Repository navigation
Correct AuthenticationPolicy contract for 2026-01-01 - #45892
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
Next Steps to Merge✅ All automated merging requirements have been met! To get your PR merged, see aka.ms/azsdk/specreview/merge.Comment generated by summarize-checks workflow run. |
|
Azure Pipelines: Successfully started running 9 pipeline(s). 5 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
API Change CheckAPIView identified API level changes in this PR and created the following API reviews
Comment generated by After APIView workflow run. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
|
Addressed in 49afe4c. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
|
Addressed in 9d1040b:
|
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
|
Updated in e90beb8 using the service-tested payloads:
The advanced-routing fragment is intentionally not included because its advanced routing map/rule models are not public in this API version; adding those values to the existing URL path map/routing rule types would recreate the unsupported placement issue this PR removes. |
TypeSpec suppressions requiring review (testing, non-blocking)Status: ❌ Approval required (currently under testing, review NOT enforced) — 4 suppressions
New suppressions (4)
For an overview of TypeSpec linting rules click here. 💬 Have feedback on the TypeSpec suppression flow? Let us know. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
|
Corrected in 4909de5 based on the updated service information:
|
…uthentication-policy-2026-01-01-followup
The tags-only PATCH takes the shared Network RP TagsObject body, matching ApplicationGateways_UpdateTags. The service only updates tags on this operation, so identity does not belong in the request body.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
|
Addressed in 502f154:
The branch also incorporated the concurrent release-branch merge and PATCH identity-property suppression before this commit was pushed. |
Sandip Shahane (sandipsh)
left a comment
There was a problem hiding this comment.
ARM API Review
Posting findings from the ARM API Reviewer agent (critic-verified, 3 iteration(s), converged) against commit 502f154. See inline comments for findings 1-2.
Approval labels observed: none.
| @added(Versions.v2026_01_01) | ||
| @TypeSpec.OpenAPI.extension("x-ms-identifiers", #["name"]) | ||
| @maxItems(1) | ||
| defaultAuthConfigs?: ApplicationGatewayAuthConfig[]; |
There was a problem hiding this comment.
[NEW] 🔴 Blocking [Section 2 - API Versioning] specification/network/resource-manager/Microsoft.Network/Network/Network/models.tsp - line 7991 - This moves published authentication bindings to different models in stable 2026-01-01: ApplicationGatewayUrlPathMap.defaultAuthConfigs and ApplicationGatewayRoutingRule.authConfigs are removed, while similarly named properties are added to the advanced routing map/rule models. The new properties are not wire-compatible replacements for the removed properties.
Classification reasoning: Introduced in this PR. Both removed properties are present in the PR base, including defaultAuthConfigs at base source line 7843, and absent at the current head; the advanced-model properties are newly added at current lines 7991 and 8081.
Approval context: No Versioning-Approved-* label was observed at the session SHA. If API versioning approval already covers this exact published-contract correction, apply the matching label and resolve this conversation; otherwise preserve the old properties or introduce the corrected placement in a new API version.
Suggested fix: Restore the two published properties in 2026-01-01 and add the corrected advanced-model bindings in a new API version. If changing the published stable version is unavoidable, obtain explicit versioning approval for both removals and apply the matching Versioning-Approved-* label.
There was a problem hiding this comment.
This one I would like to push back on, because the premise that 2026-01-01 is a published stable contract does not hold.
2026-01-01 has never shipped. It exists only on the release-microsoft-network-2026-01-01 release branch, which is the base branch of this PR. There is no stable/2026-01-01 directory on main:
$ git ls-tree --name-only origin/main specification/network/resource-manager/Microsoft.Network/Network/stable/
...
specification/network/resource-manager/Microsoft.Network/Network/stable/2025-07-01
specification/network/resource-manager/Microsoft.Network/Network/stable/2025-09-01
The latest stable version on main is 2025-09-01. ApplicationGatewayUrlPathMap.defaultAuthConfigs and ApplicationGatewayRoutingRule.authConfigs were both introduced on this same release branch by #45764 and have never been released, so removing them is not a change to a published contract and there is no client that could depend on them. Introducing the corrected placement in "a new API version" would mean shipping 2026-01-01 with bindings the service does not implement and then immediately deprecating them.
That is exactly what this follow-up PR is for: correcting the unreleased 2026-01-01 contract before it is merged to main, so that the released shape matches the implemented NRP behavior. ApplicationGatewayAdvancedRoutingMap / ApplicationGatewayAdvancedRoutingRule are the service's actual advanced routing attachment points; ApplicationGatewayUrlPathMap and ApplicationGatewayRoutingRule are not.
The "not wire-compatible replacements" observation is correct and intentional. They are not replacements, they are the correct attachment points. Please let me know if you would still like a Versioning-Approved-* label applied for tracking, but no versioning exception should be required for a version that has not been released.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3
|
Addressed in ea8ce5e:
|
- Make the arm-resource-invalid-envelope-property suppression reason self-contained by stating why the user-assigned identity belongs in the resource envelope. - Scope the PatchIdentityProperty suppression with a where: clause targeting the AuthenticationPolicies_UpdateTags PATCH operation. - Type issuer as url and require an https scheme, consistent with jwksUri and clientSecret. - Document the sessionTimeout string syntax and units, and constrain it with a base-10 integer pattern and max length. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…ter path Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…uthentication-policy-2026-01-01-followup
…uthentication-policy-2026-01-01-followup
The service supports only GET, PUT, and DELETE for authenticationPolicies, matching ApplicationGatewayWebApplicationFirewallPolicies, which also ships without a PATCH. Removing the tags-only PATCH also resolves the PatchIdentityProperty finding at its source: that rule fires only on an existing PATCH, so with no PATCH the identity envelope property no longer needs a suppression. - Remove AuthenticationPolicies_UpdateTags and its source and generated examples. - Drop the PatchIdentityProperty suppression. - Restore the TrackedResourcePatchOperation no-PATCH suppression. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The AuthenticationPolicy PATCH operation was removed, so the patch response entry in the where: list no longer matches anything. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…uthentication-policy-2026-01-01-followup
AuthenticationPolicy is a tracked resource: it extends the Network RP Resource base type, which supplies location, tags and x-ms-azure-resource. ARM requires resource providers to support PATCH for updating tags on a tracked resource, so removing the operation was incorrect. Restore PATCH using a resource-specific AuthenticationPolicyUpdateParameters model carrying both tags and identity, rather than the shared TagsObject. This satisfies the tracked-resource tags requirement and the MSI onboarding requirement that the control plane accept identity updates on PATCH, which means PatchIdentityProperty is now satisfied at the source and needs no suppression. - Add AuthenticationPolicyUpdateParameters (tags, identity). - Add AuthenticationPolicies_Update, replacing the former tags-only AuthenticationPolicies_UpdateTags. - Add an example exercising both tags and identity updates. - Drop the TrackedResourcePatchOperation suppression, no longer applicable. - Scope ProvisioningStateMustBeReadOnly to the new PATCH 200 response schema. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
6e7d5cd
into
Azure:release-microsoft-network-2026-01-01
* Add API version 2026-01-01 for Microsoft.Network (#45569) Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com> * Add Enum values for VPN migrationType (#45647) Co-authored-by: Akshat Kale <akale@microsoft.com> * Fix Bug 38477992: type computedDisabledRules.rules as integers (2026-01-01) (#45621) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com> Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3 * [Network] Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01 (#45625) * Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01 Ports the change from azure-rest-api-specs-pr PR 29807 onto the public 2026-01-01 release branch. Adds three read-only properties that NRP surfaces from api-version 2026-01-01 for Application Gateway WAF: - paranoiaLevel on ApplicationGatewayFirewallRule - displayName on ApplicationGatewayFirewallRuleSetPropertiesFormat - displayName on ApplicationGatewayFirewallManifestRuleSet - displayName on DefaultRuleSetPropertyFormat paranoiaLevel uses a new extensible enum ApplicationGatewayWafRuleParanoiaLevel with values PL1 to PL4. All new members are annotated with @added(Versions.v2026_01_01). The change is additive and all new properties are optional. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Retrigger CI The SDK Validation - Rust build failed on a transient GitHub timeout while installing the Azure SDK Tools CLI. Nothing in the spec changed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Centurion WAF: add WAF policy tier + Basic_v2/Basic_WAF_v2 SKUs (2026-01-01) (#45766) * Add Centurion WAF updates for 2026-01-01 Update WAF policy tier and reserved capacity support. Add Basic_v2 and Basic_WAF_v2 SKUs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Basic v2 application gateway tiers WebApplicationFirewallPolicyTier ordering aligns Standard=0 and Basic=1. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Basic WAF and application gateway examples Add Basic WAF policy create/get examples and Basic-tier coverage. Add Basic_v2 and Basic_WAF_v2 application gateway create/get examples, including reservedCapacity and WAF policy association. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add AuthenticationPolicy resource and Application Gateway authConfigs binding for 2026-01-01 (#45764) * Add AuthenticationPolicy support for 2026-01-01 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Align AuthenticationPolicy contract with service behavior Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Enforce AuthenticationPolicy name and binding constraints Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Add authentication policy tags update Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 --------- Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 (#45650) * Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 Adds optional min/max allocation-size bounds to the Microsoft.Network IpamPool resource in api-version 2026-01-01: - IpamPoolProperties (PUT/GET): minAllocationSize, maxAllocationSize - IpamPoolUpdateProperties (PATCH): minAllocationSize, maxAllocationSize marked x-nullable so an explicit null clears the bound while an absent bound is preserved, per ARM merge-patch semantics. Both properties are gated with @added(Versions.v2026_01_01) so earlier api-versions are unchanged. Regenerated virtualNetwork.json and updated the 2026-01-01 IpamPools Create/Get/List/Update examples. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Move min/max allocation size into dedicated IpamPool examples The allocation-size bounds are optional, so the baseline IpamPools examples should not imply they are always supplied. Restores IpamPools_Create/Get/List/Update to their original content and adds dedicated examples that exercise the feature: - IpamPools_CreateWithAllocationBounds.json: PUT setting both bounds. - IpamPools_UpdateAllocationBounds.json: PATCH setting both bounds. - IpamPools_UpdateClearAllocationBounds.json: PATCH clearing both bounds with an explicit null, per ARM merge-patch semantics. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address ARM review: drop nullable union on new min/max update properties New properties must not use a nullable union, since backward compatibility does not apply to additions. The RP already treats an empty string as a clear on PATCH, so the explicit null is unnecessary. - IpamPoolUpdateProperties min/maxAllocationSize: string | null -> string, removing the no-nullable suppressions and x-nullable from the swagger. - Document clearing via an empty string. - IpamPools_UpdateClearAllocationBounds example now clears with "". Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add Swagger Avocado suppression for frozen 2018-10-01 VMSS surface Per ARM reviewer guidance on PR #45650: the package-2026-01-01 default tag intentionally retains stable/2018-10-01/vmssNetwork.json for backward compatibility, which trips Avocado's MULTIPLE_API_VERSION rule. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix Avocado suppression tool name to SwaggerAvocado Per ARM reviewer bot feedback on PR #45650: the suppression tool name has no space. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add approvalReference to private endpoint connection in 2026-01-01 (#45604) * Add approvalReference (create-only) to private endpoint connection in 2026-01-01 Adds optional approvalReference.privateEndpointId to PrivateLinkServiceConnectionProperties, gated @added(v2026_01_01) with @visibility(Lifecycle.Read, Lifecycle.Create) so it is create-only (emits x-ms-mutability: [read, create]) and is not resupplied on update. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Regenerate vmssNetwork.json for approvalReference (Vmss project) The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and emits stable/2018-10-01/vmssNetwork.json, which must be regenerated so approvalReference/ApprovalReference are included. Fixes TypeSpec Validation (Vmss). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Remove x-ms-mutability (create-only) from approvalReference Per internal discussion, drop the create-only mutability restriction on approvalReference. Removes the @visibility(Lifecycle.Read, Lifecycle.Create) decorator in Common/main.tsp and regenerates the Network and Vmss project swaggers so x-ms-mutability is no longer emitted. The approvalReference property and ApprovalReference model are retained. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Type approvalReference.privateEndpointId as armResourceIdentifier Address ARM review finding [TSP-ARM-RESOURCE-ID]: privateEndpointId references an existing private endpoint, so type it as Azure.Core.armResourceIdentifier<Microsoft.Network/privateEndpoints> instead of plain string. Regenerated swagger emits format: arm-id and x-ms-arm-id-details.allowedResources. --------- Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Add ExpressRoutCircuit on ExpressRouteLag (#45689) * Add ExpressRoutCircuit on ExpressRouteLag * Fix ExpressRouteLag examples: sync circuits to output copies and remove invalid circuit properties Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Align ExpressRouteCircuitCreateOnExpressRouteLag responses with request (EX-PARAM-CONSISTENCY) Fix response bodies to match request: LAG reference lagName (was test), enableDirectPortRateLimit true, and SKU Premium_MeteredData in the 200 response. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * Add AppGw Advanced Routing Rule in NRR API 2026-01-01 (#45844) * Add advanced routing features to Application Gateway for API version 2026-01-01 * buid artifacts after changes to models.tsp * added examples * fix merge conflict --------- Co-authored-by: Paawan Kohli <paawankohli@microsoft.com> * Modify sdk-suppressions.yaml for breaking changes (#45914) Updated breaking changes for Azure SDK suppressions in network resource manager. * [Microsoft.Network] Add provider-led ExpressRoute circuit migration APIs (#45905) * Add ExpressRoute circuit migration APIs Add TypeSpec operations and models for provider-led ExpressRoute circuit migration, generated 2026-01-01 Swagger, examples, and the scoped brownfield resource-name suppression. * Fix Network specification validation Use valid UUID subscription IDs, add required TypeSpec example metadata, regenerate migration LRO metadata, and suppress the intentional mixed-version VMSS surface in the combined Network package. * Fix Network Avocado suppression Move the mixed API-version exception from an unsupported AutoRest directive to the Network SwaggerAvocado path-suppression file, scoped to the default-tag readme. * Fix Network validation suppressions * Correct Avocado suppression identifier * Geo-Ip filter changes (#45631) * Geo Ip Filter Changes * Document GeoIP filter format (ISO 3166-1 alpha-2) and fix WAF scrubbing-rule model * Fixing Swagger ModelValidation Filure related errors * Dummy Push to reinitate build * Type Spec validation failure fix * Remove duplicate GeoIP filter properties --------- Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com> * Add NeuroShield API for 2026-01-01 (#45722) * Add NeuroShield API for 2026-01-01 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add NeuroShield API for 2026-01-01 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Align NeuroShield contract with service behavior Require customer-facing configuration, align mitigation responses with the safe service projection, make cancellation synchronous, and correct protected-resource delete polling. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Refine NeuroShield 2026-01-01 contract Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Fix NeuroShield validation regressions * Address ARM review feedback for NeuroShield Use supported ARM resource templates, scope Swagger suppressions to exact operations, and isolate inherited Network validation debt. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Fix NeuroShield LintDiff suppressions * Use standard ARM entity tag property --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Add post calls for auth key of authorization objects for expressrouteciruits and expressrouteports (#45679) * Added post calls for expressroute auth key * Added the objects in 2026-01-01 version * addressed ai comments * Addressed comments * fixed * removed suppression * fixed suppressions --------- Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com> Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com> * Fix Hub virtual network IPv6 peering contract (#45637) * Fix IPv6 peering contract for Network 2026-01-01 * Correct IPv6 peering contract in Network 2025-09-01 * Update client.tsp * Update sdk-suppressions.yaml --------- Co-authored-by: Caren Lim <carenlim@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: kazrael2119 <98569699+kazrael2119@users.noreply.github.com> * Correct AuthenticationPolicy contract for 2026-01-01 (#45892) * Correct authentication policy contract Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Keep provider type extensible Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Document authentication policy constraints Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Align authentication examples with service Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Restore authentication policy tags update Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Suppress PatchIdentityProperty for AuthenticationPolicies_UpdateTags The tags-only PATCH takes the shared Network RP TagsObject body, matching ApplicationGateways_UpdateTags. The service only updates tags on this operation, so identity does not belong in the request body. * Complete authentication policy constraints Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Correct Basic v2 authentication example Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Address ARM review feedback on AuthenticationPolicy 2026-01-01 - Make the arm-resource-invalid-envelope-property suppression reason self-contained by stating why the user-assigned identity belongs in the resource envelope. - Scope the PatchIdentityProperty suppression with a where: clause targeting the AuthenticationPolicies_UpdateTags PATCH operation. - Type issuer as url and require an https scheme, consistent with jwksUri and clientSecret. - Document the sessionTimeout string syntax and units, and constrain it with a base-10 integer pattern and max length. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Also scope PatchIdentityProperty suppression to the PATCH body parameter path Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Remove AuthenticationPolicy PATCH operation The service supports only GET, PUT, and DELETE for authenticationPolicies, matching ApplicationGatewayWebApplicationFirewallPolicies, which also ships without a PATCH. Removing the tags-only PATCH also resolves the PatchIdentityProperty finding at its source: that rule fires only on an existing PATCH, so with no PATCH the identity envelope property no longer needs a suppression. - Remove AuthenticationPolicies_UpdateTags and its source and generated examples. - Drop the PatchIdentityProperty suppression. - Restore the TrackedResourcePatchOperation no-PATCH suppression. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Drop stale PATCH path from ProvisioningStateMustBeReadOnly suppression The AuthenticationPolicy PATCH operation was removed, so the patch response entry in the where: list no longer matches anything. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Restore AuthenticationPolicy PATCH with a resource-specific update model AuthenticationPolicy is a tracked resource: it extends the Network RP Resource base type, which supplies location, tags and x-ms-azure-resource. ARM requires resource providers to support PATCH for updating tags on a tracked resource, so removing the operation was incorrect. Restore PATCH using a resource-specific AuthenticationPolicyUpdateParameters model carrying both tags and identity, rather than the shared TagsObject. This satisfies the tracked-resource tags requirement and the MSI onboarding requirement that the control plane accept identity updates on PATCH, which means PatchIdentityProperty is now satisfied at the source and needs no suppression. - Add AuthenticationPolicyUpdateParameters (tags, identity). - Add AuthenticationPolicies_Update, replacing the former tags-only AuthenticationPolicies_UpdateTags. - Add an example exercising both tags and identity updates. - Drop the TrackedResourcePatchOperation suppression, no longer applicable. - Scope ProvisioningStateMustBeReadOnly to the new PATCH 200 response schema. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Add bastion session recording configuration and identity properties (#45630) * Add bastion session recording configuration property * Fix the patch body for identity support * Update examples * Fix prettier violation * Revert documentation changes * Add BastionHostUpdate model instead of anonymous type * Add tpye constraint for userAssignedIdentityId * Fix invalid arm id for public ip in example * Fix wrong name in 200 responses in new examples * Fix documentation for BastionHostUpdate * Preserve existing updateTags operation * Update suppression justification * Revert previous changes which maintained the old operation * Update suppression justification for update operation --------- Co-authored-by: Matthew Lee <matthelee@microsoft.com> * Add azureFirewall enableAiAddOn (#45976) * Add azureFirewall enableAiAddOn * Enable aiSecurityAddOn in Azure Firewall configuration Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * copilot messed up, fix typescript * fix fields in exampels * fix fields in examples --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Revert "Add NeuroShield API for 2026-01-01 (#45722)" (#46208) This reverts commit efb6f29. * Address swagger review findings on AuthenticationPolicy for 2026-01-01 (#46260) * Address swagger review findings on AuthenticationPolicy Resolves five of the review findings at the source rather than by suppression, removing four AuthenticationPolicy suppressions. RequiredReadOnlySystemData: declare systemData explicitly on AuthenticationPolicy, following the existing Network RP pattern used by AdminRuleCollection, BaseAdminRule and Commit. It is emitted read-only. RPC-Delete-V1-01: drop the ArmDeletedNoContentResponse override so the sync DELETE emits 200, 204 and default. AuthenticationPolicy was the only resource in this project overriding the delete response; every sibling uses the default. Removes the DeleteResponseCodes and DeleteOperationResponses suppressions. SEC-SECRET-DETECT: remove the secret-prop suppression. The rule only fires on properties typed as the builtin string, and clientSecret is typed url, so the suppression had no effect. The property holds only a Key Vault reference, which the documentation now states explicitly. The XMSSecretInResponse suppression is also removed, as nothing in the generated file is marked x-ms-secret. RPC-SUPPRESS-SCOPE: scope RequiredPropertiesMissingInResourceModel to $.definitions.AuthenticationPolicy, and explain why LatestVersionOfCommonTypesMustBeUsed stays file-level: the common-types version is pinned package-wide by arm-types-dir, so the finding applies to every common-types reference in the file rather than to any single definition. Section 4.1: document the authenticationPolicy Features member instead of suppressing documentation-required, and replace the placeholder FIXME justification on WebApplicationFirewallPolicyTier with a real one. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix LintDiff and ModelValidation failures on AuthenticationPolicy 2026-01-01 Three CI failures introduced by the previous review-feedback commit: 1. LintDiff RequiredPropertiesMissingInResourceModel: the where: scope added for this rule only covered $.definitions.AuthenticationPolicy, but the rule also fires on AuthenticationPolicyListResult. Added that definition to the scope and extended the reason to explain that the list result is a paged envelope rather than a resource. 2. LintDiff XMSSecretInResponse on clientSecret: removing the TypeSpec secret-prop suppression did not clear this because the swagger rule matches purely on the property name ending in a sensitive keyword. The property only ever carries an absolute HTTPS Key Vault reference URL, never secret material, so annotating it with x-ms-secret would be incorrect - it would stop the service returning the reference in GET. Renamed the property to clientSecretUrl, which both clears the rule without any suppression and describes the value accurately. 2026-01-01 is not yet published, so the rename carries no breaking-change cost. 3. ModelValidation RESPONSE_STATUS_CODE_NOT_IN_EXAMPLE: the delete operation now declares a 200 response, so AuthenticationPolicyDelete.json needs a matching (bodyless) 200 entry alongside the existing 204. Swagger Avocado remains failing with MULTIPLE_API_VERSION on the package-2026-01-01 tag. That failure reproduces on the base release branch PR (#46086) and is unrelated to this change. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Rename clientSecretUrl to clientSecretUri TypeSpec Validation compiles client.tsp with --warn-as-error, which surfaces @azure-tools/typespec-client-generator-core/csharp-no-url-suffix: properties ending in 'Url' must use the 'Uri' suffix so the generated C# surface is idiomatic. The local emit-only compile of the Network project does not run client.tsp, so this was missed. clientSecretUri still avoids the LintDiff XMSSecretInResponse keyword match, which only fires on names ending in a sensitive keyword. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Revert clientSecret rename and suppress XMSSecretInResponse instead The rename to clientSecretUrl/clientSecretUri was wrong. The property name is part of the contract already implemented by the Network resource provider, so the spec has to match NRP rather than pick a name that happens to dodge the linter's keyword match. Reverted to clientSecret. To keep LintDiff green, XMSSecretInResponse is suppressed instead, scoped to $.definitions.AuthenticationProviderProperties.properties.clientSecret. The justification is substantive rather than a waiver: the property carries only an absolute HTTPS Key Vault secret URL, never secret material - the secret value is read from Key Vault at runtime using the resource's user-assigned identity and is never accepted or returned by this API. Annotating it with x-ms-secret would be actively incorrect, because that would stop the service returning the Key Vault reference on GET, which callers need in order to see how a policy is configured. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com> Co-authored-by: Akshat Kale <kaleakshat@gmail.com> Co-authored-by: Akshat Kale <akale@microsoft.com> Co-authored-by: yaarark <yaararonenkr@gmail.com> Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com> Co-authored-by: Shaigoldbourt22 <118125561+Shaigoldbourt22@users.noreply.github.com> Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: baoqihuang0326 <119557638+baoqihuang0326@users.noreply.github.com> Co-authored-by: Arjun Patel <94936045+arjun-d-patel@users.noreply.github.com> Co-authored-by: ajoyduwary <ajoyduwary@gmail.com> Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com> Co-authored-by: mshrimankar10 <66165250+mshrimankar10@users.noreply.github.com> Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: paawankohli <44478509+paawankohli@users.noreply.github.com> Co-authored-by: Paawan Kohli <paawankohli@microsoft.com> Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com> Co-authored-by: gurram-amulya <111553857+gurram-amulya@users.noreply.github.com> Co-authored-by: kshitizmathur-max <kshitiz.mathur@gmail.com> Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com> Co-authored-by: Satya-Kotha1008 <sathi.kotha1008@gmail.com> Co-authored-by: carenlim20 <carenlim+github@microsoft.com> Co-authored-by: Caren Lim <carenlim@microsoft.com> Co-authored-by: Matthew Lee <mwlee29@gmail.com> Co-authored-by: Matthew Lee <matthelee@microsoft.com> Co-authored-by: Ben Eshed <105308016+bewatersmsft@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3 Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac
Summary
Follow-up to #45764 that aligns the
2026-01-01AuthenticationPolicy contract with the implemented Network RP service behavior.2026-01-01is unreleased — it exists only on therelease-microsoft-network-2026-01-01branch and has no counterpart onmain— so these corrections land before the version ships rather than changing a published contract.Application Gateway authentication bindings
defaultAuthConfigsonApplicationGatewayAdvancedRoutingMapandauthConfigsonApplicationGatewayAdvancedRoutingRule.defaultAuthConfigsfromApplicationGatewayUrlPathMapandauthConfigsfromApplicationGatewayRoutingRule; those are not advanced routing attachment types and were never implemented.authConfigsonApplicationGatewayRequestRoutingRule.maxItems: 1because NRP supports one auth config per attachment point.AuthenticationPolicy resource
identityenvelope property used by user sign-in policies to reach their Key Vault client secret.AuthenticationPolicies_UpdateTagsPATCH withAuthenticationPolicies_Update, backed by a resource-specificAuthenticationPolicyUpdateParametersmodel carrying bothtagsandidentity. AuthenticationPolicy is a tracked resource, so ARM requires PATCH for tag updates, and the MSI onboarding guidance requires the control plane to accept identity updates on PATCH. Using a dedicated update model rather than the sharedTagsObjectsatisfies both at the source instead of via suppression.UserTrustProviderTypeextensible (modelAsString: true) with theEntraSDK constant mapped to the lowercase wire valueentra.Constraints and documentation
issueris typed asurlwith an HTTPS pattern, consistent withjwksUriandclientSecret.sessionTimeoutremains a string to match the implemented wire shape, with its accepted syntax and units documented and enforced via pattern and length.clientIdis documented and constrained as a GUID.Suppressions
Net change for AuthenticationPolicy is two fewer suppressions.
ProvisioningStateMustBeReadOnlysuppression to the specific GET, PUT, and PATCH response schemas.arm-resource-invalid-envelope-propertysuppression reason self-contained for theidentityproperty.PatchIdentityPropertysuppression is needed, because the PATCH body acceptsidentity.TrackedResourcePatchOperationsuppression, which no longer applies now that PATCH exists.SchemaDescriptionOrTitlesuppression now that the description is emitted.Clarifications
Entra, while its serialized wire value remains lowercaseentra. This is intentional and matches the existing NRP contract.ApplicationGatewayAuthConfigis not renamed in this PR. The shared Azure Firewall naming question can be resolved before a Firewall binding is introduced, avoiding an unrelated change to the currently published Application Gateway model.AuthenticationPolicies_UpdateTagstoAuthenticationPolicies_Updateis safe because2026-01-01is unreleased, and the former name is no longer accurate now that the body is not tags-only.Validation
authenticationPolicy.jsonandapplicationGateway.jsonauthenticationPolicy.json