Securing 2M+ accounts & $15B+ in assets, protected & secure·B5 Secure™ — per data-element authorization for .NET platforms

Q4 2026 Roadmap Extensions

← Roadmap
Q4 2026

Every capability, with its real status.

This table is generated from the Product Truth Registry. Nothing on it is written by hand, which is the point: a status that can be edited on one page and not another is not a status, it is a claim.

GeneratedItem-levelSingle source
Q4 2026 Roadmap Extension

Three axes, not one list

Maturity is mutually exclusive: Generally Available, Preview, Design Partner or Q4 2026 Roadmap Extension. Qualifiers accompany any maturity: Third-Party Integration marks a dependency on an external platform, and Independently Verified marks a claim backed by a named external report. Type is a third axis from the capability specification: New means the capability is not yet defined as a complete product feature, and Expand means it exists today and the extension adds to it. Twelve of the twenty-eight are Expand, which is why twelve items carry both a Generally Available badge and a roadmap extension badge.

Priority

The specification assigns every item a priority: twelve Critical, fourteen High and two Medium. Priority is published here rather than on the individual pages, because a capability page is not the place to argue about sequencing.

Generally Available
Preview
Design Partner
Q4 2026 Roadmap Extension
Third-Party Integration
Independently Verified
IDCapabilityStatusPrimary page
MF-001Policy Control Plane
Central lifecycle, approval, signing, deployment state and rollback
Q4 2026 Roadmap Extension/platform/policy-control-plane/
MF-002Simulation and Shadow Mode
Live shadow evaluation, historical replay and decision difference reports
Q4 2026 Roadmap Extension/platform/policy-simulation/
MF-003Query Authorization
EF Core filtering, secure pagination, joins, aggregates and exports
Q4 2026 Roadmap Extension/platform/active-data-authorization/
MF-004Batch Authorization
High-volume mixed resource/action decision APIs
Q4 2026 Roadmap Extension/developers/batch-authorization/
MF-005AuthZEN and ReBAC Interoperability
B5 as PEP for OpenFGA, Cedar, Cerbos and external PDPs
Q4 2026 Roadmap ExtensionThird-Party Integration/platform/security-extensions/
MF-006Continuous Revocation
CAEP/SSF signals, rapid propagation, cache invalidation and recovery
Preview/solutions/continuous-authorization/
MF-007Policy-as-Code and GitOps
CI validation, signed bundles, promotion and drift detection
Q4 2026 Roadmap Extension/platform/policy-control-plane/
MF-008Authorization Testing
Assertions, property tests, replay, mutation and coverage
Q4 2026 Roadmap Extension/developers/testing/
MF-009Roslyn Analyzers
Missing protection, invalid permissions, unsafe bypass and build gates
Q4 2026 Roadmap Extension/developers/analyzers/
MF-010Break-Glass Access
Time-limited, dual-approved emergency authority
Q4 2026 Roadmap Extension/solutions/continuous-authorization/
MF-011Decision Explainability
Human-readable and machine-readable decision graph
Q4 2026 Roadmap Extension/platform/decision-evidence/
MF-012Consistency Controls
Staleness policies, offline behavior, refresh and split-brain handling
Q4 2026 Roadmap Extension/architecture/consistency/
MF-013Entra Mapping
Normalized users, groups, app roles, PIM, workloads and risk context
Q4 2026 Roadmap ExtensionThird-Party Integration/microsoft/entra/
MF-014Entra Agent ID
Agent, sponsor, purpose, tool/data scope and transaction limits
Q4 2026 Roadmap ExtensionThird-Party Integration/microsoft/agent-id/
MF-015Sentinel and Defender
Connectors, analytics, workbooks, hunting and response playbooks
Q4 2026 Roadmap ExtensionThird-Party Integration/microsoft/sentinel-defender/
MF-016Azure Governance
Azure Policy, AKS admission, inventory and drift reporting
Q4 2026 Roadmap ExtensionThird-Party Integration/microsoft/azure-governance/
MF-017Runtime Coverage
gRPC, Functions, workers, queues, SignalR, Dapr and Orleans
Preview/developers/frameworks/
MF-018Polyglot Protocol
Language-neutral decision, evidence, permit and revocation contracts
Q4 2026 Roadmap Extension/developers/protocols/
MF-019Migration Tooling
Discovery and conversion from ASP.NET roles, handlers and custom checks
Q4 2026 Roadmap Extension/developers/migration/
MF-020Frictionless Evaluation
CLI, playground, Docker, Codespaces and public samples
Preview/developers/
MF-021Assurance Program
Completed certifications, pen tests and vendor-review evidence
Q4 2026 Roadmap Extension/trust-center/
MF-022Public Benchmarks
Reproducible latency, throughput, memory and failure testing
Q4 2026 Roadmap Extension/trust-center/benchmarks/
MF-023Verifiable Evidence
Signing, hash chains, timestamps, WORM and external verifier
Preview/platform/decision-evidence/
MF-024Telemetry Privacy
Redaction, pseudonymization, residency, retention and legal holds
Q4 2026 Roadmap Extension/trust-center/privacy/
MF-025Multi-Tenant Administration
Tenant policy spaces, delegated administration and isolated keys
Q4 2026 Roadmap Extension/platform/policy-control-plane/
MF-026Enterprise Service Management
SLAs, LTS, lifecycle, support and continuity
Q4 2026 Roadmap Extension/trust-center/operations/
MF-027Marketplace and Licensing
Transactable offer, private offers, entitlements and air-gap licensing
PreviewThird-Party Integration/pricing/
MF-029OCSF Authorization Event Class
A registered OCSF extension defining the per-record authorization decision, with B5 as reference implementation
Q4 2026 Roadmap Extension/platform/decision-evidence/
MF-030Actionable Response Interface
Revoke, suspend and tighten-limit as authorised, recorded operations a SOAR playbook can call
Q4 2026 Roadmap ExtensionThird-Party Integration/microsoft/sentinel-defender/
MF-031Policy Change Impact in Pull Requests
Decision-difference reporting posted onto the pull request that changes policy
Q4 2026 Roadmap Extension/platform/policy-simulation/
MF-032Multi-Party Authorization (m-of-n)
Configurable m-of-n approval before a protected operation executes, each approval an evidenced decision
Q4 2026 Roadmap Extension/roadmap/q4-2026/
MF-033Payments Authorization Profile
The authority decision class applied to money-movement events, so a hold or release carries the same evidenced decision as a data read
Q4 2026 Roadmap Extension/roadmap/q4-2026/
MF-028Product Truth Registry
Single source for capability status, edition, release and evidence
Q4 2026 Roadmap Extension/roadmap/q4-2026/
CRYPTO-confidential-by-defaultConfidential by Default
Generally Available/cryptography/confidential-by-default/
CRYPTO-fips-140-3-level-3FIPS 140-3 Level 3
Generally Available/cryptography/fips-140-3-level-3/
CRYPTO-multi-person-controlMulti-Person Control
Generally Available/cryptography/multi-person-control/
EXT-adaptive-identity-firewallAdaptive Identity Firewall
Generally Available/platform/security-extensions/adaptive-identity-firewall/
EXT-co-hosted-one-hostCo-Hosted, One Host
Generally Available/platform/security-extensions/co-hosted-one-host/
EXT-granular-authorizationGranular Authorization
Generally Available/platform/security-extensions/granular-authorization/
EXT-hmac-request-signingHMAC Request Signing
Generally Available/platform/security-extensions/hmac-request-signing/
EXT-ip-firewallIP Firewall (Extensions)
Generally Available/platform/security-extensions/ip-firewall/
EXT-multi-factorMulti-Factor (Extensions)
Generally Available/platform/security-extensions/multi-factor/
EXT-policy-driven-suspension-caePolicy-Driven Suspension & CAE
Generally Available/platform/security-extensions/policy-driven-suspension-cae/
EXT-rules-based-suspensionRules-Based Suspension
Generally Available/platform/security-extensions/rules-based-suspension/
FEAT-account-managementAccount Management
Generally Available/features/account-management/
FEAT-account-verificationUser Account Verification
Generally Available/features/account-verification/
FEAT-activity-data-authorizationActivity-Data Authorization
Generally Available/features/activity-data-authorization/
FEAT-administrationAdministration
Generally Available/features/administration/
FEAT-ai-agentsAI Agents & Agentic Identity
Generally Available/features/ai-agents/
FEAT-auth-cookieAuthCookie
Generally Available/features/auth-cookie/
FEAT-authenticationAuthentication
Generally Available/features/authentication/
FEAT-credential-blockingPassword / Credential Blocking
Generally Available/features/credential-blocking/
FEAT-error-handlingProfessional Error Handling
Generally Available/features/error-handling/
FEAT-feature-hidingFeature Hiding
Generally Available/features/feature-hiding/
FEAT-hmacHMAC
Generally Available/features/hmac/
FEAT-identitiesIdentities
Generally Available/features/identities/
FEAT-integrator-identificationIntegrator Identification
Generally Available/features/integrator-identification/
FEAT-ip-firewallIP Firewall
Generally Available/features/ip-firewall/
FEAT-key-leakage-protectionKey-Leakage Protection
Generally Available/features/key-leakage-protection/
FEAT-multi-factor-authenticationMulti-Factor Authentication
Generally Available/features/multi-factor-authentication/
FEAT-password-hashingStrong Password Hashing
Generally Available/features/password-hashing/
FEAT-replay-tamper-protectionReplay & Tamper Protection
Generally Available/features/replay-tamper-protection/
FEAT-request-integrity-expirationRequest Integrity & Expiration
Generally Available/features/request-integrity-expiration/
FEAT-security-notificationsSecurity Notifications
Generally Available/features/security-notifications/
FEAT-service-hmacService-HMAC
Generally Available/features/service-hmac/
FEAT-service-keyService-Key
Generally Available/features/service-key/
FEAT-source-packagesSource Packages
Generally Available/features/source-packages/
FEAT-suspensionSuspension
Generally Available/features/suspension/
FEAT-user-managementUser Management
Generally Available/features/user-management/
FEAT-xss-protectionXSS Protection
Generally Available/features/xss-protection/
PIPE-active-data-authorizationActivity-based, data-aware authorization (ADA)
Generally Available/platform/active-data-authorization/
PIPE-b1-xss-screeningB1 · XSS Screening
Generally Available/platform/b1-xss-screening/
PIPE-b2-authenticationB2 · Authentication
Generally Available/platform/b2-authentication/
PIPE-b3-ip-firewall-mfaB3 · IP Firewall & MFA
Generally Available/platform/b3-ip-firewall-mfa/
PIPE-b4-verification-suspensionB4 · Verification & Suspension
Generally Available/platform/b4-verification-suspension/
PIPE-b5-activity-data-authorizationB5 · Activity-Data Authorization
Generally Available/platform/b5-activity-data-authorization/
PIPE-co-hosted-one-hostCo-Hosted, One Host
Generally Available/platform/co-hosted-one-host/
PIPE-security-extensionsSecurity Extensions
Generally Available/platform/security-extensions/
PIPE-security-pipelineThe Security Pipeline
Generally Available/platform/security-pipeline/

Q4 2026 roadmap extensions

These capabilities are specified and not yet released. Each page carries its status from the Product Truth Registry.

Scroll to Top