Every capability, with its real status.
This table is generated from the Product Truth Registry. Nothing on it is written by hand, which is the point: a status that can be edited on one page and not another is not a status, it is a claim.
Three axes, not one list
Maturity is mutually exclusive: Generally Available, Preview, Design Partner or Q4 2026 Roadmap Extension. Qualifiers accompany any maturity: Third-Party Integration marks a dependency on an external platform, and Independently Verified marks a claim backed by a named external report. Type is a third axis from the capability specification: New means the capability is not yet defined as a complete product feature, and Expand means it exists today and the extension adds to it. Twelve of the twenty-eight are Expand, which is why twelve items carry both a Generally Available badge and a roadmap extension badge.
Priority
The specification assigns every item a priority: twelve Critical, fourteen High and two Medium. Priority is published here rather than on the individual pages, because a capability page is not the place to argue about sequencing.
| ID | Capability | Status | Primary page |
|---|---|---|---|
| MF-001 | Policy Control Plane Central lifecycle, approval, signing, deployment state and rollback | Q4 2026 Roadmap Extension | /platform/policy-control-plane/ |
| MF-002 | Simulation and Shadow Mode Live shadow evaluation, historical replay and decision difference reports | Q4 2026 Roadmap Extension | /platform/policy-simulation/ |
| MF-003 | Query Authorization EF Core filtering, secure pagination, joins, aggregates and exports | Q4 2026 Roadmap Extension | /platform/active-data-authorization/ |
| MF-004 | Batch Authorization High-volume mixed resource/action decision APIs | Q4 2026 Roadmap Extension | /developers/batch-authorization/ |
| MF-005 | AuthZEN and ReBAC Interoperability B5 as PEP for OpenFGA, Cedar, Cerbos and external PDPs | Q4 2026 Roadmap ExtensionThird-Party Integration | /platform/security-extensions/ |
| MF-006 | Continuous Revocation CAEP/SSF signals, rapid propagation, cache invalidation and recovery | Preview | /solutions/continuous-authorization/ |
| MF-007 | Policy-as-Code and GitOps CI validation, signed bundles, promotion and drift detection | Q4 2026 Roadmap Extension | /platform/policy-control-plane/ |
| MF-008 | Authorization Testing Assertions, property tests, replay, mutation and coverage | Q4 2026 Roadmap Extension | /developers/testing/ |
| MF-009 | Roslyn Analyzers Missing protection, invalid permissions, unsafe bypass and build gates | Q4 2026 Roadmap Extension | /developers/analyzers/ |
| MF-010 | Break-Glass Access Time-limited, dual-approved emergency authority | Q4 2026 Roadmap Extension | /solutions/continuous-authorization/ |
| MF-011 | Decision Explainability Human-readable and machine-readable decision graph | Q4 2026 Roadmap Extension | /platform/decision-evidence/ |
| MF-012 | Consistency Controls Staleness policies, offline behavior, refresh and split-brain handling | Q4 2026 Roadmap Extension | /architecture/consistency/ |
| MF-013 | Entra Mapping Normalized users, groups, app roles, PIM, workloads and risk context | Q4 2026 Roadmap ExtensionThird-Party Integration | /microsoft/entra/ |
| MF-014 | Entra Agent ID Agent, sponsor, purpose, tool/data scope and transaction limits | Q4 2026 Roadmap ExtensionThird-Party Integration | /microsoft/agent-id/ |
| MF-015 | Sentinel and Defender Connectors, analytics, workbooks, hunting and response playbooks | Q4 2026 Roadmap ExtensionThird-Party Integration | /microsoft/sentinel-defender/ |
| MF-016 | Azure Governance Azure Policy, AKS admission, inventory and drift reporting | Q4 2026 Roadmap ExtensionThird-Party Integration | /microsoft/azure-governance/ |
| MF-017 | Runtime Coverage gRPC, Functions, workers, queues, SignalR, Dapr and Orleans | Preview | /developers/frameworks/ |
| MF-018 | Polyglot Protocol Language-neutral decision, evidence, permit and revocation contracts | Q4 2026 Roadmap Extension | /developers/protocols/ |
| MF-019 | Migration Tooling Discovery and conversion from ASP.NET roles, handlers and custom checks | Q4 2026 Roadmap Extension | /developers/migration/ |
| MF-020 | Frictionless Evaluation CLI, playground, Docker, Codespaces and public samples | Preview | /developers/ |
| MF-021 | Assurance Program Completed certifications, pen tests and vendor-review evidence | Q4 2026 Roadmap Extension | /trust-center/ |
| MF-022 | Public Benchmarks Reproducible latency, throughput, memory and failure testing | Q4 2026 Roadmap Extension | /trust-center/benchmarks/ |
| MF-023 | Verifiable Evidence Signing, hash chains, timestamps, WORM and external verifier | Preview | /platform/decision-evidence/ |
| MF-024 | Telemetry Privacy Redaction, pseudonymization, residency, retention and legal holds | Q4 2026 Roadmap Extension | /trust-center/privacy/ |
| MF-025 | Multi-Tenant Administration Tenant policy spaces, delegated administration and isolated keys | Q4 2026 Roadmap Extension | /platform/policy-control-plane/ |
| MF-026 | Enterprise Service Management SLAs, LTS, lifecycle, support and continuity | Q4 2026 Roadmap Extension | /trust-center/operations/ |
| MF-027 | Marketplace and Licensing Transactable offer, private offers, entitlements and air-gap licensing | PreviewThird-Party Integration | /pricing/ |
| MF-029 | OCSF Authorization Event Class A registered OCSF extension defining the per-record authorization decision, with B5 as reference implementation | Q4 2026 Roadmap Extension | /platform/decision-evidence/ |
| MF-030 | Actionable Response Interface Revoke, suspend and tighten-limit as authorised, recorded operations a SOAR playbook can call | Q4 2026 Roadmap ExtensionThird-Party Integration | /microsoft/sentinel-defender/ |
| MF-031 | Policy Change Impact in Pull Requests Decision-difference reporting posted onto the pull request that changes policy | Q4 2026 Roadmap Extension | /platform/policy-simulation/ |
| MF-032 | Multi-Party Authorization (m-of-n) Configurable m-of-n approval before a protected operation executes, each approval an evidenced decision | Q4 2026 Roadmap Extension | /roadmap/q4-2026/ |
| MF-033 | Payments Authorization Profile The authority decision class applied to money-movement events, so a hold or release carries the same evidenced decision as a data read | Q4 2026 Roadmap Extension | /roadmap/q4-2026/ |
| MF-028 | Product Truth Registry Single source for capability status, edition, release and evidence | Q4 2026 Roadmap Extension | /roadmap/q4-2026/ |
| CRYPTO-confidential-by-default | Confidential by Default | Generally Available | /cryptography/confidential-by-default/ |
| CRYPTO-fips-140-3-level-3 | FIPS 140-3 Level 3 | Generally Available | /cryptography/fips-140-3-level-3/ |
| CRYPTO-multi-person-control | Multi-Person Control | Generally Available | /cryptography/multi-person-control/ |
| EXT-adaptive-identity-firewall | Adaptive Identity Firewall | Generally Available | /platform/security-extensions/adaptive-identity-firewall/ |
| EXT-co-hosted-one-host | Co-Hosted, One Host | Generally Available | /platform/security-extensions/co-hosted-one-host/ |
| EXT-granular-authorization | Granular Authorization | Generally Available | /platform/security-extensions/granular-authorization/ |
| EXT-hmac-request-signing | HMAC Request Signing | Generally Available | /platform/security-extensions/hmac-request-signing/ |
| EXT-ip-firewall | IP Firewall (Extensions) | Generally Available | /platform/security-extensions/ip-firewall/ |
| EXT-multi-factor | Multi-Factor (Extensions) | Generally Available | /platform/security-extensions/multi-factor/ |
| EXT-policy-driven-suspension-cae | Policy-Driven Suspension & CAE | Generally Available | /platform/security-extensions/policy-driven-suspension-cae/ |
| EXT-rules-based-suspension | Rules-Based Suspension | Generally Available | /platform/security-extensions/rules-based-suspension/ |
| FEAT-account-management | Account Management | Generally Available | /features/account-management/ |
| FEAT-account-verification | User Account Verification | Generally Available | /features/account-verification/ |
| FEAT-activity-data-authorization | Activity-Data Authorization | Generally Available | /features/activity-data-authorization/ |
| FEAT-administration | Administration | Generally Available | /features/administration/ |
| FEAT-ai-agents | AI Agents & Agentic Identity | Generally Available | /features/ai-agents/ |
| FEAT-auth-cookie | AuthCookie | Generally Available | /features/auth-cookie/ |
| FEAT-authentication | Authentication | Generally Available | /features/authentication/ |
| FEAT-credential-blocking | Password / Credential Blocking | Generally Available | /features/credential-blocking/ |
| FEAT-error-handling | Professional Error Handling | Generally Available | /features/error-handling/ |
| FEAT-feature-hiding | Feature Hiding | Generally Available | /features/feature-hiding/ |
| FEAT-hmac | HMAC | Generally Available | /features/hmac/ |
| FEAT-identities | Identities | Generally Available | /features/identities/ |
| FEAT-integrator-identification | Integrator Identification | Generally Available | /features/integrator-identification/ |
| FEAT-ip-firewall | IP Firewall | Generally Available | /features/ip-firewall/ |
| FEAT-key-leakage-protection | Key-Leakage Protection | Generally Available | /features/key-leakage-protection/ |
| FEAT-multi-factor-authentication | Multi-Factor Authentication | Generally Available | /features/multi-factor-authentication/ |
| FEAT-password-hashing | Strong Password Hashing | Generally Available | /features/password-hashing/ |
| FEAT-replay-tamper-protection | Replay & Tamper Protection | Generally Available | /features/replay-tamper-protection/ |
| FEAT-request-integrity-expiration | Request Integrity & Expiration | Generally Available | /features/request-integrity-expiration/ |
| FEAT-security-notifications | Security Notifications | Generally Available | /features/security-notifications/ |
| FEAT-service-hmac | Service-HMAC | Generally Available | /features/service-hmac/ |
| FEAT-service-key | Service-Key | Generally Available | /features/service-key/ |
| FEAT-source-packages | Source Packages | Generally Available | /features/source-packages/ |
| FEAT-suspension | Suspension | Generally Available | /features/suspension/ |
| FEAT-user-management | User Management | Generally Available | /features/user-management/ |
| FEAT-xss-protection | XSS Protection | Generally Available | /features/xss-protection/ |
| PIPE-active-data-authorization | Activity-based, data-aware authorization (ADA) | Generally Available | /platform/active-data-authorization/ |
| PIPE-b1-xss-screening | B1 · XSS Screening | Generally Available | /platform/b1-xss-screening/ |
| PIPE-b2-authentication | B2 · Authentication | Generally Available | /platform/b2-authentication/ |
| PIPE-b3-ip-firewall-mfa | B3 · IP Firewall & MFA | Generally Available | /platform/b3-ip-firewall-mfa/ |
| PIPE-b4-verification-suspension | B4 · Verification & Suspension | Generally Available | /platform/b4-verification-suspension/ |
| PIPE-b5-activity-data-authorization | B5 · Activity-Data Authorization | Generally Available | /platform/b5-activity-data-authorization/ |
| PIPE-co-hosted-one-host | Co-Hosted, One Host | Generally Available | /platform/co-hosted-one-host/ |
| PIPE-security-extensions | Security Extensions | Generally Available | /platform/security-extensions/ |
| PIPE-security-pipeline | The Security Pipeline | Generally Available | /platform/security-pipeline/ |
Required of every extension
These four requirements apply to all twenty-eight capabilities identically. They are stated here once rather than repeated on every page, because a requirement that appears twenty times reads as boilerplate and stops being read at all.
- The capability shall fail closed for protected actions unless an explicitly approved degraded-mode policy applies.
- All administrative and runtime decisions shall emit traceable evidence with tenant, actor, correlation ID and version metadata.
- Configuration shall support environment isolation and shall not require secrets in source control.
- The capability shall be exposed through documented APIs and administrative workflows.
Required tests
Every capability carries the same six test classes:
- Positive functional tests
- Negative and bypass tests
- Tenant-isolation tests
- Failure and degraded-mode tests
- Telemetry and privacy tests
- Performance regression tests where runtime behaviour is affected
Release gates
No capability ships without clearing these, whatever its badge says:
- Security: zero unresolved critical or high-severity findings.
- Performance: documented p50/p95/p99 and no unapproved regression beyond release thresholds.
- Reliability: deterministic fail-closed behavior and tested disaster recovery.
Q4 2026 roadmap extensions
These capabilities are specified and not yet released. Each page carries its status from the Product Truth Registry.