Skip to content

Parity changelog

How the feature-parity map changed across releases — generated by diffing the parity tables between consecutive v* tags.

Current (latest-da4d56a): 68 🟢 Real · 6 🟡 Emulated · 3 🟠 BYO-engine · 16 🔴 Not implemented.

No parity changes.

No parity changes.

  • SCIM service provider (inbound): ServiceProviderConfig, ResourceTypes, Schemas; Users + Groups CRUD, PatchOp: 🔴 → 🟢
  • SCIM provisioning client (outbound): filter-probe → create / update / active:false deprovision, member-correlated groups, incremental watermark: 🔴 → 🟢
  • Provisioning scheduler (the ~40-minute cycle): 🔴 → 🟡
  • MSAL.NET (Microsoft.Identity.Client): 🔴 → 🟢
  • msal4j (Java): 🔴 → 🟢
  • OpenFGA · SpiceDB · Keto · Permify · Casbin · OPA · Cedar: 🔴 → 🟢

No parity changes.

  • wids (directory-role template GUIDs): 🔴 → 🟢
  • Instance discovery (/common/discovery/instance): 🔴 → 🟢
  • Recycle bin (directory/deletedItems, restore, permanent delete): 🔴 → 🟡
  • OAuth2 permission grants (consent): 🔴 → 🟢
  • Directory roles (roleManagement/directory): 🔴 → 🟢
  • Authentication methods inventory (password / FIDO2): 🔴 → 🟡
  • @microsoft/microsoft-graph-client: 🔴 → 🟢

No parity changes.

No parity changes.

  • Graph permission enforcement (scopes/roles gating operations): 🔴 → 🟢
  • PUT /Groups/{id}: 🔴 → 🟢
  • Cloud-instance metadata (tenant_region_scope, cloud_instance_name, cloud_graph_host_name, msgraph_host, rbac_url): added 🟢
  • Sovereign clouds (US Gov / China / Germany instance routing): added 🔴
  • Cloud-instance metadata (tenant_region_scope, cloud_instance_name, sovereign clouds): removed
  • private_key_jwt client assertion: 🟡 → 🟢
  • Implicit / hybrid flow: 🔴 → 🟢
  • Custom role definitions: 🔴 → 🟢
  • Workload identity federation (federatedIdentityCredential): 🔴 → 🟢
  • Token signing algorithm: added 🟢
  • RP-initiated logout (end_session_endpoint): added 🟢
  • Front-channel logout (OP calls each RP’s frontchannel_logout_uri): added 🟢
  • JAR by reference (request_uri, RFC 9101): added 🟢
  • Inline request parameter: added 🟢
  • PAR (pushed authorization requests): added 🟢
  • Administrative units: added 🟢
  • Custom security attributes: added 🟢
  • Sign-in logs (Graph auditLogs/signIns): added 🟢
  • Directory audit logs (Graph auditLogs/directoryAudits): added 🔴
  • Password reset (Graph authentication/passwordMethods/{id}/resetPassword): added 🟢
  • Interactive SSPR (verify by email / SMS / security questions at passwordreset.microsoftonline.com): added 🔴
  • B2B guest invitations: added 🟢
  • Cross-tenant access policies (partner settings, inbound/outbound trust): added 🔴
  • Graph route for federatedIdentityCredentials: added 🔴
  • Signing algorithms other than RS256 (ES256 / PS256): removed
  • Front-channel logout: removed
  • PAR / JAR (request_uri): removed
  • Administrative units, custom security attributes: removed
  • Sign-in / audit logs (Graph auditLogs, signIns): removed
  • SSPR / password reset: removed
  • B2B guest invitations / cross-tenant access: removed

No parity changes.

  • Directory audit logs (Graph auditLogs/directoryAudits): 🔴 → 🟢
  • Graph route for federatedIdentityCredentials: 🔴 → 🟢
  • @azure/msal-browser: 🔴 → 🟢
  • Token lifetime policies: added 🟢
  • Claims-mapping policies: added 🔴
  • CORS on the OIDC surface: added 🟢
  • Token-lifetime / claims-mapping policies: removed
  • User realm probe (/common/UserRealm/{user}): added 🟢
  • getMemberObjects / getMemberGroups: added 🟢
  • SAML 2.0 SP-initiated SSO: added 🟢
  • WS-Federation: added 🔴
  • SAML / WS-Federation: removed
  • Wilson (Microsoft.IdentityModel): added 🟢
  • Chromium navigator.credentials: added 🟢
  • fabric-emulator (workspace-identity handshake): added 🟢
  • Chromium implicit / hybrid: added 🟢
  • Azure CLI (az): added 🟢
  • WS-Federation: 🔴 → 🟢

No parity changes.

No parity changes.

No parity changes.