4.9.0-beta.3 (2026-09-27)
Features Added
- Added
IDisposabletoKeyVaultAccessControlClient,KeyVaultBackupClient,KeyVaultEkmClient, andKeyVaultSettingsClientto release internally owned HTTP pipelines and transports. Reuse clients and dispose them after all operations and polling have completed; caller-provided transports are not disposed. - Added a narrowly scoped bearer-token fallback for attested managed-identity tenant eligibility denials, with the decision remembered by the Key Vault client for subsequent token acquisitions.
- Added support for Proof-of-Possession (PoP) token binding in the Key Vault authentication policy.
Bugs Fixed
- Fixed intermittent authentication failures by retrying requests rejected because the mTLS Proof-of-Possession certificate did not match the token binding.
- Fixed a
NullReferenceExceptionin the challenge-based authentication policy that could occur when a Continuous Access Evaluation (CAE) claims challenge was received for an authority that had not yet been cached. - Fixed an issue in the challenge-based authentication policy where a cached authentication challenge, and the access token acquired for it, could be reused for a request to a different Key Vault or Managed HSM endpoint. The policy now resolves the challenge per request endpoint, ensuring a token acquired for one vault is never attached to a request to another.