Illustration of a secure cloud platform linking code, documents, Rust, Azure services, and a PostgreSQL database.
Microsoft's September 2026 Azure SDK roundup has three headline items. Azure AI Search has a new set of preview SDKs. The Rust crate for Azure Storage shared access signatures (SAS) has reached 1.0. And two new libraries let PostgreSQL apps sign in with Microsoft Entra ID, one for .NET and one for JavaScript. The roundup also lists initial stable and beta releases for .NET, Java, JavaScript, Python, Go and Rust.

Microsoft notes that this month's list includes some first releases that were public before September but missed an earlier post. Each package version appears only once. The company's central inventory of Azure SDK packages lists .NET, Java, JavaScript/TypeScript, Python, Go, Rust, C++ and other languages, and shows "Last updated: Sep 2026".

Azure AI Search: new previews for the 2026-08-01-preview API​

The Azure AI Search previews appear under the heading "Azure AI Search 12.1.0-beta.2." They add support for the service's 2026-08-01-preview REST API version in .NET, Java, JavaScript and Python. Microsoft says they expand two areas: managing file knowledge sources and retrieving from knowledge bases. The JavaScript library can also stream retrieval responses.

The API version is a preview, not a stable release. Microsoft Learn lists it as the newest preview data-plane version. The newest stable version is 2026-04-01. Microsoft's standard warning applies: preview features have no service-level agreement, aren't recommended for production, and may change or be limited before general availability.

New service features in this API version​

Microsoft Learn's "What's new" page describes what 2026-08-01-preview adds to the service:

  • File knowledge sources: They now work on Serverless search services. The limits rise to 200 files (up from 100) and 100 MB per file, but only on Serverless and on Dedicated tiers above Free and Basic. There is also a multipart upload operation that accepts custom metadata.
  • Streaming retrieval: Retrieve results can arrive as server-sent events instead of one JSON response. The events report query planning, source activity and the finished answer as each becomes available, and a heartbeat keeps idle connections open. Answers arrive as whole messages. Token-by-token streaming is not supported, so don't build a typing effect around it.
  • Citation URLs: Results from indexed knowledge sources can include a citationUrl that looks up the source document. You follow it with the same query-time authorization token you used for permission-filtered retrieval.
  • Cursor pagination: List Data Sources, List Indexers, List Indexes and List Skillsets now page with pageSize. To filter by name, use search with searchType=prefix, then follow @odata.nextLink to get each next page.
  • Automatic per-language analyzers: Blob, indexed OneLake and indexed SharePoint knowledge sources can detect each document's language and apply a matching Microsoft language analyzer.

These are features of the API version. The roundup doesn't say that every one is exposed in all four language SDKs, so check each package's changelog before counting on a specific feature.

Breaking changes for existing preview code​

The roundup tells anyone who built against an earlier preview to review the changed listing parameters and other preview-only API changes before upgrading. Microsoft Learn's migration page lists these breaking changes:

  • List operations: Listing data sources, indexers, indexes, skillsets and knowledge sources no longer uses $top, $skip and $count. It uses cursor pagination with pageSize, search and @odata.nextLink.
  • Agentic retrieval: Model objects in activity logs are now nested. For server tools in the MCP knowledge source, resultsProcessing replaces inclusionMode.
  • Work IQ knowledge sources: They now sign in through a Microsoft Entra app that you own and a federated credential. This replaces the old preview feature registration and separate access requests.

Microsoft says other existing APIs behave as before. It also recommends upgrading one API version at a time rather than jumping straight to the newest.

Python details​

PyPI's release history lists azure-search-documents version 12.1.0b2, released August 27, 2026. Its changelog:

  1. Adds ApiVersion.V2026_08_01_PREVIEW, which you select with the api_version keyword on the clients.
  2. Adds operations for multipart file knowledge sources, such as update_knowledge_source_file.
  3. Changes list_indexes, list_index_names and their async versions to take search, page_size and search_type instead of top, skip and count.
  4. Replaces McpServerTool.inclusion_mode, matching the service-level resultsProcessing change.
  5. Drops Python 3.9. Python 3.10 or later is now required.

The same PyPI page still says Python 3.9 or later is enough in the prerequisites section of the README. Go by the changelog: plan for Python 3.10 or later.

The changelog confirms the roundup's point that these changes don't touch the stable Python API. Earlier entries name stable version 11.6.0 as unaffected; only code written against a beta is at risk. That guarantee is stated for the Python package, so don't assume it holds identically for the other languages.

Section summary: If you're on an earlier preview, treat this as a real migration. Paging, MCP tool settings, activity-log shapes and Work IQ authentication all change. Stable Python apps on 11.6.0 are unaffected.

Rust: Azure Storage SAS 1.0.0 and Storage Common 1.0.0​

Rust developers get two first stable releases: Azure Storage SAS 1.0.0 and Storage Common 1.0.0. The SAS crate builds Azure Storage shared access signatures.

Microsoft says the stable release fixes SAS generation for blob and directory paths that contain backslashes by normalizing the signed resource path. A SAS is a signed token, so a signature built over one form of the path and checked against another won't match. If your Rust app had signing failures on names with backslashes, this fix is aimed at you.

There is one migration step for preview users. UserDelegationKey now comes from azure_storage_common::models. It is no longer re-exported from azure_storage_sas, so update your imports.

This matters because Microsoft's Storage documentation recommends a user delegation SAS wherever you use SAS. It is secured with Microsoft Entra credentials rather than the storage account key. To get a user delegation key, the Entra identity needs a role that includes the generateUserDelegationKey action. The same documentation warns that Azure Storage doesn't track or audit SAS generation, so limit who can create tokens and keep expiry times short.

Microsoft's roundup doesn't give release dates or detailed changelogs for these crates. Check the crate release notes before you pin versions.

PostgreSQL + Entra ID: stable libraries for .NET and JavaScript​

Two libraries for connecting to PostgreSQL with Entra ID reached 1.0.0:

  • .NET: an Entra ID authentication extension for the Npgsql PostgreSQL driver.
  • JavaScript: @azure/postgresql-auth 1.0.0.

.NET: how it plugs into Npgsql​

The official sample in the Azure SDK for .NET repository shows the setup:

  1. Build an NpgsqlDataSourceBuilder from your connection string.
  2. Call UseEntraAuthentication with a TokenCredential, such as DefaultAzureCredential. There's also UseEntraAuthenticationAsync if you prefer async setup.
  3. Build the data source and open connections as usual.

The extension reads your username from the Entra ID token. It also sets up a password provider that fetches a fresh token when a connection needs one, so your app never handles a long-lived database password. If your connection string already includes a Username, the extension uses it instead. That helps when your database role name differs from your Entra identity.

The sample's prerequisite is an Azure Database for PostgreSQL Flexible Server with Entra ID authentication turned on. If sign-in fails, check that setting first.

JavaScript: the Node.js 22 requirement​

The key upgrade note for JavaScript: version 1.0.0 requires Node.js 22 or later. Microsoft says the API is otherwise the same as the preview.

The earlier beta documentation said the package supported LTS versions of Node.js. Teams still running pipelines or containers on older runtimes should check them before upgrading. According to that beta documentation, the package works with the pg client through entraTokenProvider and with Sequelize through configureEntraAuthentication. That describes the preview; Microsoft says the stable API hasn't changed apart from the Node.js requirement.

Section summary: These libraries replace a hand-rolled token refresh loop with a supported one. On JavaScript, check your Node.js version before you upgrade.

Everything else that shipped​

New stable (1.0.0) releases:

LanguagePackages
.NET clientCode Transparency, PostgreSQL Authentication
.NET managementConnected Cache, Edge Zones, Enclave, Resources Bicep, Resources Deployments, Service Groups
Java managementEdge Zones, Enclave, Resources Deployments, Storage Sync
JavaScript clientAzure PostgreSQL Authentication
JavaScript managementEdge Zones, Enclave
Python managementEdge Zones, Enclave, Service Groups
Go managementEdge Zones, Enclave
Rust clientStorage Common, Azure Storage SAS

New beta releases:

  • .NET client: Discovery. Provisioning libraries for Desktop Virtualization, Enclave, Load Testing, Maps, Resource Health and Subscription, plus four Kubernetes Configuration libraries (Extension Types, Extensions, Flux Configurations and Private Link Scopes).
  • .NET management: Commvault Content Store, Container Service AI Manager, Kubernetes Configuration (Extension Types, Flux Configurations, Private Link Scopes) and Red Hat OpenShift HCP.
  • Java: AI Discovery (client). Management libraries for Commvault Content Store, Red Hat OpenShift HCP and Resources Policy.
  • JavaScript: Web PubSub Chat (client). Red Hat OpenShift HCP (management).
  • Python: IoT Device Registry Software Update (client). Red Hat OpenShift HCP (management).
  • Go: Red Hat OpenShift HCP management at 0.1.0.

The .NET Provisioning betas continue a push from last month. The August roundup, as NTCompatible reported, highlighted eleven new Azure.Provisioning.* betas aimed at unifying infrastructure-as-code with typed C# APIs. Nine more Provisioning packages this month suggest Microsoft is serious about letting .NET developers define Azure resources in C# instead of ARM templates.

What to do next​

  • On an Azure AI Search preview: Read the migration list before you bump versions, especially if you page through list results or use MCP knowledge sources. Upgrade one API version at a time.
  • On stable Azure AI Search Python (11.6.0): Nothing to do. If you try the beta, you'll need Python 3.10 or later.
  • Using Rust SAS: Move to 1.0.0, especially if you sign paths that contain backslashes, and fix your UserDelegationKey imports.
  • Connecting to PostgreSQL with Entra ID: .NET teams can adopt the Npgsql extension. JavaScript teams should confirm they're on Node.js 22 before installing 1.0.0.
  • Everyone else: Scan the stable list. A 1.0.0 you were waiting on for Edge Zones, Enclave or Service Groups may have just shipped.

The takeaway: this is an ordinary monthly roundup, but the Search preview changes are breaking changes. Read them before you upgrade, not after something stops working.

 

References

  1. Azure SDK Release (September 2026) Azure SDK Blog 2026-09-29T21:09:53+00:00
  2. Azure SDK Release (August 2026): AI Discovery GA, Provisioning Betas, and Rust Cosmos DB Updates ntcompatible.com
  3. azure-search-documents · PyPI pypi.org