NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #2521 most downloaded on NuGet
Interface for higher level API for confidential client applications.
Last release 7 days ago
01 Oct 2026
Release timing varies
gaps range from 8 days to 2 months
Most releases are documented
notes for 44 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
127 years old
85 releases · first in 1900
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
Full Changelog: 4.15.0...4.16.0
One column per quarter.
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
/Validate endpoint accepts Signed HTTP Request proof-of-possession tokens for app-only client-credential flows. #4008Microsoft.Identity.Web.KeyAttestation package and AddMicrosoftIdentityWebKeyAttestation() registration. #4004AgentUserId values return HTTP 400. #4011ForwardedHeaders_Enabled=true. #4018/healthz. #4023ContainerUser, and ACL authorization defaults are correctly applied to named bearer options. #4042Microsoft.Identity.Client and Microsoft.Identity.Client.KeyAttestation: 4.87.0 -> 4.90.0. #4003 #3994 #4052Microsoft.Identity.Abstractions: 12.6.0 -> 12.7.0. #4020 #3994Full changelog: 4.14.2...4.15.0
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
Microsoft.IdentityModel.* (Wilson) version to 8.22.0. See #3986.System.Security.Cryptography.Xml 8.0.4 (and its System.Security.Cryptography.Pkcs 8.0.1 dependency) instead of over-bumping to the 9.0.18 servicing line (CVE-2026-47302, -47304, -50525, -50648). net9.0 (9.0.18) and net10.0 (10.0.10) are unchanged. See #3989.The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
MicrosoftIdentityOptions.PartitionAppTokenCacheByAudience to partition the app token cache by resource/audience. See #3979.TokenAcquisitionExtensionOptions.OnBackgroundTokenRefreshCompleted. See #3973.MicrosoftIdentityOptions.UseFastUnboundedCache; stop short-circuiting the in-memory token cache serialization provider. See #3970.Microsoft.Identity.Web.OidcFIC) now supports mTLS token binding. See #3851.UseBoundCredential = true) from its unbound equivalent; the certificate-error retry path invalidates the cache entry for the actual request mode (bearer vs mTLS PoP).Microsoft.Identity.Client → 4.87.0 (#3975)Microsoft.Identity.Abstractions → 12.6.0 (#3976)System.Security.Cryptography.Xml / System.Security.Cryptography.Pkcs → patched (CVE-2026-47302, -47304, -50525, -50648) (#3964)Full changelog: 4.13.2...4.14.0
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
Full Changelog: 4.13.0...4.13.2
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
Full Changelog: 4.12.2...4.13.0
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
Microsoft.Identity.Client.KeyAttestation dependency conditional on modern .NET (.NETCoreApp) targets. It transitively pulls the native-only Microsoft.Azure.Security.KeyGuardAttestation package, which ships no .NET Framework/netstandard-compatible assets and broke NuGet restore for .NET Framework (packages.config) projects. Microsoft.Identity.Web.Certificateless now multi-targets, and .NET Framework consumers use the netstandard2.0 asset without this dependency. See #3894.The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
ManagedIdentity when converting AcquireTokenOptions to TokenAcquisitionOptions in TokenAcquirer. Previously the ITokenAcquirer.GetTokenForAppAsync / GetTokenForUserAsync paths silently dropped ManagedIdentity and fell back to the confidential-client path, breaking managed-identity mTLS PoP (e.g. MISE Native). See #3914.Sidecar:AllowOutboundRedirects flag (default false) restores the previous behavior. See #3906.IOptionsMonitor are now cloned per request (including fresh ExtraParameters / ExtraHeaderParameters / ExtraQueryParameters dictionaries), preventing request-scoped values from leaking across requests or racing under concurrency. See #3919.The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-
The release notes are available at https://github.com/AzureAD/microsoft-identity-web/releases and the roadmap at https://github.com/AzureAD/microsoft-identity-web/wiki#roadmap
IAuthorizationHeaderProvider2 (from Microsoft.Identity.Abstractions 12.3.0) on DefaultAuthorizationHeaderProvider and the public BaseAuthorizationHeaderProvider, exposing the metadata-rich CreateAuthorizationHeaderInformation* surface (returning OperationResult<AuthorizationHeaderInformation, AuthorizationHeaderError>) with binding-certificate propagation. DownstreamApi and MicrosoftIdentityMessageHandler now prefer IAuthorizationHeaderProvider2 for mTLS PoP and soft-deprecate the bound-only IBoundAuthorizationHeaderProvider path (kept as a fallback for source/binary compatibility). See #3899.TokenAcquisitionMetadata.ExpiresOn on AcquireTokenResult from the MSAL AuthenticationResult.ExpiresOn value. See #3905.DownstreamApi request (headers, query parameters, content, and customizations) before creating the authorization header, adding Authorization only after signing so request-binding providers do not include it in their signed material. See #3902.Fix CVE-2026-48109 : Pin MessagePack to patched version 2.5.301 by Tanuj Sood (@soodt) in #3865
Full Changelog: 4.10.0...4.11.0
Add WithExtraBodyParameters fluent API for attaching extra body parameters to token acquisition requests. See #3819 .
WithExtraBodyParameters fluent API for attaching extra body parameters to token acquisition requests. See #3819.IConfidentialClientApplicationProvider extensibility interface and CachePartitionKey support for silent token acquisition. See #3822.Authority values with a clearer exception, steering users to use Instance + TenantId instead. See #3805.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Bump MSAL.NET to version 4.79.2 and handle changes to deprecated WithExtraQueryParameters APIs. #3583
Correctly compute Application Key when credential usage fails. #3487
Removed support for .NET 6.0 and .NET 7.0 - Microsoft Identity Web 4.0.0 no longer targets .NET 6.0 and .NET 7.0, following Microsoft's support lifecy
Removed support for .NET 6.0 and .NET 7.0 - Microsoft Identity Web 4.0.0 no longer targets .NET 6.0 and .NET 7.0, following Microsoft's support lifecycle. The supported target frameworks are now .NET 8.0, .NET 9.0, .NET Framework 4.6.2, .NET Framework 4.7.2, and .NET Standard 2.0.
Improve User Agent processing in cookie policy extensions. See PR #3824 for details.
Microsoft.Kiota.Abstractions to 1.22.0 for GraphServiceClient, fixing NU1903 build break caused by the GHSA-7j59-v9qr-6fq9 advisory. See PR #3818 for details.Microsoft.Kiota.Abstractions to 1.22.0 for GraphServiceClientBeta, fixing the same advisory. See PR #3827 for details.Nothing published for this version
Support client secrets with agent user identities. See #3470 for details.
Support multi-tenant agent user identities. See #3461 for details.
Updated MSAL.NET to version 4.76.0
Microsoft.IdentityModel updated to version 8.14.0.
Microsoft.Abstractions updated to version 9.3.0 and using IAuthenticationSchemeInformationProvider from that library, deprecating the interface of the…
Updated MSAL to version 4.74.1 part of #3398.
Reload certificates for all client credential based issues to solve the issue that when a bad certificate was installed on the machine and picked up, and subsequently rotated, a service restart was needed for the new certificate to be used. See issue #3429 and PR #3430
Updated global.json to the latest .NET 9 runtime framework 9.0.108. See PR #3422 for details.
global.json to the latest .NET 9 runtime framework 9.0.108. See PR #3422 for details.IDW10405 error when using managed identity with common tenant. See PR #3415 for details.OidcIdpSignedAssertionLoader to remove hard dependency on IConfiguration registration. See PR #3414 for details.ExtraHeaderParameters and ExtraQueryParameters properties on DownstreamApiOptions to simplify adding custom headers and query parameters to downstream API requests. See PR #3413 for details.Updated MSAL to version 4.73.1 #3398.
global.json to the latest .NET 9 runtime framework 9.0.107 #3385.Microsoft.Identity.Web.AgentIdentities package .Microsoft.IdentityModel updated to version 8.12.1.
DefaultAuthorizationHeaderProvider to update the AcquireTokenOptions.LongRunningWebApiSessionKey after the token is acquired so that the key can be used in the next OBO call. See PR #3381 for details.Microsoft.IdentityModel updated to version 8.12.0.
.clinerules to help with AI tooling.Microsoft.IdentityModel updated to version 8.11.0.
Microsoft.Identity.Abstractions updated to version 9.1.0.
Microsoft.IdentityModel updated to version 8.10.0.
Thank you @evan-buss for your contribution and fixing the issue where RequiredScopeOrAppPermission extension method didn’t work with Minimal APIs. See #3323. Thank you @neha-bhargava for your contribution and ensuring AcquireTokenForConfidentialClient correctly passes MSAL exceptions. See #3345.
Microsoft.IdentityModel updated to version 8.9.0.
Updated to Microsoft.IdentityModel.* 8.8.0
TokenAcquistion.cs adds its service provider to the acquisition options. See issue #3315 for details.Updated to Microsoft.Identity.Abstractions 9.0.0
Updated to Microsoft.IdentityModel.* 8.7.0
Updated to Microsoft.IdentityModel.* 8.6.1
FmiPath property of AcquireTokenOptions. See #3247Updated to Microsoft.IdentityModel.* 8.5.0
Updated to Microsoft.Identity.Abstractions 8.1.0
DefaultCredentialsLoader so that partner teams, or an SDK on top of IdWeb, can bring their own credential providers. See #3220 for details.Updated to Microsoft.Identity.Abstractions 8.0.0
Updated to Microsoft.Identity.Abstractions 7.2.1
Updated to Microsoft.IdentityModel.* 8.3.1
OpenIdConnectCachingSecurityTokenProvider. See Issue #3078Updated to Microsoft.IdentityModel.* 8.3.0
Updated to Microsoft.IdentityModel.* 8.2.1
…8.0.0, which has an interface breaking change, not yet implemented in Microsoft.Identity.Web. See PR #2962 for details.
CaseSensitiveClaimsIdentity by default and provides AppContextSwitches to fallback to using ClaimsIdentity. This means that when you loopup claims with FindFirst(), FindAll() and HasClaim(), you need to provide the right casing for the claim. See PR #2977 for details.GetTokenAcquirer now sets SendX5C in particular protocols. See issue #2887 for details.The input string " was not in a correct format when enabling same-site cookie compatibility with userAgent: "Dalvik/2.1.0 (Linux; U; Android 12; Chromecast Build/STTE.230319.008.H1). See issue #2879 for details.AzureKeyVault@2 in AzureDevOps, #2981.========
See rel/v2 branch changelog for changes to all 2.x.x versions after 2.18.1.
The changes listed in the rel/v2 changelog are also in the 3.x.x versions of Id Web but are not listed here.
========
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Updated to Microsoft.IdentityModel.* 7.5.1
./default, see issue #2796 for details.Your coding agent can read these notes before it upgrades. Set up the MCP server →