Repository navigation
Add AuthenticationPolicy resource and Application Gateway authConfigs binding for 2026-01-01 - #45764
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
|
Azure Pipelines: Successfully started running 9 pipeline(s). 5 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Next Steps to Merge✅ All automated merging requirements have been met! To get your PR merged, see aka.ms/azsdk/specreview/merge.Comment generated by summarize-checks workflow run. |
TypeSpec suppressions requiring review (testing, non-blocking)Status: ❌ Approval required (currently under testing, review NOT enforced) — 11 suppressions
New suppressions (11)
Showing 5 of 11 suppressions. See the full analysis log for the complete list. For an overview of TypeSpec linting rules click here. 💬 Have feedback on the TypeSpec suppression flow? Let us know. |
API Change CheckAPIView identified API level changes in this PR and created the following API reviews
Comment generated by After APIView workflow run. |
|
Azure Pipelines: Successfully started running 9 pipeline(s). 5 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
|
Addressed the service contract review in commit 0b6d367:
TypeSpec compilation, formatting, semantic validation, and example validation all pass locally. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
|
ajaygit158 Addressed in 4dc7321. AuthenticationPolicy now exposes a tags-only I also addressed the introduced Swagger LintDiff findings by adding |
84d8d4c
into
Azure:release-microsoft-network-2026-01-01
* Add API version 2026-01-01 for Microsoft.Network (#45569) Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com> * Add Enum values for VPN migrationType (#45647) Co-authored-by: Akshat Kale <akale@microsoft.com> * Fix Bug 38477992: type computedDisabledRules.rules as integers (2026-01-01) (#45621) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com> Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3 * [Network] Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01 (#45625) * Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01 Ports the change from azure-rest-api-specs-pr PR 29807 onto the public 2026-01-01 release branch. Adds three read-only properties that NRP surfaces from api-version 2026-01-01 for Application Gateway WAF: - paranoiaLevel on ApplicationGatewayFirewallRule - displayName on ApplicationGatewayFirewallRuleSetPropertiesFormat - displayName on ApplicationGatewayFirewallManifestRuleSet - displayName on DefaultRuleSetPropertyFormat paranoiaLevel uses a new extensible enum ApplicationGatewayWafRuleParanoiaLevel with values PL1 to PL4. All new members are annotated with @added(Versions.v2026_01_01). The change is additive and all new properties are optional. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Retrigger CI The SDK Validation - Rust build failed on a transient GitHub timeout while installing the Azure SDK Tools CLI. Nothing in the spec changed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Centurion WAF: add WAF policy tier + Basic_v2/Basic_WAF_v2 SKUs (2026-01-01) (#45766) * Add Centurion WAF updates for 2026-01-01 Update WAF policy tier and reserved capacity support. Add Basic_v2 and Basic_WAF_v2 SKUs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Basic v2 application gateway tiers WebApplicationFirewallPolicyTier ordering aligns Standard=0 and Basic=1. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Basic WAF and application gateway examples Add Basic WAF policy create/get examples and Basic-tier coverage. Add Basic_v2 and Basic_WAF_v2 application gateway create/get examples, including reservedCapacity and WAF policy association. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add AuthenticationPolicy resource and Application Gateway authConfigs binding for 2026-01-01 (#45764) * Add AuthenticationPolicy support for 2026-01-01 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Align AuthenticationPolicy contract with service behavior Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Enforce AuthenticationPolicy name and binding constraints Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Add authentication policy tags update Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 --------- Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 (#45650) * Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 Adds optional min/max allocation-size bounds to the Microsoft.Network IpamPool resource in api-version 2026-01-01: - IpamPoolProperties (PUT/GET): minAllocationSize, maxAllocationSize - IpamPoolUpdateProperties (PATCH): minAllocationSize, maxAllocationSize marked x-nullable so an explicit null clears the bound while an absent bound is preserved, per ARM merge-patch semantics. Both properties are gated with @added(Versions.v2026_01_01) so earlier api-versions are unchanged. Regenerated virtualNetwork.json and updated the 2026-01-01 IpamPools Create/Get/List/Update examples. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Move min/max allocation size into dedicated IpamPool examples The allocation-size bounds are optional, so the baseline IpamPools examples should not imply they are always supplied. Restores IpamPools_Create/Get/List/Update to their original content and adds dedicated examples that exercise the feature: - IpamPools_CreateWithAllocationBounds.json: PUT setting both bounds. - IpamPools_UpdateAllocationBounds.json: PATCH setting both bounds. - IpamPools_UpdateClearAllocationBounds.json: PATCH clearing both bounds with an explicit null, per ARM merge-patch semantics. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address ARM review: drop nullable union on new min/max update properties New properties must not use a nullable union, since backward compatibility does not apply to additions. The RP already treats an empty string as a clear on PATCH, so the explicit null is unnecessary. - IpamPoolUpdateProperties min/maxAllocationSize: string | null -> string, removing the no-nullable suppressions and x-nullable from the swagger. - Document clearing via an empty string. - IpamPools_UpdateClearAllocationBounds example now clears with "". Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add Swagger Avocado suppression for frozen 2018-10-01 VMSS surface Per ARM reviewer guidance on PR #45650: the package-2026-01-01 default tag intentionally retains stable/2018-10-01/vmssNetwork.json for backward compatibility, which trips Avocado's MULTIPLE_API_VERSION rule. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix Avocado suppression tool name to SwaggerAvocado Per ARM reviewer bot feedback on PR #45650: the suppression tool name has no space. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add approvalReference to private endpoint connection in 2026-01-01 (#45604) * Add approvalReference (create-only) to private endpoint connection in 2026-01-01 Adds optional approvalReference.privateEndpointId to PrivateLinkServiceConnectionProperties, gated @added(v2026_01_01) with @visibility(Lifecycle.Read, Lifecycle.Create) so it is create-only (emits x-ms-mutability: [read, create]) and is not resupplied on update. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Regenerate vmssNetwork.json for approvalReference (Vmss project) The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and emits stable/2018-10-01/vmssNetwork.json, which must be regenerated so approvalReference/ApprovalReference are included. Fixes TypeSpec Validation (Vmss). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Remove x-ms-mutability (create-only) from approvalReference Per internal discussion, drop the create-only mutability restriction on approvalReference. Removes the @visibility(Lifecycle.Read, Lifecycle.Create) decorator in Common/main.tsp and regenerates the Network and Vmss project swaggers so x-ms-mutability is no longer emitted. The approvalReference property and ApprovalReference model are retained. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Type approvalReference.privateEndpointId as armResourceIdentifier Address ARM review finding [TSP-ARM-RESOURCE-ID]: privateEndpointId references an existing private endpoint, so type it as Azure.Core.armResourceIdentifier<Microsoft.Network/privateEndpoints> instead of plain string. Regenerated swagger emits format: arm-id and x-ms-arm-id-details.allowedResources. --------- Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Add ExpressRoutCircuit on ExpressRouteLag (#45689) * Add ExpressRoutCircuit on ExpressRouteLag * Fix ExpressRouteLag examples: sync circuits to output copies and remove invalid circuit properties Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Align ExpressRouteCircuitCreateOnExpressRouteLag responses with request (EX-PARAM-CONSISTENCY) Fix response bodies to match request: LAG reference lagName (was test), enableDirectPortRateLimit true, and SKU Premium_MeteredData in the 200 response. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * Add AppGw Advanced Routing Rule in NRR API 2026-01-01 (#45844) * Add advanced routing features to Application Gateway for API version 2026-01-01 * buid artifacts after changes to models.tsp * added examples * fix merge conflict --------- Co-authored-by: Paawan Kohli <paawankohli@microsoft.com> * Modify sdk-suppressions.yaml for breaking changes (#45914) Updated breaking changes for Azure SDK suppressions in network resource manager. * [Microsoft.Network] Add provider-led ExpressRoute circuit migration APIs (#45905) * Add ExpressRoute circuit migration APIs Add TypeSpec operations and models for provider-led ExpressRoute circuit migration, generated 2026-01-01 Swagger, examples, and the scoped brownfield resource-name suppression. * Fix Network specification validation Use valid UUID subscription IDs, add required TypeSpec example metadata, regenerate migration LRO metadata, and suppress the intentional mixed-version VMSS surface in the combined Network package. * Fix Network Avocado suppression Move the mixed API-version exception from an unsupported AutoRest directive to the Network SwaggerAvocado path-suppression file, scoped to the default-tag readme. * Fix Network validation suppressions * Correct Avocado suppression identifier * Geo-Ip filter changes (#45631) * Geo Ip Filter Changes * Document GeoIP filter format (ISO 3166-1 alpha-2) and fix WAF scrubbing-rule model * Fixing Swagger ModelValidation Filure related errors * Dummy Push to reinitate build * Type Spec validation failure fix * Remove duplicate GeoIP filter properties --------- Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com> * Add NeuroShield API for 2026-01-01 (#45722) * Add NeuroShield API for 2026-01-01 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add NeuroShield API for 2026-01-01 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Align NeuroShield contract with service behavior Require customer-facing configuration, align mitigation responses with the safe service projection, make cancellation synchronous, and correct protected-resource delete polling. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Refine NeuroShield 2026-01-01 contract Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Fix NeuroShield validation regressions * Address ARM review feedback for NeuroShield Use supported ARM resource templates, scope Swagger suppressions to exact operations, and isolate inherited Network validation debt. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Fix NeuroShield LintDiff suppressions * Use standard ARM entity tag property --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Add post calls for auth key of authorization objects for expressrouteciruits and expressrouteports (#45679) * Added post calls for expressroute auth key * Added the objects in 2026-01-01 version * addressed ai comments * Addressed comments * fixed * removed suppression * fixed suppressions --------- Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com> Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com> * Fix Hub virtual network IPv6 peering contract (#45637) * Fix IPv6 peering contract for Network 2026-01-01 * Correct IPv6 peering contract in Network 2025-09-01 * Update client.tsp * Update sdk-suppressions.yaml --------- Co-authored-by: Caren Lim <carenlim@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: kazrael2119 <98569699+kazrael2119@users.noreply.github.com> * Correct AuthenticationPolicy contract for 2026-01-01 (#45892) * Correct authentication policy contract Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Keep provider type extensible Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Document authentication policy constraints Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Align authentication examples with service Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Restore authentication policy tags update Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Suppress PatchIdentityProperty for AuthenticationPolicies_UpdateTags The tags-only PATCH takes the shared Network RP TagsObject body, matching ApplicationGateways_UpdateTags. The service only updates tags on this operation, so identity does not belong in the request body. * Complete authentication policy constraints Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Correct Basic v2 authentication example Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Address ARM review feedback on AuthenticationPolicy 2026-01-01 - Make the arm-resource-invalid-envelope-property suppression reason self-contained by stating why the user-assigned identity belongs in the resource envelope. - Scope the PatchIdentityProperty suppression with a where: clause targeting the AuthenticationPolicies_UpdateTags PATCH operation. - Type issuer as url and require an https scheme, consistent with jwksUri and clientSecret. - Document the sessionTimeout string syntax and units, and constrain it with a base-10 integer pattern and max length. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Also scope PatchIdentityProperty suppression to the PATCH body parameter path Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Remove AuthenticationPolicy PATCH operation The service supports only GET, PUT, and DELETE for authenticationPolicies, matching ApplicationGatewayWebApplicationFirewallPolicies, which also ships without a PATCH. Removing the tags-only PATCH also resolves the PatchIdentityProperty finding at its source: that rule fires only on an existing PATCH, so with no PATCH the identity envelope property no longer needs a suppression. - Remove AuthenticationPolicies_UpdateTags and its source and generated examples. - Drop the PatchIdentityProperty suppression. - Restore the TrackedResourcePatchOperation no-PATCH suppression. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Drop stale PATCH path from ProvisioningStateMustBeReadOnly suppression The AuthenticationPolicy PATCH operation was removed, so the patch response entry in the where: list no longer matches anything. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Restore AuthenticationPolicy PATCH with a resource-specific update model AuthenticationPolicy is a tracked resource: it extends the Network RP Resource base type, which supplies location, tags and x-ms-azure-resource. ARM requires resource providers to support PATCH for updating tags on a tracked resource, so removing the operation was incorrect. Restore PATCH using a resource-specific AuthenticationPolicyUpdateParameters model carrying both tags and identity, rather than the shared TagsObject. This satisfies the tracked-resource tags requirement and the MSI onboarding requirement that the control plane accept identity updates on PATCH, which means PatchIdentityProperty is now satisfied at the source and needs no suppression. - Add AuthenticationPolicyUpdateParameters (tags, identity). - Add AuthenticationPolicies_Update, replacing the former tags-only AuthenticationPolicies_UpdateTags. - Add an example exercising both tags and identity updates. - Drop the TrackedResourcePatchOperation suppression, no longer applicable. - Scope ProvisioningStateMustBeReadOnly to the new PATCH 200 response schema. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Add bastion session recording configuration and identity properties (#45630) * Add bastion session recording configuration property * Fix the patch body for identity support * Update examples * Fix prettier violation * Revert documentation changes * Add BastionHostUpdate model instead of anonymous type * Add tpye constraint for userAssignedIdentityId * Fix invalid arm id for public ip in example * Fix wrong name in 200 responses in new examples * Fix documentation for BastionHostUpdate * Preserve existing updateTags operation * Update suppression justification * Revert previous changes which maintained the old operation * Update suppression justification for update operation --------- Co-authored-by: Matthew Lee <matthelee@microsoft.com> * Add azureFirewall enableAiAddOn (#45976) * Add azureFirewall enableAiAddOn * Enable aiSecurityAddOn in Azure Firewall configuration Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * copilot messed up, fix typescript * fix fields in exampels * fix fields in examples --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Revert "Add NeuroShield API for 2026-01-01 (#45722)" (#46208) This reverts commit efb6f29. * Address swagger review findings on AuthenticationPolicy for 2026-01-01 (#46260) * Address swagger review findings on AuthenticationPolicy Resolves five of the review findings at the source rather than by suppression, removing four AuthenticationPolicy suppressions. RequiredReadOnlySystemData: declare systemData explicitly on AuthenticationPolicy, following the existing Network RP pattern used by AdminRuleCollection, BaseAdminRule and Commit. It is emitted read-only. RPC-Delete-V1-01: drop the ArmDeletedNoContentResponse override so the sync DELETE emits 200, 204 and default. AuthenticationPolicy was the only resource in this project overriding the delete response; every sibling uses the default. Removes the DeleteResponseCodes and DeleteOperationResponses suppressions. SEC-SECRET-DETECT: remove the secret-prop suppression. The rule only fires on properties typed as the builtin string, and clientSecret is typed url, so the suppression had no effect. The property holds only a Key Vault reference, which the documentation now states explicitly. The XMSSecretInResponse suppression is also removed, as nothing in the generated file is marked x-ms-secret. RPC-SUPPRESS-SCOPE: scope RequiredPropertiesMissingInResourceModel to $.definitions.AuthenticationPolicy, and explain why LatestVersionOfCommonTypesMustBeUsed stays file-level: the common-types version is pinned package-wide by arm-types-dir, so the finding applies to every common-types reference in the file rather than to any single definition. Section 4.1: document the authenticationPolicy Features member instead of suppressing documentation-required, and replace the placeholder FIXME justification on WebApplicationFirewallPolicyTier with a real one. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix LintDiff and ModelValidation failures on AuthenticationPolicy 2026-01-01 Three CI failures introduced by the previous review-feedback commit: 1. LintDiff RequiredPropertiesMissingInResourceModel: the where: scope added for this rule only covered $.definitions.AuthenticationPolicy, but the rule also fires on AuthenticationPolicyListResult. Added that definition to the scope and extended the reason to explain that the list result is a paged envelope rather than a resource. 2. LintDiff XMSSecretInResponse on clientSecret: removing the TypeSpec secret-prop suppression did not clear this because the swagger rule matches purely on the property name ending in a sensitive keyword. The property only ever carries an absolute HTTPS Key Vault reference URL, never secret material, so annotating it with x-ms-secret would be incorrect - it would stop the service returning the reference in GET. Renamed the property to clientSecretUrl, which both clears the rule without any suppression and describes the value accurately. 2026-01-01 is not yet published, so the rename carries no breaking-change cost. 3. ModelValidation RESPONSE_STATUS_CODE_NOT_IN_EXAMPLE: the delete operation now declares a 200 response, so AuthenticationPolicyDelete.json needs a matching (bodyless) 200 entry alongside the existing 204. Swagger Avocado remains failing with MULTIPLE_API_VERSION on the package-2026-01-01 tag. That failure reproduces on the base release branch PR (#46086) and is unrelated to this change. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Rename clientSecretUrl to clientSecretUri TypeSpec Validation compiles client.tsp with --warn-as-error, which surfaces @azure-tools/typespec-client-generator-core/csharp-no-url-suffix: properties ending in 'Url' must use the 'Uri' suffix so the generated C# surface is idiomatic. The local emit-only compile of the Network project does not run client.tsp, so this was missed. clientSecretUri still avoids the LintDiff XMSSecretInResponse keyword match, which only fires on names ending in a sensitive keyword. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Revert clientSecret rename and suppress XMSSecretInResponse instead The rename to clientSecretUrl/clientSecretUri was wrong. The property name is part of the contract already implemented by the Network resource provider, so the spec has to match NRP rather than pick a name that happens to dodge the linter's keyword match. Reverted to clientSecret. To keep LintDiff green, XMSSecretInResponse is suppressed instead, scoped to $.definitions.AuthenticationProviderProperties.properties.clientSecret. The justification is substantive rather than a waiver: the property carries only an absolute HTTPS Key Vault secret URL, never secret material - the secret value is read from Key Vault at runtime using the resource's user-assigned identity and is never accepted or returned by this API. Annotating it with x-ms-secret would be actively incorrect, because that would stop the service returning the Key Vault reference on GET, which callers need in order to see how a policy is configured. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com> Co-authored-by: Akshat Kale <kaleakshat@gmail.com> Co-authored-by: Akshat Kale <akale@microsoft.com> Co-authored-by: yaarark <yaararonenkr@gmail.com> Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com> Co-authored-by: Shaigoldbourt22 <118125561+Shaigoldbourt22@users.noreply.github.com> Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: baoqihuang0326 <119557638+baoqihuang0326@users.noreply.github.com> Co-authored-by: Arjun Patel <94936045+arjun-d-patel@users.noreply.github.com> Co-authored-by: ajoyduwary <ajoyduwary@gmail.com> Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com> Co-authored-by: mshrimankar10 <66165250+mshrimankar10@users.noreply.github.com> Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: paawankohli <44478509+paawankohli@users.noreply.github.com> Co-authored-by: Paawan Kohli <paawankohli@microsoft.com> Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com> Co-authored-by: gurram-amulya <111553857+gurram-amulya@users.noreply.github.com> Co-authored-by: kshitizmathur-max <kshitiz.mathur@gmail.com> Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com> Co-authored-by: Satya-Kotha1008 <sathi.kotha1008@gmail.com> Co-authored-by: carenlim20 <carenlim+github@microsoft.com> Co-authored-by: Caren Lim <carenlim@microsoft.com> Co-authored-by: Matthew Lee <mwlee29@gmail.com> Co-authored-by: Matthew Lee <matthelee@microsoft.com> Co-authored-by: Ben Eshed <105308016+bewatersmsft@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3 Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac
Summary
Adds the AuthenticationPolicy resource (
Microsoft.Network/authenticationPolicies) and binds it to Application Gateway request routing rules, targeting thestable/2026-01-01API version.Changes
stable/2026-01-01/authenticationPolicy.json— standaloneMicrosoft.Network/authenticationPoliciesresource withListAll/List/Get/CreateOrUpdate/Deleteoperations and definitions (AuthenticationPolicy,AuthenticationPolicyPropertiesFormat,AuthenticationProviderProperties, enumsUserTrustProviderType,OnUnauthenticatedRequest).stable/2026-01-01/examples/(CreateOrUpdate, Get, Delete, List, ListAll).stable/2026-01-01/applicationGateway.json— addedauthConfigsarray on the request routing rule properties plus theApplicationGatewayAuthConfigdefinition (links a named config to an authentication policy and/or authorization policy).Network/readme.md— wiredauthenticationPolicy.jsoninto thepackage-2026-01-01input-file list.Local validation performed
specification/**/*.jsonswagger plugin config) — passoav validate-spec(semantic) — pass (authenticationPolicy.json and applicationGateway.json)oav validate-example(model/example) — passContribution checklist