion packages you use alongside the driver to 7.0.3. Assembly versions remain 7.0.0.0, unchanged from 7.0.2.
Microsoft.Data.SqlClient.SNI and Microsoft.Data.SqlClient.SNI.runtime dependencies to 6.0.3 (was 6.0.2).Fixed a SqlBulkCopy regression in environments where the application login cannot read sys.all_columns. Bulk copy now falls back to the earlier column-discovery behavior when that permission is unavailable. Support for hidden columns and SQL Graph column aliases still requires access to the metadata view.
(#4370, #4306, #4402)
Fixed a memory-allocation regression in connection and command operations caused by formatting diagnostic strings even when tracing was disabled. Also corrected trace messages that reported an incorrect object ID or could throw FormatException when traced values contained braces.
(#4528, #4533)
Fixed ServerCertificate validation on the managed SNI path so the configured certificate is compared against the server certificate even when the server certificate passes chain and host-name validation. When certificate validation is enabled, a missing, unreadable, or invalid certificate file, a certificate mismatch, or a missing server certificate now causes the TLS handshake to fail instead of bypassing the configured certificate check. (net8.0/net9.0 only)
(#4445, #4583)
Fixed Always Encrypted VSM/HGS enclave attestation to verify that the enclave public key used to establish a session matches the key committed to by the signed attestation report. Missing, malformed, or mismatched key-binding data now causes attestation to fail before the session secret is derived.
(#4532, #4553)
Fixed SqlConnection.AccessTokenCallback not disabling Transparent Network IP Resolution by default, making it consistent with SqlConnection.AccessToken. An explicitly configured TransparentNetworkIPResolution connection-string value still takes precedence. (net462 only)
(#4520, #4561)
Fixed authentication state handling so clearing SqlConnection.AccessToken, AccessTokenCallback, or SspiContextProvider preserves the other authentication values in the connection pool key. Cloning a connection or updating its credential also preserves its SspiContextProvider. Combining a non-null SspiContextProvider with AccessToken or AccessTokenCallback now throws InvalidOperationException instead of silently discarding authentication state; applications must use one authentication mechanism at a time.
(#4520, #4561, #4644)
Fixed configurable retry logic installing a permanent, process-wide assembly-resolution handler that could interfere with unrelated assembly loading. The handler is now active only while an explicitly configured custom retry provider is resolved and constructed, and probes AppContext.BaseDirectory instead of the current working directory. Place custom retry assemblies in the application base directory; dependencies loaded after provider construction must be resolvable through normal application dependency resolution or an application-provided handler. (net8.0/net9.0 only)
(#2214, #4547, #4663)
We thank the following public contributors. Their efforts toward this project are very much appreciated.
Full details: release-notes/7.0/7.0.3.md
Breaking change (.NET Framework only): As part of this alignment, the AssemblyVersion of Microsoft.Data.SqlClient.Extensions.Azure , Microsoft.Data.Sq…
This update brings the following changes since the 7.0.1 release:
Important — package version alignment: Starting with 7.0.2, the
Microsoft.Data.SqlClientdriver and its companion packages share a single aligned version. The following packages now ship together as7.0.2:
Microsoft.Data.SqlClientMicrosoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProviderMicrosoft.Data.SqlClient.Extensions.AzureMicrosoft.Data.SqlClient.Extensions.AbstractionsMicrosoft.Data.SqlClient.Internal.Logging(
Microsoft.SqlServer.Servercontinues to version independently and remains at1.0.0.)Applications must reference the same versions of
Microsoft.Data.SqlClientand its extensions for best compatibility. In particular, applications that referenceMicrosoft.Data.SqlClient.Extensions.Azuremust upgrade it to7.0.2when upgradingMicrosoft.Data.SqlClientto7.0.2.
Breaking change (.NET Framework only): As part of this alignment, the
AssemblyVersionofMicrosoft.Data.SqlClient.Extensions.Azure,Microsoft.Data.SqlClient.Extensions.Abstractions, andMicrosoft.Data.SqlClient.Internal.Loggingchanged from1.0.0.0to7.0.0.0(theMicrosoft.Data.SqlClientandMicrosoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProviderassembly versions are unchanged). On .NET Framework,AssemblyVersionis part of the strong-name identity, so applications that drop these assemblies into an existing deployment without rebuilding must rebuild against the 7.0.2 packages (or add binding redirects). Applications on .NET / .NET Core are not affected.
The following companion packages ship aligned as 7.0.2. See their individual release notes for package-specific changes (including the Microsoft.Data.SqlClient.Extensions.Azure WAM broker support):
Fixed a NullReferenceException in SqlCommand.Cancel(). The diagnostic message built during cancellation dereferenced the active connection directly; it now uses a null-conditional access so cancellation no longer throws when the connection has already been torn down.
(#4372,#4373)
Fixed a NullReferenceException in SqlDataReader when calling GetBytes/GetChars with a null destination buffer. The argument-validation path that constructs the InvalidDestinationBufferIndex exception now guards against the null buffer so the correct ArgumentException is surfaced instead of an NRE.
(#4159,#4206)
Fixed Always Encrypted column master key signature verification incorrectly reusing cached results. The SignatureVerificationCache lookup logic was corrected so signature verification outcomes are cached and retrieved against the correct key, preventing stale or mismatched verification results.
(#4339,#4343)
What Changed:
Who Benefits:
Impact:
We thank the following public contributors. Their efforts toward this project are very much appreciated.
This update brings the following changes since the 7.0.1 release. See the full release notes for detailed descriptions.
Important — package version alignment: Starting with 7.0.2, the
Microsoft.Data.SqlClientdriver and its companion packages share a single aligned version. The following packages now ship together as7.0.2:
Microsoft.Data.SqlClientMicrosoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProviderMicrosoft.Data.SqlClient.Extensions.AzureMicrosoft.Data.SqlClient.Extensions.AbstractionsMicrosoft.Data.SqlClient.Internal.Logging(
Microsoft.SqlServer.Servercontinues to version independently and remains at1.0.0.)Applications must reference the same versions of
Microsoft.Data.SqlClientand its extensions for best compatibility. In particular, applications that referenceMicrosoft.Data.SqlClient.Extensions.Azuremust upgrade it to7.0.2when upgradingMicrosoft.Data.SqlClientto7.0.2.
Breaking change (.NET Framework only): As part of this alignment, the
AssemblyVersionofMicrosoft.Data.SqlClient.Extensions.Azure,Microsoft.Data.SqlClient.Extensions.Abstractions, andMicrosoft.Data.SqlClient.Internal.Loggingchanged from1.0.0.0to7.0.0.0. On .NET Framework,AssemblyVersionis part of the strong-name identity, so applications that drop these assemblies into an existing deployment without rebuilding must rebuild against the 7.0.2 packages (or add binding redirects). Applications on .NET / .NET Core are not affected.Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvideralready used a7.xassembly version and is unaffected.
Fixed a NullReferenceException in SqlCommand.Cancel() when the active connection has already been torn down.
(#4372,
#4373)
Fixed a NullReferenceException in SqlDataReader.GetBytes/GetChars when called with a null destination buffer.
(#4159,
#4206)
Fixed Always Encrypted column master key signature verification incorrectly reusing cached results. (#4339, #4343)
Hardened TDS token parsing by adding data-length bounds checks for token and feature-extension-acknowledgment data. (#4340, #4358)
Released Microsoft.Data.SqlClient.Extensions.Azure 7.0.2, adding WAM broker support for Entra ID authentication modes on Windows. See release notes.
(#4288,
#4388)
Re-shipped Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider, Microsoft.Data.SqlClient.Extensions.Abstractions, and Microsoft.Data.SqlClient.Internal.Logging as 7.0.2 (version alignment only, no functional changes). See release notes for AKV, Abstractions, and Logging.
This update brings the following changes since the 7.0.0 release:
This update brings the following changes since the 7.0.0 release:
Fixed SqlBulkCopy failing on SQL Server 2016 with Invalid column name 'graph_type' error. The column metadata query now uses dynamic SQL so that references to the graph_type column (introduced in SQL Server 2017) are not compiled on older versions that lack the column. (#3714, #4092, #4147)
Fixed SqlBulkCopy failing on Azure Synapse Analytics dedicated SQL pools. The column-list query previously used a variable-assignment pattern that Synapse does not support; it now uses STRING_AGG when targeting Synapse (engine edition 6) and falls back to the variable-assignment approach for SQL Server 2016 compatibility. (#4149, #4176, #4182)
Fixed SqlDataReader.GetFieldType() and GetProviderSpecificFieldType() returning typeof(byte[]) instead of typeof(SqlVector<float>) for vector float32 columns. The methods now follow the same type-determination logic as GetValue(). (#4104, #4105, #4152)
Added missing System.Data.Common (v4.3.0) NuGet package dependency for .NET Framework consumers. The inbox System.Data.Common assembly on .NET Framework predates APIs such as IDbColumnSchemaGenerator; without the explicit NuGet dependency, consumers encountered CS0012 compilation errors when using these types through Microsoft.Data.SqlClient. (#4063, #4074)
Enabled the User Agent TDS feature extension unconditionally. The Switch.Microsoft.Data.SqlClient.EnableUserAgent AppContext switch has been removed; the driver now always sends User Agent information during login. (#4124, #4154)
Added type forwards from the core Microsoft.Data.SqlClient assembly to public types that were moved to the Microsoft.Data.SqlClient.Extensions.Abstractions package: SqlAuthenticationMethod, SqlAuthenticationParameters, SqlAuthenticationProvider, SqlAuthenticationProviderException, and SqlAuthenticationToken. This ensures binary compatibility for assemblies compiled against earlier versions of Microsoft.Data.SqlClient where these types lived in the core assembly. (#4067, #4117)
Fixed API documentation include paths and duplicate doc snippets. (#4084, #4086, #4107, #4161)
We thank the following public contributors. Their efforts toward this project are very much appreciated.
This update brings the following changes since the 7.0.0 release. See the full release notes for detailed descriptions.
Fixed SqlBulkCopy failing on SQL Server 2016 with Invalid column name 'graph_type' error by using dynamic SQL to extract column names.
(#3714,
#4092,
#4147)
Fixed SqlBulkCopy failing on Azure Synapse Analytics dedicated SQL pools by using STRING_AGG for the column-list query when targeting Synapse.
(#4149,
#4176,
#4182)
Fixed SqlDataReader.GetFieldType() and GetProviderSpecificFieldType() returning incorrect type for vector float32 columns.
(#4104,
#4105,
#4152)
Added missing System.Data.Common (v4.3.0) NuGet package dependency for .NET Framework consumers to resolve CS0012 compilation errors.
(#4063,
#4074)
Enabled the User Agent TDS feature extension unconditionally; removed the Switch.Microsoft.Data.SqlClient.EnableUserAgent AppContext switch.
(#4124,
#4154)
Added type forwards from the core assembly to public types moved to Microsoft.Data.SqlClient.Extensions.Abstractions.
(#4067,
#4117)
Fixed API documentation include paths and duplicate doc snippets. (#4084, #4086, #4107, #4161)
Deprecation of SqlAuthenticationMethod.ActiveDirectoryPassword
This is the general availability release of Microsoft.Data.SqlClient 7.0, a major milestone for the .NET data provider for SQL Server. This release addresses the most upvoted issue in the repository's history — extracting Azure dependencies from the core package — introduces pluggable SSPI authentication, adds enhanced routing for Azure SQL Hyperscale, and delivers async read performance improvements.
Also released as part of this milestone:
Microsoft.Data.SqlClient.Extensions.Azure package installed, guiding users to install the correct package. (#3962, #4046)Microsoft.Data.SqlClient.Extensions.Logging package to Microsoft.Data.SqlClient.Internal.Logging to indicate it is for internal use only and should not be referenced directly by application code. (#4038)Azure.Core to v1.51.1Azure.Identity to v1.18.0Azure.Security.KeyVault.Keys to v4.9.0Microsoft.Extensions.Caching.Memory to v9.0.13 (.NET 9.0)Microsoft.IdentityModel.JsonWebTokens to v8.16.0Microsoft.IdentityModel.Protocols.OpenIdConnect to v8.16.0Microsoft.Bcl.Cryptography to v9.0.13 (.NET 9.0)System.Configuration.ConfigurationManager to v9.0.13 (.NET 9.0)System.Diagnostics.DiagnosticSource to v10.0.3System.Security.Cryptography.Pkcs to v9.0.13 (.NET 9.0)System.Text.Json to v10.0.3System.Threading.Channels to v10.0.3System.ValueTuple to v4.6.2This section summarizes all changes across the 7.0 preview cycle for users upgrading from the latest 6.1 stable release.
What Changed:
Microsoft.Data.SqlClient package no longer depends on Azure.Core, Azure.Identity, or their transitive dependencies (e.g., Microsoft.Identity.Client, Microsoft.Web.WebView2). Azure Active Directory / Entra ID authentication functionality (ActiveDirectoryAuthenticationProvider and related types) has been extracted into a new Microsoft.Data.SqlClient.Extensions.Azure package. (#1108, #3680, #3902, #3904, #3908, #3917, #3982, #3978, #3986)Microsoft.Data.SqlClient.Extensions.Abstractions (shared types between the core driver and extensions) and Microsoft.Data.SqlClient.Internal.Logging (shared ETW tracing infrastructure). (#3626, #3628, #3967, #4038)Who Benefits:
Impact:
ActiveDirectoryInteractive, ActiveDirectoryDefault, ActiveDirectoryManagedIdentity, etc.) must now install the Microsoft.Data.SqlClient.Extensions.Azure NuGet package separately:dotnet add package Microsoft.Data.SqlClient.Extensions.Azure
What Changed:
SspiContextProvider property on SqlConnection, completing the SSPI extensibility work begun in 6.1.0. Applications can now supply a custom SSPI context provider for integrated authentication, enabling custom Kerberos ticket negotiation and NTLM username/password authentication scenarios. (#2253, #2494)Who Benefits:
Impact:
SspiContextProvider on SqlConnection before opening the connection:var connection = new SqlConnection(connectionString);
connection.SspiContextProvider = new MyKerberosProvider();
connection.Open();SspiContextProvider is part of the connection pool key. Care should be taken when using this property to ensure the implementation returns a stable identity per resource.What Changed:
Who Benefits:
ExecuteReaderAsync with big result sets, streaming scenarios, or bulk data retrieval).Impact:
AppContext.SetSwitch("Switch.Microsoft.Data.SqlClient.UseCompatibilityAsyncBehaviour", false);
AppContext.SetSwitch("Switch.Microsoft.Data.SqlClient.UseCompatibilityProcessSni", false);false enables the new async processing path. By default, the driver uses the existing (compatible) behavior.What Changed:
Who Benefits:
Impact:
What Changed:
Who Benefits:
Impact:
What Changed:
Enabled SqlClientDiagnosticListener for SqlCommand on .NET Framework, closing a long-standing observability gap where diagnostic events were previously only emitted on .NET Core. (#3658)
Brought the 15 strongly-typed diagnostic event classes in the Microsoft.Data.SqlClient.Diagnostics namespace — originally introduced for .NET Core in 6.0 — to .NET Framework as part of the codebase merge. Both platforms now use the same strongly-typed event model. The types cover command, connection, and transaction lifecycle events:
SqlClientCommandBefore, SqlClientCommandAfter, SqlClientCommandErrorSqlClientConnectionOpenBefore, SqlClientConnectionOpenAfter, SqlClientConnectionOpenErrorSqlClientConnectionCloseBefore, SqlClientConnectionCloseAfter, SqlClientConnectionCloseErrorSqlClientTransactionCommitBefore, SqlClientTransactionCommitAfter, SqlClientTransactionCommitErrorSqlClientTransactionRollbackBefore, SqlClientTransactionRollbackAfter, SqlClientTransactionRollbackError(#3493)
Who Benefits:
SqlClientDiagnosticListener events for observability, distributed tracing, or custom telemetry. These users now have parity with .NET Core, gaining IntelliSense, compile-time safety, and eliminating the need to access diagnostic payloads via reflection or dictionary lookups.Impact:
SqlCommand now emits the same diagnostic events that were previously only available on .NET Core. Subscribers to DiagnosticListener events (e.g., Microsoft.Data.SqlClient.WriteCommandBefore) receive the strongly-typed objects:listener.Subscribe(new Observer<KeyValuePair<string, object?>>(kvp =>
{
if (kvp.Value is SqlClientCommandBefore before)
{
Console.WriteLine($"Executing: {before.Command.CommandText}");
}
}));IReadOnlyList<KeyValuePair<string, object>> for backward compatibility with code that iterates properties generically.SqlConfigurableRetryFactory.BaselineTransientErrors static property exposing the default transient error codes list as a ReadOnlyCollection<int>, making it easier to extend the default list with application-specific error codes. (#3903)Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefault to set MultiSubnetFailover=true globally without modifying connection strings. (#3841)Switch.Microsoft.Data.SqlClient.IgnoreServerProvidedFailoverPartner to let the client ignore server-provided failover partner info in Basic Availability Groups. (#3625)Switch.Microsoft.Data.SqlClient.EnableUserAgent). (#3606)SqlAuthenticationMethod.ActiveDirectoryPasswordWhat Changed:
SqlAuthenticationMethod.ActiveDirectoryPassword (the ROPC flow) is now marked [Obsolete] and will generate compiler warnings. This aligns with Microsoft's move toward mandatory multifactor authentication. (#3671)Who Benefits:
Impact:
Authentication=Active Directory Password, migrate to a supported alternative:| Scenario | Recommended Authentication |
|---|---|
| Interactive / desktop apps | Active Directory Interactive |
| Service-to-service | Active Directory Service Principal |
| Azure-hosted workloads | Active Directory Managed Identity |
| Developer / CI environments | Active Directory Default |
IoControlCodeAccess and IoControlTransferType) that were accidentally made public during the project merge. (#3900)Constrained Execution Region error handling blocks and associated SqlConnection cleanup. (#3535)SqlBulkCopy to operate on hidden columns. (#3590)ExecuteScalar to propagate errors when the server sends data followed by an error token. (#3912)NullReferenceException in SqlDataAdapter when processing batch scenarios. (#3857)AppContextSwitchOverrides configuration field. (#3960)TdsParserStateObject.TryReadPlpBytes where zero-length reads returned null instead of an empty array. (#3872)CreatePerformanceCounters. (#3623)SetProvider to return immediately if user-defined authentication provider found. (#3620)We thank the following public contributors. Their efforts toward this project are very much appreciated.
This section summarizes all changes across the 7.0 preview cycle for users upgrading from the latest 6.1 stable release. See the full release notes for detailed descriptions.
Also released as part of this milestone:
Breaking: Removed Azure dependencies from the core package. Entra ID authentication (ActiveDirectoryAuthenticationProvider and related types) has been extracted into a new Microsoft.Data.SqlClient.Extensions.Azure package. The core Microsoft.Data.SqlClient package no longer depends on Azure.Core, Azure.Identity, or their transitive dependencies. Applications using Entra ID authentication must now install Microsoft.Data.SqlClient.Extensions.Azure separately.
(#1108,
#3680,
#3902,
#3904,
#3908,
#3917,
#3982,
#3978,
#3986)
Two additional packages were introduced to support this separation: Microsoft.Data.SqlClient.Extensions.Abstractions (shared types between the core driver and extensions) and Microsoft.Data.SqlClient.Internal.Logging (shared ETW tracing infrastructure).
(#3626,
#3628,
#3967,
#4038)
Deprecated SqlAuthenticationMethod.ActiveDirectoryPassword (ROPC flow). The method is now marked [Obsolete] and will generate compiler warnings. Migrate to ActiveDirectoryInteractive, ActiveDirectoryServicePrincipal, ActiveDirectoryManagedIdentity, or ActiveDirectoryDefault.
(#3671)
Reverted public visibility of internal interop enums (IoControlCodeAccess and IoControlTransferType) that were accidentally made public during the project merge.
(#3900)
Removed Constrained Execution Region error handling blocks and associated SqlConnection cleanup.
(#3535)
Performance improvements across SqlStatistics timing, Always Encrypted scenarios, and connection opening: (#3609, #3612, #3732, #3660, #3791, #3772, #3554)
Allow SqlBulkCopy to operate on hidden columns.
(#3590)
Updated UserAgent feature to use a pipe-delimited format, replacing the previous JSON format. (#3826)
Minor improvements to Managed SNI tracing to capture continuation events and errors. (#3859)
Added SspiContextProvider abstract class and SqlConnection.SspiContextProvider property, enabling custom SSPI authentication for scenarios like cross-domain Kerberos negotiation and NTLM username/password authentication.
(#2253,
#2494)
Continued refinement of packet multiplexing with bug fixes and stability improvements, plus new app context switches for opt-in control. (#3534, #3537, #3605)
Added support for enhanced routing, a TDS feature that allows the server to redirect connections to a specific server and database during login, enabling Azure SQL Hyperscale read replica load balancing. (#3641, #3969, #3970, #3973)
Updated pipelines and test suites to compile the driver using the .NET 10 SDK. (#3686)
Added SqlConfigurableRetryFactory.BaselineTransientErrors static property exposing the default transient error codes list as a ReadOnlyCollection<int>.
(#3903)
Added app context switch Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefault to set MultiSubnetFailover=true globally without modifying connection strings.
(#3841)
Added app context switch Switch.Microsoft.Data.SqlClient.IgnoreServerProvidedFailoverPartner to let the client ignore server-provided failover partner info in Basic Availability Groups.
(#3625)
Enabled SqlClientDiagnosticListener for SqlCommand on .NET Framework, closing a long-standing observability gap where diagnostic events were previously only available on .NET Core.
(#3658)
Brought the 15 strongly-typed diagnostic event classes in the Microsoft.Data.SqlClient.Diagnostics namespace (e.g., SqlClientCommandBefore, SqlClientConnectionOpenAfter, SqlClientTransactionCommitError) to .NET Framework as part of the codebase merge. These types were originally introduced for .NET Core in 6.0.
(#3493)
Enabled User Agent Feature Extension (opt-in via Switch.Microsoft.Data.SqlClient.EnableUserAgent).
(#3606)
Added actionable error message when Entra ID authentication methods are used without the Microsoft.Data.SqlClient.Extensions.Azure package installed.
(#3962,
#4046)
Fixed a connection performance regression where SPN generation was triggered for non-integrated authentication modes (e.g., SQL authentication) on the native SNI path. (#3929)
Fixed ExecuteScalar to propagate errors when the server sends data followed by an error token.
(#3912)
Fixed NullReferenceException in SqlDataAdapter when processing batch scenarios.
(#3857)
Fixed reading of multiple app context switches from a single AppContextSwitchOverrides configuration field.
(#3960)
Fixed an edge case in TdsParserStateObject.TryReadPlpBytes where zero-length reads returned null instead of an empty array.
(#3872)
Fixed issue where extra connection deactivation was occurring. (#3758)
Fixed debug assertion in connection pool (no impact to production code). (#3587)
Prevented uninitialized performance counters escaping CreatePerformanceCounters.
(#3623)
Fixed SetProvider to return immediately if user-defined authentication provider found.
(#3620)
Fixed connection pool concurrency issue. (#3632)
This update brings the following changes since the 6.1.6 release:
This update brings the following changes since the 6.1.6 release:
Microsoft.Data.SqlClient.SNI and Microsoft.Data.SqlClient.SNI.runtime dependencies to 6.0.3 (was 6.0.2).Fixed ServerCertificate validation on the managed SNI path so the configured certificate is compared against the server certificate even when the server certificate passes chain and host-name validation. When certificate validation is enabled, a missing, unreadable, or invalid certificate file, a certificate mismatch, or a missing server certificate now causes the TLS handshake to fail instead of bypassing the configured certificate check. (net8.0/net9.0 only)
(#4445, #4584)
Fixed Always Encrypted VSM/HGS enclave attestation to verify that the enclave public key used to establish a session matches the key committed to by the signed attestation report. Missing, malformed, or mismatched key-binding data now causes attestation to fail before the session secret is derived.
(#4532, #4552)
Fixed SqlConnection.AccessTokenCallback not disabling Transparent Network IP Resolution by default, making it consistent with SqlConnection.AccessToken. An explicitly configured TransparentNetworkIPResolution connection-string value still takes precedence. (net462 only)
(#4520, #4560)
Fixed token authentication state handling so clearing SqlConnection.AccessToken preserves an existing AccessTokenCallback in the connection pool key, and clearing AccessTokenCallback preserves an existing AccessToken. Callback-based authentication now also follows the same prelogin server-certificate validation rules as an explicitly supplied access token.
(#4520, #4560)
Fixed configurable retry logic installing a permanent, process-wide assembly-resolution handler that could interfere with unrelated assembly loading. The handler is now active only while an explicitly configured custom retry provider is resolved and constructed, and probes AppContext.BaseDirectory instead of the current working directory. Place custom retry assemblies in the application base directory; dependencies loaded after provider construction must be resolvable through normal application dependency resolution or an application-provided handler. (net8.0/net9.0 only)
(#2214, #4547, #4664)
Full details: release-notes/6.1/6.1.7.md
This update brings the following changes since the 6.1.5 release:
This update brings the following changes since the 6.1.5 release:
What Changed:
ActiveDirectoryAuthenticationProviderOptions options bag and a corresponding ActiveDirectoryAuthenticationProvider(ActiveDirectoryAuthenticationProviderOptions options) constructor were introduced, exposing a UseWamBroker property (alongside ApplicationClientId and DeviceCodeFlowCallback).SetParentActivityOrWindowFunc(Func<object> parentActivityOrWindowFunc) method so callers can supply a parent window handle on Windows or a parent Activity/UIViewController on Android/iOS/MAUI.Who Benefits:
ActiveDirectoryInteractive and other supported Entra ID authentication modes on Windows benefit from the WAM broker's improved security (tokens are brokered by the OS), single sign-on with the logged-in Windows account, and support for Conditional Access and Windows Hello.Impact:
ApplicationClientId, WAM is opt-in via ActiveDirectoryAuthenticationProviderOptions.UseWamBroker. Consider enabling it when you want OS-brokered tokens, single sign-on with the signed-in Windows account, Windows Hello, and Conditional Access support.UseWamBroker is a Windows-only setting and has no effect on non-Windows platforms, where interactive Entra ID flows always use the system browser.var options = new ActiveDirectoryAuthenticationProviderOptions
{
ApplicationClientId = "<your-app-client-id>",
// Enable WAM (Windows only) for OS-brokered tokens, SSO, Windows Hello, and Conditional Access.
UseWamBroker = true,
};
var provider = new ActiveDirectoryAuthenticationProvider(options);
// Supply the parent window/activity that owns the interactive sign-in prompt.
provider.SetParentActivityOrWindowFunc(() => parentWindowHandle);
SqlAuthenticationProvider.SetProvider(SqlAuthenticationMethod.ActiveDirectoryInteractive, provider);What Changed:
Who Benefits:
Impact:
Microsoft.Identity.Client to 4.84.2 (was 4.80.0)Microsoft.Identity.Client.Broker 4.84.2Fixed a NullReferenceException in SqlDataReader.GetChars on the PLP + CommandBehavior.SequentialAccess path when a null buffer was passed together with a negative bufferIndex. The call now correctly throws ArgumentOutOfRangeException for the bufferIndex parameter.
(#4159, #4205)
Fixed column master key (CMK) signature verification caching where GetSignatureVerificationResult returned whether the cache key existed rather than the cached value itself. Once a signature verification failure was cached as false, subsequent lookups incorrectly returned true, causing the caller to skip re-verification and treat the column master key as having a valid signature.
(#4339, #4356)
This update brings the following changes since the 6.1.5 release. See the full release notes for detailed descriptions.
ActiveDirectoryAuthenticationProviderOptions type with a UseWamBroker property, an ActiveDirectoryAuthenticationProvider(ActiveDirectoryAuthenticationProviderOptions options) constructor overload, and a cross-platform SetParentActivityOrWindowFunc(Func<object>) method.
(#4288,
#4387)Hardened TDS token parsing with data-length bounds checks to prevent unbounded memory allocation from a server spoofing length fields. (#4340, #4359)
Updated dependencies (#4387):
Microsoft.Identity.Client to 4.84.2 (was 4.80.0)Microsoft.Identity.Client.Broker 4.84.2Fixed a NullReferenceException in SqlDataReader.GetChars on the PLP + SequentialAccess path when a null buffer was passed with a negative bufferIndex; it now throws ArgumentOutOfRangeException.
(#4159,
#4205)
Fixed column master key (CMK) signature verification caching where a cached verification failure could subsequently be reported as a valid signature. (#4339, #4356)
This update brings the following changes since the 6.1.4 release:
This update brings the following changes since the 6.1.4 release:
ExecuteScalar to properly propagate errors when the server sends data followed by an error token. Previously, errors such as conversion failures during WHERE clause evaluation were silently consumed during SqlDataReader.Close() instead of being thrown to the caller, which could result in transactions being unexpectedly zombied. (#3736, #3947)SqlDataReader.GetFieldType and SqlDataReader.GetProviderSpecificFieldType to return the correct type (SqlVector<float>) for vector float32 columns. Previously, these methods did not follow the same type-resolution logic as GetValue, returning an incorrect type for vector columns. (#4104, #4151)This update brings the following changes since the 6.1.4 release. See the full release notes for target platform support and dependency information.
Fixed a connection performance regression where SPN (Service Principal Name) generation was triggered for non-integrated authentication modes (e.g., SQL authentication) on the native SNI path, causing unnecessary DNS lookups and significantly slower connection times. (#3523, #3946)
Fixed ExecuteScalar to properly propagate errors when the server sends data followed by an error token. Previously, errors such as conversion failures during WHERE clause evaluation were silently consumed during SqlDataReader.Close() instead of being thrown to the caller, which could result in transactions being unexpectedly zombied.
(#3736, #3947)
Fixed SqlDataReader.GetFieldType and SqlDataReader.GetProviderSpecificFieldType to return the correct type (SqlVector<float>) for vector float32 columns.
(#4104, #4151)
This update brings the following changes since the 6.1.3 release:
This update brings the following changes since the 6.1.3 release:
SqlDataAdapter when processing batch scenarios where certain SQL RPC calls may not include system parameters.
(#3877)What Changed:
Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefault to set MultiSubnetFailover=true by default in connection string.
(#3851)Who Benefits:
Impact:
// In application code
AppContext.SetSwitch("Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefault", true);
// In runtimeconfig.json
{
"configProperties": {
"Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefault": true
}
}
<!-- In App.Config -->
<runtime>
<AppContextSwitchOverrides value="Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefault=true" />
</runtime>
SqlStatistics execution timing by using Environment.TickCount instead of more expensive timing mechanisms.
(#3830)This update includes the following changes since the 6.1.2 release:
This update includes the following changes since the 6.1.2 release:
What Changed:
Switch.Microsoft.Data.SqlClient.IgnoreServerProvidedFailoverPartner was introduced to let the client ignore server-provided failover partner info in Basic Availability Groups (BAGs). When the switch is enabled, only the failover partner specified in the connection string is used; server-supplied partner values are skipped. This context switch was introduced in PR #3702.Who Benefits:
Impact:
AppContext.SetSwitch("Switch.Microsoft.Data.SqlClient.IgnoreServerProvidedFailoverPartner", true);
tcp:host,port) so that the client uses that instead of the server's suggestion.This update includes the following changes since the 6.1.1 release:
This update includes the following changes since the 6.1.1 release:
System.InvalidOperationException #3629This update includes the following changes since the 6.1.0 release:
This update includes the following changes since the 6.1.0 release:
SqlVector<T>.Null API signature in Reference assembly. #3521This update brings the following changes since the 6.1.0-preview2 release:
This update brings the following changes since the 6.1.0-preview2 release:
No new features were added.
What Changed:
Who Benefits:
Impact:
What Changed:
CreateNull() method.Size property was removed.Who Benefits:
Impact:
[Stable release 6.0.5] - 2026-01-15
This update brings the below changes over the previous stable release:
SqlDataAdapter when processing batch scenarios where certain SQL RPC calls may not include system parameters.What Changed:
Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefault to set MultiSubnetFailover=true by default in connection string.Who Benefits:
Impact:
// In application code
AppContext.SetSwitch("Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefault", true);// In runtimeconfig.json
{
"configProperties": {
"Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefault": true
}
}<!-- In App.Config -->
<runtime>
<AppContextSwitchOverrides value="Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefault=true" />
</runtime>.NET Framework 4.6.2:
.NET 8.0:
.NET 9.0:
This update brings the below changes over the previous stable release:
This update brings the below changes over the previous stable release:
What Changed:
Switch.Microsoft.Data.SqlClient.IgnoreServerProvidedFailoverPartner was introduced to let the client ignore server-provided failover partner info in Basic Availability Groups (BAGs). When the switch is enabled, only the failover partner specified in the connection string is used; server-supplied partner values are skipped. This context switch was introduced in PR #3703.Who Benefits:
Impact:
AppContext.SetSwitch("Switch.Microsoft.Data.SqlClient.IgnoreServerProvidedFailoverPartner", true);
tcp:host,port) so that the client uses that instead of the server's suggestion.This update brings the below changes over the previous stable release:
This update brings the below changes over the previous stable release:
This update brings the below changes over the previous release:
This update brings the below changes over the previous release:
NullPointerException during socket receive #3283This update brings the below changes over the previous release:
_No changes since the last preview release_
No changes since the last preview release
System.Private.Uri 4.3.2 - Avoid transitive CVE-2019-0820 (PR #3076)
This update brings the following changes since the 5.2.2 release:
NullPointerException during socket receive (PR #3284)Upgraded Azure.Identity version from 1.11.3 to 1.11.4 #2648 to address CVE-2024-35255.
AcquireTokenAsync timeout handling for edge cases in ActiveDirectoryAuthenticationProvider. #2650Socket.Connect in managed SNI. #2779AssemblyAttributes in obj folder causing NET 8.0 assembly to appear in NET 6.0 dll. #2789ArgumentNullException on SqlDataRecord.GetValue when using user-defined data type on .NET. #2816SqlDataReader against an encrypted column. #2817Azure.Identity version from 1.11.3 to 1.11.4 #2648 to address CVE-2024-35255.Microsoft.Identity.Client version from 4.60.0 to 4.61.3 #2648 to address CVE-2024-35255.TokenCredential objects to take advantage of token caching. #2775This update brings the below changes over the previous release:
This update brings the below changes over the previous release:
SqlConnection.FireInfoMessageEventOnUserErrors when set to true throws an exception #2505DATETIMEOFFSET(n) in a TVP if n is 1, 2, 3, or 4 #2506OpenAsync #2507SqlConnection.Clone() to include AccessTokenCallback #2527Upgraded Azure.Identity dependency version to 1.10.3 to address CVE-2023-36414, #2189
AccessTokenCallBack API to SqlConnection. #1260SqlBatch support on .NET 6+ #1825, #2223,#2371, #2373SqlDiagnosticListener on .NET Standard. #1931RowsCopied64 to SqlBulkCopy. #2004SuperSocketNetLib registry option for Encrypt on .NET on Windows. #2047SqlConnectionStringBuilder property indexer not supporting non-string values. #2018SqlDataAdapter.Fill and configurable retry logic issue on .NET Framework. #2084SqlConnectionEncryptOption type conversion by introducing the SqlConnectionEncryptOptionConverter attribute when using appsettings.json files. #2057AccessViolationException when using a SQL Express user instance #2101TdsParser. #1544Microsoft.Identity.Client version from 4.47.2 to 4.53.0. #2031, #2055ignoreSniOpenTimeout in open connection process on Windows. #2067StringComparison operations. #2068AppContext switches are in use #2227Azure.Identity dependency version to 1.10.3 to address CVE-2023-36414, #2189Microsoft.Data.SqlClient.SNI (.NET Framework dependency) and Microsoft.Data.SqlClient.SNI.runtime (.NET/.NET Standard dependency) version to v5.2.0. #2363, which includes removing dead code and addressing static analysis warningsThis update brings the following changes since the 5.1.8 release:
This update brings the following changes since the 5.1.8 release:
Azure.Core 1.41.0 (Avoids transitive vulnerability)
This update brings the following changes since the 5.1.7 release:
What Changed:
Switch.Microsoft.Data.SqlClient.IgnoreServerProvidedFailoverPartner was introduced to let the client ignore server-provided failover partner info in Basic Availability Groups (BAGs). When the switch is enabled, only the failover partner specified in the connection string is used; server-supplied partner values are skipped. This context switch was introduced in PR #3704.Who Benefits:
Impact:
AppContext.SetSwitch("Switch.Microsoft.Data.SqlClient.IgnoreServerProvidedFailoverPartner", true);
tcp:host,port) so that the client uses that instead of the server's suggestion.Microsoft.Identity.Client.PublicClientApplication
instances to use its builder pattern.
(#3367)SqlDecimal values.
(#3465)Microsoft.Extensions.Caching.Memory 6.0.1 to 6.0.3 - Avoid CVE-2024-43483 (PR #3068)
This update brings the following changes since the 5.1.6 release:
NullPointerException during socket receive (PR #3285)…to address CVE-2024-35255.
OpenAsync. #1983 #2508AcquireTokenAsync timeout handling for edge cases in ActiveDirectoryAuthenticationProvider. #2706SqlDataReader against an encrypted column. #2618 #2818Azure.Identity version from 1.11.3 to 1.11.4 [#2649] (https://github.com/dotnet/SqlClient/pull/2649) [#2529] (https://github.com/dotnet/SqlClient/pull/2529) to address CVE-2024-35255.Microsoft.Identity.Client version from 4.60.0 to 4.61.3 [#2649] (https://github.com/dotnet/SqlClient/pull/2649) [#2529] (https://github.com/dotnet/SqlClient/pull/2529) to address CVE-2024-35255.TokenCredential objects to take advantage of token caching. #2776…version 6.24.0 to 6.35.0 #2320 to address CVE-2024-21319
This update brings the below changes over the previous release:
Upgraded Azure.Identity dependency version to 1.10.3 to address CVE-2023-36414.
This update brings the below changes over the previous release:
Azure.Identity dependency version to 1.10.3 to address CVE-2023-36414.Fixed encryption downgrade issue. CVE-2024-0056
This update brings the below changes over the previous release:
This update includes the following changes over the previous release:
Thanks to the following public contributors. Their efforts toward this project are very much appreciated.
This update brings the below changes over the previous release:
This update brings the below changes over the previous release:
SqlConnectionStringBuilder property indexer issue. #2018SqlConnectionEncryptOption type conversion by introducing the SqlConnectionEncryptOptionConverter attribute when using appsettings.json files. #2057OpenAsync. #1983Microsoft.Data.SqlClient.SNI (.NET Framework dependency) and Microsoft.Data.SqlClient.SNI.runtime (.NET Core/Standard dependency) version to 5.1.1. #2123This update brings the below changes over the previous release:
This update brings the below changes over the previous release:
TransactionScope connection issue when Enlist is enabled, Pooling is disabled, and Network Connection Type is set to Redirect. #1967AcquireTokenSilent. #1966SqlCommand.ExecuteReaderAsync. #1965NullReferenceException in GetBytesAsync. #1964This update brings the below changes over the previous release:
This update brings the below changes over the previous release:
Microsoft.Data.SqlClient.SNI (.NET Framework dependency) and Microsoft.Data.SqlClient.SNI.runtime (.NET Core/Standard dependency) version to 5.1.0. #1889 which includes fix for AppDomain crash in issue #1418, TLS 1.3 Support, removal of ARM32 binaries, and support for the ServerCertificate option.Fixed memory leak regression from #1785 using a DisposableTemporaryOnStack struct. #1980
DisposableTemporaryOnStack struct. #1980TransactionScope connection issue when Enlist is enabled, Pooling is disabled, and Network Connection Type is set to Redirect. #1978SqlCommand.ExecuteReaderAsync. #1976Fixed missing HostNameInCertificate connection string property in .NET Framework. #1782
HostNameInCertificate connection string property in .NET Framework. #1782null to SqlConnectionStringBuilder.Encrypt. #1784ReadAsync() behavior to register Cancellation token action before streaming results. #1785This update brings the below changes over the previous release:
This update brings the below changes over the previous release:
TDS 8. To use TDS 8, users should specify Encrypt=Strict in the connection string. #1608TDS 8 version for TDSLogin. #1657FailoverPartner key on SQL servers with availability group configured. #1614EncryptionOptions. #1672Microsoft.SqlServer.Server netcore project package reference. #1654AuthProviderInfo struct to be matched the changes in native SNI for TDS 8 server certificate validation. #1680TDS 8 on managed code. #1678Microsoft.Data.SqlClient.SNI (.NET Framework dependency) and Microsoft.Data.SqlClient.SNI.runtime (.NET Core/Standard dependency) version to 5.0.0. #1680Fixed connection failure by not requiring Certificate Revocation List (CRL) check during authentication. #1706
Added new Attestation Protocol None for VBS enclave types. This protocol will allow users to forgo enclave attestation for VBS enclaves. #1419 #1425
Fixed connection to unsubscribe from transaction completion events before returning it to the connection pool #2301 #2435
Fixed encryption downgrade issue. CVE-2024-0056
Fixed Always Encrypted secure enclave retry logic for async queries. #1988
Fixed throttling of token requests by calling AcquireTokenSilent in AAD Integrated/Password flows when the account is already cached.#1995
Fixed connection failure by not requiring Certificate Revocation List (CRL) check during authentication. #1718
Added AppContext switch SuppressInsecureTLSWarning to allow suppression of TLS security warning when using Encrypt=false in the connection string. #14
Added AppContext switch SuppressInsecureTLSWarning to allow suppression of TLS security warning when using Encrypt=false in the connection string. #1457
Added missing SqlClientLogger class to .NET Core refs and missing SqlClientLogger.LogWarning method in .NET Framework refs #1392
SqlClientLogger class to .NET Core refs and missing SqlClientLogger.LogWarning method in .NET Framework refs #1392Code health improvements: #2147, #2515, #2517 addresses CVE-2019-0545, #2539
AcquireTokenAsync timeout handling for edge cases in ActiveDirectoryAuthenticationProvider. #2709Microsoft.Data.SqlClient assembly. #2789Nothing published for this version
Fixed encryption downgrade issue. CVE-2024-0056
Fixed Always Encrypted secure enclave retry logic for async queries. #1988
Fixed throttling of token requests by calling AcquireTokenSilent in AAD Integrated/Password flows when the account is already cached.#1926
Added Windows ARM64 support when targeting .NET Framework. #1908
Fixed null SqlBinary as rowversion. #1700
Added new Attestation Protocol None for VBS enclave types. This protocol will allow users to forgo enclave attestation for VBS enclaves. #1539
None for VBS enclave types. This protocol will allow users to forgo enclave attestation for VBS enclaves. #153942108 and 42109 error codes to retriable transient errors list. #1560Fixed async thread blocking issues on SqlConnection.Open() for active directory authentication modes. #1270
SqlConnection.Open() for active directory authentication modes. #1270LegacyRowVersionNullBehavior App Context switch. #1246RetryLogicProvider when calling SqlCommand.ExecuteScalarAsync. #1245Added support for column encryption key caching when the server supports retrying queries that require enclave computations #1062
Microsoft.Data.SqlClient.SNI (.NET Framework dependency) and Microsoft.Data.SqlClient.SNI.runtime (.NET Core/Standard dependency) version to v3.0.0 #1102Fixed encryption downgrade issue. CVE-2024-0056
Fixed TDS RPC error on large queries in SqlCommand.ExecuteReaderAsync.#1986
Added CommandText length validation when using stored procedure command types. #1726
Fixed issue with connection encryption to ensure connections fail when encryption is required. #1232
Your coding agent can read these notes before it upgrades. Set up the MCP server →