Repository navigation
Releases: Azure/azure-iot-operations
Release list
2609 Update
AIO2609 Public Release Notes
Release date: September 2026
Release type: Patch
Current GA version: 2609 · Version history
Azure IoT Operations 2609 adds general availability support for Red Hat OpenShift Container Platform and delivers reliability and security fixes for industrial connectors, MQTT messaging, state store workloads, and deployment workflows. It improves connector continuity, broker recovery under memory pressure, configuration validation, media clip storage, and managed identity protection.
Release Highlights
-
Red Hat OpenShift Container Platform support now generally available: Deploy Azure IoT Operations on Red Hat OpenShift Container Platform (x86_64). Supported environments | Prepare your cluster
-
MQTT broker resilience: Broker recovery and state store processing now remain available when durable client state exceeds a reconnecting client's in-flight limit, when long-lived state entries use time-to-live settings, and when response memory is under pressure.
-
Connector continuity: OPC UA connector deployments no longer restart unnecessarily after supervisor restarts, and heartbeat monitoring no longer grows memory while an OPC UA server is offline.
-
Media clip storage: Media connector MP4 and MKV clip tasks can now complete when writing to filesystem-backed persistent storage.
-
Stronger MQTT configuration validation: MQTT Connector configuration now enforces safe source-to-destination mappings, and authenticated access.
-
Deployment reliability: Deployments that disable OPC UA now complete without waiting for an unused connector template.
-
Security hardening: This release strengthens shared-subscription authorization and managed identity authentication for transform artifact registries.
-
Deployment Image List (DIL): Download the DIL for this release to support dependency scanning and private-registry mirroring. Download the DIL for this release | How to mirror images to a private registry
Upgrade recommended if you use OPC UA, Media, REST or SSE connectors; MQTT shared subscriptions; long-lived state store entries; persisted MQTT sessions; transform artifact registries with managed identity; or deployments that disable OPC UA. This release contains reliability, validation, observability, and security fixes across these scenarios.
Upgrade to 2609 from any supported GA version to receive the latest deployment and runtime reliability improvements. Staying current is recommended for continued support and reliability.
Version support: Azure IoT Operations 2609 continues the 1.4.x minor version series. Under the N-2 version support policy, the supported versions remain 1.4.x, 1.3.x, and 1.2.x. The 1.1.x series is no longer supported. Customers still on 1.1.x should upgrade to remain eligible for Azure support.
Known Issues
For the full list of active known issues, see Known Issues.
- Fixed in this release: MQTT shared-subscription authorization no longer allows a topic wildcard to match shared-subscription topics outside its intended scope.
Components Overview
This release improves OPC UA, MQTT, Media, REST, and SSE connectors; strengthens MQTT broker recovery and state store memory handling; corrects deployment behavior when OPC UA is disabled; removes obsolete metrics from the sample monitoring dashboard; and hardens authorization and managed identity use.
Connectors
OPC UA
Fixes
-
Stable connector deployment names: Supervisor restarts could generate different names for long secret-volume identifiers and trigger a rollout of every affected connector pod, interrupting asset telemetry. Generated names are now stable across restarts, preventing these unnecessary rollouts.
-
Heartbeat memory usage: Heartbeat monitoring could steadily consume memory while a monitored OPC UA server was offline. Monitoring now releases resources correctly while the server is unavailable.
For configuration guidance, see OPC UA connector.
MQTT
Improvements
- Publish-loop prevention: Configurations that use the built-in MQTT broker now reject an identical source and destination topic, preventing circular publish loops.
Breaking Changes
- MQTT connector authentication validation: MQTT connector configurations now reject anonymous authentication for external brokers. Existing deployments that rely on anonymous authentication must be updated to use a supported authentication mechanism before upgrading.
Media
Fixes
- clip-to-fs .wav file generation:
clip-to-fstasks supports audio-only.wavfile generation. - -to-fs task destination: 'snapshot-to-fs' and 'clip-to-fs' tasks do respect an Asset's defaultStreamsDestinations' storage path configuration.
- snapshot and clip filenames: Snapshot and clip files now use stable UTC timestamp-based names
- Snapshots:
snapshot_YYYYMMDD-HHMMSS-NNNNNNNNNZ. - Clips:
clip_YYYYMMDD-HHMMSS-000000000Z_s.
- Snapshots:
- Duplicate task starts no longer interrupt active work. Repeated start management calls for clip, snapshot, or stream tasks are ignored while the task is already running, rather than cancelling and restarting it.
- Filesystem clip output: MP4 and MKV clip capture could start but fail when handing the completed clip to filesystem-backed persistent storage. Clip tasks can now write completed files to the configured destination.
- Asset deletion now stops associated tasks. Deleting an Asset or device endpoint cleans up remaining data-operation tasks and management-action handlers, preventing orphaned workloads.
- FFmpeg task cleanup was improved. Task cancellation and panic handling were hardened to reduce the risk of orphaned FFmpeg processes.
Messaging and MQTT
Fixes
-
Persisted session recovery: Broker recovery could repeatedly restart while restoring durable client state that contained more unacknowledged messages than the reconnecting client's current in-flight limit. Recovery now restores the state safely while continuing to enforce flow control for new messages.
-
State store time-to-live memory: State entries with long time-to-live values could retain request buffers until expiry, eventually causing memory backpressure and rejecting unrelated publishes. State store processing now releases the request buffer after copying the entry into state store memory.
-
State store responses under pressure: Completing a state store operation could restart a broker backend when response memory crossed its allocation threshold after the operation was accepted. Accepted operations and notifications can now complete while existing backpressure continues to reject new work at the configured threshold.
-
Shared-subscription authorization: Subscription authorization could apply a wildcard match to shared-subscription topics and grant unintended message access. Shared-subscription topics now receive the required authorization handling.
Azure IoT Operations CLI
Fixes
- Deployments with OPC UA disabled: Creating an Azure IoT Operations instance with OPC UA disabled could wait indefinitely because the deployment still included an OPC UA connector template. The template is now omitted when OPC UA is disabled, allowing the deployment to complete.
For full changelog, see Releases · Azure/azure-iot-ops-cli-extension.
Observability
Fixes
- Sample dashboard metrics: The sample Grafana dashboard no longer includes obsolete discovered-asset and discovered-device metrics that are not emitted by current releases.
Security
Fixes
- Transform artifact registry authentication: Managed identity authentication for transform artifact registries now validates the destination before requesting and transmitting credentials, preventing tokens from being sent to untrusted endpoints.
For more information, see the Azure IoT Operations documentation.
2608 Update
AIO2608 Public Release Notes
Release date: August 2026
Release type: Patch
Current GA version: 2608 · Version history
Azure IoT Operations 2608 is a reliability-focused release for industrial connectors and command-line deployment workflows. It improves media stream recovery, message processing, and 3 OPC UA functionalities: connector provisioning, high-availability behavior, and lifecycle cleanup.
Release Highlights
-
Deployment Image List for private registries: Every release now ships a machine-readable inventory of its container images, identified by immutable SHA-256 digest, for dependency scanning and private-registry mirroring. Download the DIL for this release | How to mirror images to a private registry
-
OPC UA high-availability recovery: Asset health reporting now recovers after an OPC UA connector leader change.
-
OPC UA data delivery under load: High-availability connector deployments now preserve individual values while an OPC PLC is under load.
-
Reliable instance deletion: Azure IoT Operations instance deletion now completes without the OPC UA supervisor recreating connector resources during cascading cleanup.
-
Media stream recovery: The media connector now restarts processing after its stream source restarts.
-
User properties handling: MQTT connector no longer forwards user properties to avoid collision with reserved property names.
Upgrade recommended if you use OPC UA high availability, media connectors, MQTT connector CloudEvents metadata, or command-line deployment workflows. This release contains nine fixes and one command-line workflow improvement focused on deployment and runtime reliability.
Upgrade to 2608 from any supported GA version to receive the latest deployment and runtime reliability improvements. Staying current is recommended for continued support and reliability.
Version support: Azure IoT Operations 2608 continues the 1.4.x minor version series. Under the N-2 version support policy, the supported versions remain 1.4.x, 1.3.x, and 1.2.x. The 1.1.x series is no longer supported. Customers still on 1.1.x should upgrade to remain eligible for Azure support.
Known Issues
For the full list of active known issues, see Known Issues.
- Fixed in this release: OPC UA connector high-availability deployments now recover asset health after a leader change, remove the previous connector instance after configuration changes, and preserve individual values under load.
Components Overview
This release improves OPC UA connector provisioning, high-availability operation, and deletion cleanup; restores media connector processing after source restarts; updates MQTT connector handling of reserved CloudEvents properties; and aligns command-line workflows with the 2608 release.
Connectors
OPC UA
Fixes
-
Connector template availability: The OPC UA connector template could be missing after an Azure IoT Operations instance deployment. Deployments now include the connector template required to configure OPC UA assets.
-
Provisioning status completion: The OPC UA connector template provisioning status could remain in progress. Provisioning status now transitions to Succeeded when deployment completes.
-
Health recovery after leader changes: Asset health could remain stale after the active OPC UA connector changed in a high-availability deployment. Asset health now recovers after leader changes.
-
High-availability configuration cleanup: Changing the high-availability setting after initial creation could leave the previously created connector instance running. Configuration changes now remove the superseded instance.
-
Data delivery under load: The OPC UA connector could drop individual values from an OPC PLC under load in high-availability mode. The connector now preserves those values during sustained load.
-
Instance deletion completion: Azure IoT Operations instance deletion could hang while the OPC UA supervisor recreated connector resources during cascading cleanup. Deletion now prevents resource recreation and completes successfully.
For configuration guidance, see OPC UA connector.
MQTT
Fixes
- CloudEvents property handling: MQTT connector messages containing reserved CloudEvents property names in user properties could be skipped. Message processing now does not forward any user properties to avoid collisions.
Media
Fixes
- Stream source recovery: The Media connector could remain stopped after its stream source restarted. The connector now resumes processing after the source becomes available again.
Azure IoT Operations CLI
Improvements
-
Release alignment: Command-line deployment and lifecycle workflows are updated for the 2608 release.
-
Data flow graph validation: Data flow graph creation now detects transforms that are incompatible with your instance (i.e., that require a newer runtime version).
Fixes
-
SecretSync federation: Fixed OIDC issuer mismatches and repairs affected federated identity credentials.
-
OPC UA upgrades: Upgrades now create missing or repair failed default OPC UA connector templates.
For full changelog, see Releases · Azure/azure-iot-ops-cli-extension.
Security
Fixes
- Vulnerability remediation: Addressed security vulnerabilities across multiple components including Akri, Connectors, and Schema Registry.
For more information, see the Azure IoT Operations documentation.
2607 Update
AIO2607 (v1.4.41) Public Release Notes
Release date: July 2026
Release type: Milestone
Current GA version: 2607 · Version history
Azure IoT Operations 2607 is a milestone release that delivers ARM64 platform support (GA), new built-in data flow graph transforms (count-based windows, trigger-based windows, and per-topic throttling), raw data observation via Azure Event Grid, OPC UA connector high availability and recursive tag onboarding, broker backpressure resilience, and critical security fixes.
Release Highlights
-
ARM64 platform support now generally available: Azure IoT Operations now supports ARM64 architectures, enabling deployment on ARM64-based Kubernetes clusters with full parity across installation, observability, and lifecycle operations. Supported environments matrix
-
Enhanced transforms for data flow graphs: Use the new Throttle transform for better control over your data streams, or the improved Window, Branch, Filter, and Map transforms for more flexible aggregation, routing, validation, and broker state store lookups. Process data with data flow graphs
-
In-place transform upgrades: Use the operations experience to upgrade or downgrade a transform right where it is within a data flow graph — no need to delete and add again.
-
OPC UA connector high availability: Configure high availability mode for OPC UA assets to achieve near-zero message loss during failover scenarios, improving data reliability for critical industrial workloads.
-
Recursive OPC UA tag onboarding: Recursively discover and onboard all tags from a starting node in an OPC UA server's address space into one or more assets, significantly reducing manual configuration for large-scale deployments.
-
Broker backpressure resilience: Eliminated the risk of dataflow and application deadlocks when data is re-injected into a backpressured MQTT broker, improving system stability under high-throughput conditions.
-
Security vulnerability remediation: Addressed a security vulnerability in dataflow managed identity token handling and updated dependencies to remediate known vulnerabilities.
Upgrade recommended if you deploy on ARM64, rely on data flow transforms, OPC UA connectors, or management actions — this release delivers new GA capabilities, critical stability improvements, and security patches.
Upgrade to 2607 from any supported GA version to ensure you receive the latest security patches and feature enhancements. Staying current is recommended for continued support and reliability.
Version support: Azure IoT Operations 2607 introduces the 1.4.x minor version series. Under the N‑2 version support policy, the supported versions are now 1.4.x, 1.3.x, and 1.2.x. The 1.1.x series is no longer supported. Customers still on 1.1.x should upgrade to remain eligible for Azure support.
Known Issues
For the full list of active known issues, see Known Issues.
- ✅ Fixed in this release: MQTT connector blocks external MQTT brokers with private IPs. Starting in 2605, if an external MQTT broker used a private IP address, the MQTT connector would not connect to it. This is now fully resolved.
Components Overview
This release spans improvements to data flow graphs (new built-in transforms, transform version management), Connectors (OPC UA high availability, recursive tag onboarding, Akri-based OPC UA deployment, MQTT private IP fix, diagnostics improvements), Messaging (backpressure resilience, message expiry correctness, topic filter security), Platform (ARM64 GA), Azure IoT Operations Experience (management actions configuration, raw data observation, transform version picker), CLI (2607 deployment alignment), and Security (managed identity token hardening, dependency updates).
Data Flows & Data Flow Graphs
New features
-
Count-based window transform: A new built-in transform that aggregates records based on a configurable record count threshold, enabling count-driven data aggregation directly in data flow graphs without custom WebAssembly modules.
-
Trigger-based window transform: A new built-in transform that aggregates records based on trigger conditions, enabling event-driven windowing for scenarios where time-based aggregation is insufficient.
-
Per-topic throttle transform: A diagnostic data flow can subscribe to selected MQTT topics and use the new Throttle transform to apply independent message-rate limits before forwarding sampled messages to cloud endpoints such as Azure Event Grid. This enables raw data observation while controlling cloud egress volume.
-
Date and time expression functions: Map, Branch, Filter, and Accumulate transforms now support built-in date and time functions including
now,duration_between,day_of_week,format_timestamp, epoch conversion, and timestamp parsing. -
Dynamic DSS lookup keys: Dataset enrichment can now derive Distributed State Store (DSS) lookup keys from fields in each incoming message, enabling per-message enrichment without static keys or separate graph deployments.
-
Transform version management: Data flow transforms now support minimum Azure IoT Operations version compatibility checks and a version picker in the transform catalog, enabling operators to select compatible transform versions during pipeline configuration.
Improvements
- Branch schema validation: Branch transforms can now validate incoming messages against their schemas and route valid and invalid messages through separate output paths, allowing invalid messages to be sent to a dedicated topic for inspection or further processing.
Fixes
-
Connector startup resilience: Fixed issues where data flow connectors could permanently stop processing after transient startup failures (such as state store timeouts) and where the state manager retry loop lacked backoff, causing Kubernetes API flooding. Connectors now recover gracefully from transient startup errors with proper exponential backoff.
-
Status client performance: Fixed status client inefficiencies that could overload the Kubernetes API under high connector counts, including a thundering herd pattern in concurrent resource updates and an unnecessary GET request that blocked ConfigMap writes. The status client now batches updates efficiently and writes directly without redundant reads.
-
Operator ConfigMap update ordering: Fixed a race condition in operator reconciliation where ConfigMap updates could arrive out of order, causing stale configuration to be applied to data flow components.
-
Custom resource cleanup ordering: Fixed an issue where the CRD deletion job attempted to patch custom resources before removing webhook configurations, which could cause the deletion to hang.
-
WebAssembly runtime resilience: Fixed multiple issues affecting WebAssembly transform reliability: data flow pods could become permanently stuck after a WASM graph controller restart, the controller could serve partial artifacts due to non-atomic file writes, and channel closures could cause unrecoverable backpressure buildup. The WASM runtime now handles controller restarts, ensures atomic artifact delivery, and automatically recovers from channel failures.
-
Upgrade status job transient error handling: Fixed an issue where the upgrade status job failed immediately on transient Kubernetes API errors instead of retrying. The job now retries transient failures before reporting an error.
-
Redundant MQTT keepalive traffic: Fixed an issue where the MQTT client sent redundant PINGREQ packets even when other outgoing packets already satisfied the keepalive interval, generating excessive log noise. The client now correctly suppresses keepalives when regular traffic is flowing.
-
Transform schema rendering: Fixed issues where certain transform schema fields could not be rendered correctly in the configuration UI, affecting the Branch, Throttle, Map, Window, and Filter modules. Schemas now use compatible type representations across all built-in transforms.
-
Window transform boundary handling: Fixed an issue where burst-input messages were incorrectly accumulated across window boundaries, causing data from one window to leak into the next. Window boundaries are now enforced correctly.
-
Health status after upgrade: Fixed an issue where the health status ConfigMap was not created after upgrading from version 1.3 to 1.4, which could prevent health status reporting from initializing on upgraded clusters.
-
Dataflow and dataflow graph metrics accuracy: Fixed an issue where active dataflow and dataflow graph metrics reported flaky or inconsistent values, which could produce misleading monitoring dashboards. Metrics are now reported consistently.
-
Concurrent token request handling: Fixed a thundering herd issue where concurrent system-assigned managed identity token requests during pod startup caused HTTP 429 throttling responses from the token endpoint, leading to pod crashes. Token requests are now serialized with backoff.
Akri
New features
- Readiness-driven health evaluation: Connectors now use readiness-driven health evaluation when a readiness probe is configured, falling back to existing pod event-based health logic otherwise.
- Improved connector observability: connector instance counts can now be broken down by protocol (endpoint type), and a new ac...
2606 Update
AIO2606 (v1.3.137) Public Release Notes
Release date: June 2026
Release type: Patch
Current GA version: 2606 · Version history
Azure IoT Operations (AIO) 2606 is a security and stability-focused patch release that delivers critical security vulnerability remediation across MQTT broker authorization, registry endpoints, and onboarding components, reliability improvements for OPC UA and dataflow connectors, and enhanced testing coverage for connector resilience.
Upgrade to 2606 from any supported GA version to ensure you receive the latest security patches and reliability enhancements. Staying current is recommended for continued support and reliability.
Release Highlights
-
Critical security vulnerability remediation: Addressed three high-priority security vulnerabilities including globe metacharacter injection in broker authorization, arbitrary audience/host token minting in registry endpoints, and incomplete ABAC conditions in onboarding role assignment.
-
OPC UA connector session management enhancements: Improved session lifecycle management with configurable method-execution client idle timeout and fixed issues preventing endpoints from transitioning between states correctly.
-
Dataflow health status and enrichment reliability: Fixed issues where dataflow health status could become stuck in a degraded state after transient failures, and resolved problems with the Map transform when enriching datasets with multiple records.
-
MQTT connector resilience improvements: Fixed an issue where async task panics could silently fail, addressed MQTT source status reporting on disconnect, and enhanced broker authorization handling with improved attribute matching validation.
Connectors
Fixes (MQTT)
- Connector async task panic handling: Fixed an issue where panics in connector async tasks could cause the MQTT connector to stop processing device data without surfacing a clear failure signal. The connector now properly surfaces and logs async task failures to enable faster diagnosis.
OPC UA
Fixes
-
Session management and idle timeout: Fixed an issue where OPC UA Commander opened and closed sessions too frequently in certain customer scenarios. The method-execution client idle timeout is now configurable, allowing operators to tune session lifecycle behavior for their specific workloads.
-
Action request expiration handling: Fixed an issue where actions were enqueued in the OPC UA execution queue even if the request had already expired. Expired requests are now properly rejected before reaching the execution queue.
-
Endpoint state transitions: Fixed an issue where changed endpoints never transitioned to other states, causing them to remain in an inconsistent state. Endpoints now correctly transition between states in response to configuration changes and operational events.
MQTT
Fixes
- Broker authorization attribute matching: Fixed an issue where MQ Broker authorization with attributes expected all attributes from the Security Access Token (SAT) to match configured patterns. Authorization validation now correctly handles partial attribute matching according to configured policies.
Dataflows
Fixes
-
Health status state machine recovery: Fixed an issue where dataflow graph health status could become stuck at Degraded after a download timeout. The health status state machine now correctly transitions out of degraded states when operations succeed.
-
Map transform enrichment with multi-record datasets: Fixed an issue where the 1P "Map" transform failed to enrich records when the context dataset contained multiple records and belonged to an asset. The enrichment logic now correctly handles multi-record context datasets.
-
Source status unavailability reporting on disconnect: Fixed an issue where the MQTT source status was not reporting unavailable when the connector disconnected. The source now correctly reports availability state changes on connection events.
Platform
Fixes
- Meta Operator recovery from transient failures: Fixed an issue where an Azure IoT Operations instance custom resource (CR) could become permanently stuck in Failed state after a transient upgrade failure. Instance recovery is now more resilient to temporary failures during upgrades and cluster scaling events.
Security
Fixes
-
Glob metacharacter injection in BrokerAuthorization: Fixed a critical security vulnerability where special characters in BrokerAuthorization state-store key pattern substitution could be interpreted as glob metacharacters, potentially allowing unauthorized access. Key pattern matching now properly escapes metacharacters.
-
RegistryEndpoint arbitrary audience/host for MSI token minting: Fixed a critical security vulnerability where RegistryEndpoint allowed arbitrary audience and host values when minting Managed Service Identity (MSI) tokens. Token minting now enforces strict validation of audience and host parameters.
-
Azure IoT Operations Onboarding role self-assignment: Fixed a critical security vulnerability where the Azure IoT Operations Onboarding role had incomplete Attribute-Based Access Control (ABAC) conditions, allowing identities to self-assign the Contributor role. ABAC conditions have been strengthened to prevent role self-escalation.
-
Schema Registry vulnerability remediation: Addressed security vulnerabilities in Schema Registry components by updating affected dependencies to patched versions.
Known Issues
- Inconsistent default authentication behavior on Akri Operator: The Akri Operator may display inconsistent default authentication behavior in certain configurations. Refer to updated documentation for recommended authentication configuration patterns.
- MQTT Connector blocks external MQTT brokers with private IPs. Starting 2605, if the external MQTT broker has a private IP, the MQTT connector will not connect to it. This will be fully resolved in 2607.
2605 Update
AIO2605 (v1.3.105) Public Release Notes
Release date: May 2026
Release type: Patch
Current GA version: 2605 · Version history
Azure IoT Operations (AIO) 2605 is a security and reliability-focused patch release that delivers network security hardening for MQTT, REST, and SSE connectors, vulnerability remediation across the MQTT connector and Schema Registry, improved MQTT connector resilience, and reduced logging noise in the REST and SSE connectors.
Upgrade to 2605 from any supported GA version to ensure you receive the latest security patches and reliability enhancements. Staying current is recommended for continued support and reliability.
Release Highlights
-
Connector address validation and network security hardening: The MQTT, REST, and SSE connectors now validate configured server URLs against restricted address ranges, preventing connections to internal, loopback, link-local, and cloud-reserved endpoints.
-
MQTT connector data forwarding resilience: Fixed an issue in the MQTT connector's data forwarding pipeline that could block further processing of datasets. The connector now handles forwarding errors gracefully without disrupting other datasets.
-
OPC UA connector session management improvements: The OPC UA connector's model change observer now supports multiple subscribers per endpoint using a single shared session, significantly reducing session overhead.
-
Security vulnerability remediation: Addressed High-severity security vulnerabilities across the MQTT connector and Schema Registry components, including OpenSSL and system library updates.
Connectors
Fixes (MQTT, REST, SSE)
- Address validation and network security hardening: Fixed an issue where the MQTT, REST, and SSE connectors accepted arbitrary URL targets without sufficient address validation. The connectors now block connections to restricted addresses, report configuration errors for blocked addresses, block DNS names that resolve to restricted ranges, and disable automatic HTTP redirect following to prevent bypass of address validation controls.
MQTT
Fixes
-
Data forwarding pipeline resilience: Fixed an issue where a failure in the MQTT connector's data forwarding path could block the dataset processing pipeline, affecting all datasets processed by the connector. The connector now isolates forwarding failures to the affected operation without disrupting other datasets.
-
Reconnection backoff for external MQTT servers: Fixed an issue where the MQTT connector immediately attempted to recreate a connection after a disconnection. The connector now implements a reconnect delay with exponential backoff.
Known Issues
- MQTT connector template version mismatch during update: When updating to 2605, existing MQTT connector templates may display mismatched metadata versions in the portal. To resolve, delete and recreate the connector template. Alternatively, use the Azure CLI to update the connector. This will be fully resolved in 2606.
REST / SSE
Fixes
- Reduced logging noise: Fixed an issue where the REST connector produced logs on every sampling interval, generating excessive log output. Sampling-interval and status reporting logs have been reduced and error messages improved with more actionable detail.
OPC UA
Fixes
-
Excessive session creation for model change observation: Fixed an issue where the OPC UA connector created a separate session for every model change observer, even when sync properties was disabled. The observer now shares a single session per endpoint and is no longer created when sync properties is disabled.
-
Unique certificate identity for multi-instance deployments: Fixed an issue where multiple AIO instances connecting to the same OPC UA server generated certificates with the same Common Name. Each instance now generates certificates with a unique subject Common Name.
-
OPC UA connector startup race condition: Fixed a race condition during startup where an incorrect signal after connecting to the MQTT broker caused the connector to hang.
Messaging and MQTT
Fixes
-
Broker replica recovery during cluster scaling: Fixed an issue where an MQTT broker replica joining an existing cluster could become permanently stuck during recovery. Broker replicas now correctly complete data synchronization before becoming operational.
-
Custom authentication diagnostics and connectivity: Fixed an issue where custom authentication failures and certificate parsing errors were silently discarded. Warning-level logs are now emitted for authentication failures, and the network policy has been updated to allow authentication pods to reach custom authentication servers.
-
Broker data consistency during pod failures: Fixed an issue where the MQTT broker's internal replication could produce inconsistent data if a broker pod was terminated during state synchronization. State synchronization is now atomic.
-
Diagnostics probe memory stability: Fixed an issue where the MQTT broker diagnostics probe could enter an infinite loop and consume unbounded memory under memory pressure. The probe now correctly detects and handles cyclic references.
Dataflows
Fixes
-
Unnecessary error logging for optional health status configuration: Fixed an issue where the dataflow engine logged error messages when the optional health status configuration was not present. The configuration is now correctly treated as optional.
-
Health status not reported for Kafka delivery failures: Fixed an issue where the dataflow health status was not updated when messages continuously failed to deliver to Kafka destinations. The dataflow now reports an unavailable health status when Kafka delivery fails.
-
Proxy support for image pulls: Fixed an issue where proxy environment variables were not passed through to the container runtime during image pulls. Proxy settings are now correctly propagated.
Azure Device Registry
Fixes
- Schema Registry vulnerability remediation: See Security for details.
Azure IoT Operations CLI Extension
New features
-
Data flow graph command group: Added a new
az iot ops dataflowgraphcommand group that enables operators to manage DataflowGraph resources associated with a dataflow profile. The group includes apply (create or replace from a JSON configuration file via--config-file), show, list, and delete commands, providing first-class CLI support for dataflow graph lifecycle management. -
Data flow graph configuration validation: The
az iot ops dataflowgraph applycommand now validates node connection directions and enforces required graph node configuration parameters before submission, surfacing actionable client-side errors instead of relying on server-side rejection. -
Mgmt actions clientIdPrefix: The
az iot ops mgmt-actions enablecommand now setsclientIdPrefixon the EG MQTT dataflow endpoint it creates.
Fixes
-
Friendly error for invalid configuration files: Fixed an issue where CLI commands that accept
--config-filesurfaced a raw parser traceback for malformed JSON. The CLI now raises a clear, user-friendly error message identifying the invalid file. -
Connector template image tag resolution: Fixed an issue where the connector template create flow did not use the correct image tag source. The CLI now resolves the connector image tag from
imageConfigurationSettings.tag, ensuring templates reference the intended image version.
Platform
Fixes
- Observability metrics collection during installation: Fixed a race condition during installation where a resource cleanup step could remove freshly installed observability components. The cleanup process now correctly excludes observability resources, ensuring metrics collection is reliably deployed.
Security
Fixes
-
MQTT connector vulnerability remediation: Addressed High-severity OpenSSL and system library vulnerabilities in the MQTT connector container image.
-
Schema Registry vulnerability remediation: Addressed security vulnerabilities in Schema Registry by updating affected dependencies to patched versions.
-
Dataflows WebAssembly runtime vulnerability remediation: Addressed High and Critical severity vulnerabilities in the WebAssembly runtime by updating affected dependencies to patched versions.
2604 Update
AIO2604 (v1.3.70) Public Release Notes
Release date: April 2026
Release type: Patch
Current GA version: 2604 · Version history
Azure IoT Operations (AIO) 2604 is a stability and security-focused release that delivers vulnerability remediation across multiple components, MQTT connector reliability and health reporting improvements, OPC UA connector health state consistency, dataflow stability fixes, and new portal and tooling capabilities.
Release Highlights
-
MQTT connector health status improvements: The MQTT connector now surfaces richer health status signals for assets and endpoints, improving operational visibility and enabling faster diagnosis of connectivity issues.
-
Data Flow extension for VSCode now generally available: The VS Code extension for building third-party WebAssembly transforms is now GA, enabling developers to author and test custom data transformation modules directly from VS Code.
-
Resource status in Azure Portal and CLI: AIO and Azure Device Registry resource health status is now visible in the Azure IoT Operations Experience, Azure Portal, and CLI, giving operators a unified view of resource state across cloud and edge.
-
Dataflow graph startup reliability: Fixed a race condition that could prevent dataflow graphs from starting on busy clusters, improving deployment reliability in high-density environments.
-
Security vulnerability remediation: Addressed High and Critical security vulnerabilities across Akri, Schema Registry, AIO Observability, and OpenTelemetry SDK components.
Upgrade recommended if you rely on MQTT connectors, OPC UA connectors, dataflow graphs, or health monitoring — this release delivers critical connector stability fixes, improved health reporting, and security patches.
Upgrade to 2604 from any supported GA version to ensure you receive the latest security patches and reliability enhancements. Staying current is recommended for continued support and reliability.
Components Overview
Dataflows
Fixes
-
Dataflow graph startup race condition: Fixed an issue where dataflow graphs could fail to start under certain race conditions on busy clusters, which could result in timed-out commands and failed pipeline execution. Dataflow graphs now start reliably regardless of cluster load.
-
Client-side retries for transient failures: Fixed an issue where dataflows lacked client-side retry logic, which could cause them to hang indefinitely on transient failures. Dataflows now include retry logic to recover gracefully from transient errors without requiring manual intervention, improving overall messaging reliability.
Connectors
OPC UA
Fixes
- Health state retransmission: Fixed an issue where the OPC UA connector did not periodically retransmit the last known health state for assets and devices, which could cause resources to fall to Unknown status after 5 minutes of stable operation. The connector now retransmits health state every 5 minutes, ensuring that healthy assets and devices maintain accurate status reporting.
MQTT
Fixes
-
Health status reporting improvements: The MQTT connector now surfaces improved health status signals for assets and endpoints, providing operators with more accurate and timely visibility into connector health and connectivity state.
-
Connector initialization timeout: Fixed an issue where the timeout for loading a transform graph to the connector was insufficient, which could cause dataset processing to fail.
-
Asset discovery with numeric identifiers: Fixed an issue where the MQTT connector failed to discover assets when the asset-level identifier derived from MQTT topics started with a digit (common with MAC address-based identifiers), which could prevent assets from being onboarded. The connector now correctly handles identifiers that begin with numeric characters. Connector version 2.0.0 is now available with this fix.
Azure IoT Operations Experience
New features
- Resource status visibility: AIO and Azure Device Registry resource status is now surfaced in the Azure IoT Operations Experience, Azure Portal, and CLI, enabling operators to view resource health and operational state directly from cloud management surfaces.
Security
Fixes
- Vulnerability remediation: Addressed security vulnerabilities across multiple components, including Akri, Schema Registry, and AIO Observability.
2603 Update
AIO2603 (v1.3.38) Public Release Notes
Release date: March 2026
Release type: Stable
Current GA version: 1.3.38 (2603) · Version history
Azure IoT Operations 2603 delivers three GA milestones — no-code data flow graphs, cloud-to-edge management actions, and the MQTT connector — along with unified health status reporting, broker reliability improvements, and connector stability fixes across the platform.
Release Highlights
- Unified health status across Azure IoT Operations: Core components, data flows, brokers, assets, and connectors now expose consistent health states (Available / Degraded / Unavailable / Unknown) surfaced through Kubernetes custom resources and Azure Resource Manager. Deploy observability resources
- No‑code data flow graphs now generally available: Build visual data processing pipelines using built‑in transforms (Map, Filter, Branch, Window, Concatenate) without writing custom WebAssembly, with improved reliability, validation, and observability. Process data with data flow graphs
- Cloud‑to‑edge management actions now generally available: Execute management actions from the cloud to on-premises assets using Azure Resource Manager and Event Grid MQTT messaging. Supports OPC UA, ONVIF, and MQTT connectors with built‑in RBAC access control, managed identity authentication, and activity logs for auditing. Enable and run management actions
- MQTT connector now generally available: The MQTT connector is now GA, with MQTT asset discovery for external endpoints, payload transformation using WebAssembly modules, and cloud‑to‑edge management actions for command and control scenarios. How to use the connector for MQTT
- Improved messaging and broker reliability: Enhancements include graceful shutdowns during upgrades, end‑to‑end idempotent replication, improved persistence correctness, and reduced false health signals under load.
- Stronger connector health and lifecycle stability: OPC UA, Media, ONVIF, REST/HTTP, SSE, and MQTT connectors now surface richer health signals, with improved recovery and redeployment behavior.
- Enhanced Azure IoT Operations CLI: Updated CLI capabilities for lifecycle management, bulk asset import/export, management actions, and alignment with Azure IoT Operations 2603 APIs and deployed extensions. Azure IoT Operations CLI extension
Upgrade recommended if you rely on OPC UA connectors, MQTT connectors, data flow graphs, cloud-to-edge management actions, or health monitoring — this release delivers GA-quality no-code data flow graphs, GA management actions, GA MQTT connector, unified health status, and critical connector stability fixes.
Upgrade to 2603 from any supported GA version to ensure you receive the latest security patches and feature enhancements. Staying current is recommended for continued support and reliability.
Review before upgrading if you have assets created with older API versions — they may require recreation to report health status correctly (see Known Issues).
Note
Features marked (Preview) are provided as-is and are not recommended for production use. They may be changed or removed without notice.
Version support: Azure IoT Operations 2603 introduces the 1.3.x minor version series. Under the N‑2 version support policy, the supported versions are now 1.3.x, 1.2.x, and 1.1.x. The 1.0.x series (versions 2411 through 2503) is no longer supported. Customers still on 1.0.x should upgrade to remain eligible for Azure support.
Known Issues
For the full list of active known issues, see Known Issues.
⚠️ Newly tracked: Assets created using older API versions may not report health status after upgrading to 2603. Workaround: Run the remediation script documented on the Known Issues page to update affected assets to API version2026-04-01. Known Issues- ✅ Fixed in this release: Data flow graph definitions could not be reused across multiple data flow instances (previously tracked as a known issue).
- ✅ Fixed in earlier release: Akri webhook certificate expiry error during Azure IoT Operations instance updates or deletions.
Components Overview
This release spans improvements to Observability (unified health reporting), Data flows (GA no-code data flow graphs, cloud-to-edge management actions), Messaging (broker reliability and graceful shutdown), Akri (connector lifecycle), Connectors (MQTT connector now GA; health modeling across OPC UA, Media, ONVIF, REST/HTTP, SSE, MQTT), CLI (management actions, bulk import/export), and Platform (infrastructure-as-code alignment).
Observability
New features
-
Unified health status reporting: Added unified health status reporting for core Azure IoT Operations and Azure Device Registry resources, enabling operators to quickly understand system and asset health without relying solely on logs or metrics. Deploy observability resources
-
Multi-surface visibility: Health status is now surfaced on both Kubernetes custom resources and Azure Resource Manager (ARM) resources for supported components.
Improvements
-
Standardized health states: Improved operational visibility by standardizing health states across the platform.
-
Expanded resource coverage: Health status is now reported for the following resources:
- Broker
- Data flows
- Data flow graphs
- Assets
- Device inbound endpoints
-
Consistent state model: Each resource reports one of the following health states:
- Available — functioning as expected
- Degraded — partially functional with one or more issues
- Unavailable — not operational and requires attention
- Unknown — health status cannot be determined
-
Higher-level signal: Health reporting complements existing OpenTelemetry-based metrics and logs by providing a higher-level operational signal rather than raw telemetry alone.
Fixes
-
Reduced false positives: Improved the accuracy and consistency of health signals by using aggregated evaluations over a defined time window, reducing false positives caused by transient conditions.
-
Upgrade reliability: Fixed an issue where health status was not populated correctly for some resources after upgrading to 2603, which could result in operators seeing stale or missing health data until the next refresh cycle.
Known issues
⚠️ Newly tracked: Assets created using older API versions may not report health status after upgrading to 2603. Workaround: Recreate or update the affected asset using the current API version (2026-04-01). Known Issues
Data flows
New features
- No-code data flow graphs (GA): Introduced visual, no-code data flow graphs with built-in transforms that enable data processing directly in the Azure IoT Operations experience—without writing custom WebAssembly transforms. Use WebAssembly (WASM) with data flow graphs
- Map: Applies transformation rules to each record, including renaming fields, computing values, setting defaults, removing fields, and enriching from contextual data sources. Supports wildcard field matching.
- Filter and Branch: Evaluate conditions against message schemas to include, exclude, or route records to different outputs.
- Window: Aggregates records over time-based windows using built-in functions (including
$last). - Concatenate: Merges outputs from multiple transforms into a single stream.
- Cloud-to-edge management actions (GA): Send commands from the cloud to on-premises assets using Azure Resource Manager and Event Grid MQTT messaging (mRPC pattern). Supports OPC UA, ONVIF, and MQTT connectors with built-in RBAC access control, managed identity authentication to Event Grid, and activity logs for auditing and monitoring.
Improvements
- Health modeling for data flows: Data flow operators, runtime instances, and individual transform stages now report structured health status (Available / Degraded / Unavailable) with specific reason codes for scenarios such as WebAssembly module download failures, module panics, and missing schema references.
- Kafka target reliability: Improved reliability for Kafka targets by adding message batching and periodic metadata refresh to keep connections alive. Also fixed handling for multi-topic Kafka subscriptions.
- Enhanced observability: Added data plane metrics for data flow graphs (per-stage and per-graph) and improved logging at source MQTT clients.
- Improved validation: Duplicate output field rules in transforms are now detected, input reference checking is more robust, and invalid enrich input expressions are blocked in the Window operator.
...
2602 Update
AIO2602 (v1.2.189) Public Stable Release Notes
Summary & Updates
Azure IoT Operations 2602 release includes reliability, security, and operational improvements across observability, dataflows, and messaging components.
Version Reference & Upgrade Guidance
Current GA version: 1.2.189 (2602)
Upgrade to 2602 from any supported GA version to ensure you receive the latest security patches and feature enhancements. Staying current is recommended for continued support and reliability. Detailed version legend is available at: IoT Operations versions · Azure/azure-iot-ops-cli-extension Wiki
Highlights
- Improved Kafka dataflow reliability and subscription support.
- Enhanced observability configuration for external OpenTelemetry collectors.
- Reduced excessive logging under certain operational conditions.
- Included security updates across core components and dependencies.
Observability
- Fixed a broken path where the configured OpenTelemetry collector endpoints were not propagated into AIO.
Dataflows
- Added support for subscribing to multiple Kafka topics within a single dataflow.
- Improved Kafka client behavior to prevent idle connections from being dropped by the Azure Load Balancer.
- Reduced excessive log output generated by Dataflows during reconciliation.
Messaging and MQTT
- Improved broker behavior during upgrade scenarios to avoid transient connectivity checks being surfaced as failures.
Device Registry
- Renamed
defaultEventsDestinationstodefaultDestinationsineventGroups. - Updated MQTT Broker and Akri to use latest Device Registry version.
Security
- Addressed security vulnerabilities across Azure IoT Operations components, including operators and MQTT connectors.
- Updated base images and dependencies to resolve OpenSSL and Glibc vulnerabilities.
Platform Updates
- Integrated the latest supported version of Cert Manager Extension (CME) and Secret Store Extension (SSE).
2512 Update
Azure IoT Operations – Release 2512
Summary & Updates
The 2512 release includes bug fixes, performance improvements and security updates.
Akri
General
- RegistryEndpointRef: Now supports RegistryEndpointRef when referencing the connector image inside the ConnectorTemplate.
Known Issues
- Expired Webhook Certificates: Users may encounter an error regarding expired webhook certificates with Akri when deleting/upgrading instances of Azure IoT Operations as well as performing CRUD on Akri resources such as Connector instances and ConnectorTemplates. To fix this, please run
kubectl delete pod -n azure-iot-operations aio-akri-webhook-0 --ignore-not-foundto delete and restart the webhook pods which will allow the pod to pick up the new certificate.
2510 Update
Azure IoT Operations – Release 2510
Summary & Updates
The 2510 release introduces several enhancements focused on simplifying deployment and improving edge-to-cloud observability. Key updates include:
-
Secret Management: Integrated Secret Picker with Azure Key Vault for secure, in-portal secret selection.
-
Telemetry Connectors: New connectors stream HTTP events and OpenTelemetry (OTEL) telemetry to MQTT/state stores and Azure Monitor.
-
Modular Dataflows: Dataflow graphs and import/export capabilities streamline edge automation and configuration.
-
CLI Improvements: Deprecated extensions removed, new asset migration command added, and Python 3.13 proxy compatibility patched.
-
Connector Templates: Create reusable templates to standardize connector configuration and deployment across clusters.
-
ADR Namespaces: Enable logical isolation and security boundaries for managing assets and devices at scale.
-
Devices: Added support for devices with inbound endpoints and cross-connector capabilities.
-
New Connectors:
-
ONVIF Connector – Integrate ONVIF-compliant cameras and devices for video and surveillance scenarios.
-
Media Connector – Ingest and process media streams with greater flexibility.
-
REST Connector – Connect to RESTful endpoints for seamless integration with external systems.
-
Enrich Connector – Enhance incoming data with contextual metadata for analytics.
-
-
Device & Asset Discovery: Automatic detection and onboarding of devices and assets to reduce manual configuration.
OPC UA Connector
⚠️ Breaking Changes
-
Removed PublishingInterval: Removed from datapoints and events to prevent misconfiguration; still configurable for datasets and event groups.
-
Human-Friendly Asset Names:
-
Asset name renamed to
.- -
Dataset name:
telemetry; topic:..data. .telemetry -
Event group name:
events; topic:..data. .events -
Datapoint name:
.. -
DeviceHealthAlarm renamed from
toDeviceHealthAlarm.
-
-
JSON Schema Update:
$idis now defined only at the root level using the HTTP schema format. -
Schema Referencing: OPC UA types now referenced via partial JSON pointers.
✨ New Features
-
Event Groups: Events are now organized within event groups, allowing dedicated destinations per group.
-
Dataset Write Schema Generation: Automatically generates JSON schemas (draft7) for dataset write operations.
-
OPC UA Write Support: Enables writing simple and complex datapoints within datasets using MQTT RPC API.
-
Address Space Browsing: Added support for browsing OPC UA server address spaces via MQTT RPC API.
-
Advanced Event Filtering: Supports selective event filtering on the OPC UA server to optimize processing and cost.
🐞 Bug Fixes
-
Fixed dataset write action for datapoints using Node IDs instead of Expanded Node IDs.
-
Removed incorrect
const: 0values from OPC UA JSON schemas. -
Improved reliability in asset change detection and updates.
Media Connector
⚠️ Breaking Changes
-
Lifecycle is now managed by Akri, not the AIO Connectors supervisor.
-
Removed support for
AssetEndpointProfileandAsset CR Datasets; configuration now via Namespaced Device/Asset CRs. -
Media operations now defined in the Streams section of an Asset CR (migrated from Datasets).
✨ New Features
-
Downstream Authentication: Supports authentication for downstream media servers in RTSP tasks.
-
TLS Encryption: Now available for both media endpoints and downstream connections.
ONVIF Connector
⚠️ Breaking Changes
-
Lifecycle now managed by the Akri Operator.
-
Removed support for
AssetEndpointProfileand legacy dataset configurations; uses Namespaced Device/Asset CRs. -
Endpoint discovery redesigned to create inbound endpoints within
DiscoveredDeviceCRs.
✨ New Features
-
Media Metadata Exposure: Publishes resolution and framerate attributes for discovered media endpoints.
-
Management Group Support: Now supports management groups.
-
TLS Encryption: Added for ONVIF device connections.
REST/HTTP Connector
✨ New Features
-
Summary: Enables integration with external REST/HTTP endpoints for MQTT or state store publishing.
-
Configurable Sampling: Sample data from REST endpoints at custom intervals.
-
Flexible Routing: Send data to multiple destinations for analytics and observability.
-
Authentication Options: Supports username/password, x.509 certificates, certificate bundles, and anonymous access.
SSE Connector
✨ New Features
-
Summary: Introduces support for real-time ingestion from HTTP(S) SSE streams.
-
Key Capabilities:
-
Samples SSE events and forwards them to MQTT/state stores.
-
Automatically registers schemas in Schema and Device Registries.
-
Integrates with OpenTelemetry for observability.
-
Includes retry logic on sampling failures.
-
Supports multiple authentication methods (username/password, x.509, trust bundles, anonymous).
-
MQTT Broker
✨ New Features
-
Data Persistence: Data is now durable across broker restarts with configurable persistence.
-
Azure Device Registry Integration: Supports x.509 authentication via the Device Registry.
🐞 Bug Fixes
-
Fixed broker crash when trusted client CA cert was missing.
-
Corrected batching logic for large (8KiB+) publish messages.
Dataflows
✨ New Features
-
WebAssembly Support: Enables embedded WASM modules for custom logic.
-
OpenTelemetry Endpoint Integration: Direct integration with Azure Monitor or OTEL collectors.
-
Dynamic Destination Topics: Use variables (e.g.,
${inputTopic}) for flexible routing.
🐞 Bug Fixes
- Improved retry logic for control plane operations to enhance reliability.
Akri
✨ New Features
-
Revamped Akri Services: Re-architected core for managing connectors and discovery.
-
Connector Lifecycle Management: Akri now manages both first- and third-party connectors.
-
Device & Asset Discovery: Enhanced backend for ONVIF/media devices.
-
Portal Integration: Configure Akri directly in Azure Portal.
-
Secure Registry Access: Provides secure API for connector access to Device and Asset data.
🛠️ Known Issues
-
Connector Templates: Only supports image-based deployment; Helm and StatefulSet options coming soon.
-
Secret Sync Conflicts: Secret names must be globally unique to avoid connector failures.
-
Webhook issue: Users may encounter an error regarding expired webhook certificates with Akri when deleting/upgrading instances of Azure IoT Operations as well as performing CRUD on Akri resources such as Connector instances and ConnectorTemplates. To fix this, please run kubectl delete pod -n azure-iot-operations aio-akri-webhook-0 --ignore-not-foundto delete and restart the webhook pods which will allow the pod to pick up the new certificate.
AIO Observability
✨ New Features
- Inline Observability Configuration: Add observability during upgrades using the
--ops-configparameter.
ADR & Schema Registry
✨ New Features
-
Namespace Enforcement: All AIO instances now tied to namespaces for isolation.
-
Namespace Device Resource: Replaces endpoint profiles; maintains backward compatibility.
-
Namespace Asset Actions: Define writeable management actions (e.g., setpoints).
-
Streams & Events Enhancements: Multi-dataset, multi-event support for richer modeling.
-
Destinations & QoS: Route to broker/state store with QoS per destination.
-
Schema Registry Identity: Enables workload identity federation for edge scalability.
Azure Portal
✨ New Features
-
Secret Picker Integration: Secure Azure Key Vault secret selection.
-
Server-Sent Events Connector: Real-time HTTP event streaming to MQTT/state stores.
-
Namespaces in ADR:
-
Create, view, and manage namespaces.
-
Dedicated management blade and asset visibility improvements.
-
-
Connector Templates:
-
Guided template creation wizard.
-
Centralized management view.
-
-
MQTT Persistence Configuration:
- Configure broker persistence from the portal.
Azure IoT Operations Experience
✨ New Features
-
OTEL Connector: Streams telemetry to Azure Monitor.
-
Modular Dataflows: Create real-time, low-latency edge workflows.
-
Import/Export: Simplify asset migration and replication.
-
**Expan...