NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #299 most downloaded on NuGet
This package brings certificateless authentication.
Last release 5 days ago
01 Oct 2026
Release timing varies
gaps range from 8 days to 2 months
Most releases are documented
notes for 49 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
127 years old
122 releases · first in 1900
Updated to Microsoft.IdentityModel.* 8.0.0-preview3
Updated Azure.Identity to 1.11.4
Logging:LogLevel:Microsoft.Identity.Web is assigned to None, no default logger is initialized and Microsoft.Identity.Web does not record any logs. See #2816 for details.GraphAuthenticationProvider checks that the RequestInformation.URI is a Graph URI before appending the authorization header, resolving #2710. See PR #2818 for details.One column per quarter.
Remove netcoreapp3.1 support, see issue #2262 for details.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Updated to Microsoft.IdentityModel.* 7.5.1
./default, see issue #2796 for details.Updated to Microsoft.Identity.Abstractions 5.3.0
- Updated to MSAL 4.59.1.
Fix assertions being removed from dict before callback is executed in TokenAcquisition. See issue #2734 for details.
dict before callback is executed in TokenAcquisition. See issue #2734 for details.Updated to Microsoft.IdentityModel.* 7.5.0
Added support for CIAM custom user domains. You can now use an Open ID connect authority in the "Authority" property of the configuration instead of u
Updated to Microsoft.IdentityModel.* 7.4.0
ServiceDescriptor for containers which have keyed services present. This can be an issue on .NET 8.0. See issue #2676 for details.ConfidentialClientApplicationBuilderExtension.WithClientCredentials are fully async. See issue #2566 for details.Updated to Microsoft.IdentityModel.* 7.3.1 and MSAL.NET 4.59.0
AddTokenAcquisition(useSingleton:true) to use token acquisition as a singleton, if you use .AddMicrosoftGraph and/or .AddDownstreamApi after this call,
the GraphServiceClient and IDownstreamApis are now registered as a singleton service. For details see PR #2645Update Microsoft.Identity.Abstractions 5.1.0 and Microsoft.IdentityModel.* 7.1.2
Leverage IdentityModel 7.x on all .NET core frameworks.
Update to Microsoft.Graph 5.34.0
Update Azure.Identity library to 1.10.2 for CVE-2023-36414.
For the .NET 8 rc2 target framework, the IdentityModel dependencies have been updated to Identity.Model.*.7.0.3.
Updated IdentityModel dependencies to Identity.Model.*.6.33.0 for all target frameworks other than .NET 8 rc1, for which Microsoft,Identity.Web levera
Include new OpenIdConnect options from net 8. See PR #2462
Fix to accommodate for breaking change in ASP.NET Core on .NET 8 that the SecurityToken is now a JsonWebToken. See issue #2420
HttpResponse for success before returning to the caller, instead of swallowing issues. This is a change of behavior. See issue #2426Update to IdentityModel 7.0.0-preview2 on .NET 8.
IWebHostEnvironment is not present in the collection. If you want the ASP.NET Core host, you would need to use the WebApplication.CreateBuilder().Services instead
of instantiating a simple service collection.GetAuthenticationResultForUserAsync tries to find the inbound token from user.Identity.BootstrapContext first (if not null), and then from the token acquisition host. This will help for non-asp.NET Core Azure functions for instance.
See issue #2371 for details.Fix bug found in usage of AzureAD key issuer validator, see issue #2323.
Support new AzureAD key issuer validator in AddMicrosoftIdentityWebApi by default in Owin. See #2323 for details.
Update to Wilson 6.32.0 and Microsoft.Identity.Abstractions 4.0.0
Support new AzureAD key issuer validator in AddMicrosoftIdentityWebApi by default. See #2323 for details.
fix for CVE-2023-29331 in System.Security.Cryptography.Pkcs
System.Security.Cryptography.PkcsNothing published for this version
Id Web now supports the MS Graph v5 SDK, see issue #2097 for details.
Fix bug with signed assertion for AKS, see issue #2252 for details.
Id Web now supports [trimming](https://learn.microsoft.com/dotnet/core/deploying/trimming/trim-self-contained). See #2210
Microsoft.Identity.Web now provides more logging in DownstreamAPI, see #2148 for details.
Update to Wilson 6.29.0 and MSAL.NET 4.53.0
ID Web works with Authority in place of Tenant ID and Domain. See #2160
`MicrosoftIdentityAppCallsWebApiAuthenticationBuilder` is now available on netstandard2.0
MicrosoftIdentityAppCallsWebApiAuthenticationBuilder is now available on netstandard2.0GetClientAssertion protected.Update to Wilson 6.27.0 and MSAL.NET 4.51.0
GetClientAssertion is now public, which enables inheritance of ClientAssertionProviderBase. See PR for details.TryAdd instead of Add in the InMemory and Distributed caches, this is to not overwrite previously added caches. See issue for details.ResponseType == "code". See issue #2096 for details.Make ClientAssertion public, see for details.
Update Microsoft.Identity.Abstractions 1.0.5-preview, which has breaking changes.
Use ConcurrentDictionary for MergedOptions to resolve #1957
Enable using the TokenAcquireFactory default instance from anywhere in an ASP.NET Core application #1958
Nothing published for this version
Fix Component Governance alerts due to dependent packages. CVE-2022-1941 in Google.Protobuf and CVE-2022-34716 for netcoreapp3.1, cve-2022-29117 for O…
Leverage new Microsoft.Identity.Abstractions library, version 1.0.0-preview.
LoadCredentialsIfNeeded public.TokenAcquirerFactory with ASP NET core.ClientSecret to Owin config #1911.Support for Proof-of-possession (PoP) as introduced by MSAL.NET 4.47.2.
Leverages new Microsoft.Identity.Abstractions repo.
Detailed released notes here.
Detailed released notes here.
Nothing published for this version
- Merge the PR for #1957. - Update to Wilson 6.25.1
Use ConcurrentDictionary for MergedOptions to resolve #1957
Use ConcurrentDictionary for MergedOptions to resolve #1957
Fix from @rvplauborg to DownstreamWebApiOptions.Clone, which was missing two properties. #1970
Fixes a race condition only present in .NET 7 - #1957
Fixes a race condition only present in .NET 7 - #1957
Update to latest IdentityModel 6.25.0
Fix Component Governance alerts due to dependent packages. CVE-2022-1941 in Google.Protobuf, CVE-2022-34716 for netcoreapp3.1, CVE-2021-24112 in Syste…
Update to latest IdentityModel 6.23.1, which has 20% perf improvements.
Fix Component Governance issues due to dependent packages. CVE-2022-34716 - in DataProtection 5.0.8
Microsoft.Identity.Web now surfaces the Microsoft.IdentityModel.* logs via the IIdentityLogger. Developers will see an increase in logging, with insig
Microsoft.Identity.Web now surfaces the Microsoft.IdentityModel. logs via the IIdentityLogger*. Developers will see an increase in logging, with insight into the request validation logs, especially for web APIs. See issue #1730 for details.
Regression fix where AddMicrosoftIdentityUserAuthenticationHandler needs a scoped service, not a singleton. See issue #1757 for details.
Microsoft.Identity.Web now supports checking for scopes or app permissions, via the RequestedScopeOrAppPermissionAttribute. See issue #1641 for detail
Microsoft.Identity.Web now supports checking for scopes or app permissions, via the RequestedScopeOrAppPermissionAttribute. See issue #1641 for details.
Extend TokenAcquisitionTokenCredential concept to support tokens as app. See issue #1723 for details.
IJwtBearerMiddlewareDiagnostics is now transient and not a singleton. See issue #1710 for details.
In web API scenario, use the tid claim of the incoming assertion, unless overridden. See issue #1738 for details.
Your coding agent can read these notes before it upgrades. Set up the MCP server →