github Azure/azure-sdk-for-net Azure.Security.KeyVault.Keys_4.11.0-beta.4

latest release: Azure.Data.AI_1.0.0-beta.1
pre-release3 hours ago

4.11.0-beta.4 (2026-09-27)

Features Added

  • Added IDisposable to KeyClient, CryptographyClient, and KeyResolver to release internally owned HTTP pipelines and transports. Cryptography clients returned by a key client or resolver borrow its pipeline and do not dispose it; keep the parent alive until all use of those clients has completed. Caller-provided transports are not disposed.
  • Added a narrowly scoped bearer-token fallback for attested managed-identity tenant eligibility denials, with the decision remembered by the Key Vault client for subsequent token acquisitions.
  • Added support for Proof-of-Possession (PoP) token binding in the Key Vault authentication policy.

Bugs Fixed

  • Fixed intermittent authentication failures by retrying requests rejected because the mTLS Proof-of-Possession certificate did not match the token binding.
  • Fixed a NullReferenceException in the challenge-based authentication policy that could occur when a Continuous Access Evaluation (CAE) claims challenge was received for an authority that had not yet been cached.
  • Fixed an issue in the challenge-based authentication policy where a cached authentication challenge, and the access token acquired for it, could be reused for a request to a different Key Vault or Managed HSM endpoint. The policy now resolves the challenge per request endpoint, ensuring a token acquired for one vault is never attached to a request to another.

Don't miss a new azure-sdk-for-net release

NewReleases is sending notifications on new releases.