Vault Prospector 0.2.0-preview.1
0.2.0-preview.1 was the first Windows x64 non-production evaluation release in the 0.2 series. It superseded 0.1.1-preview.1 and brought the completed readiness-integration work into one immutable Preview. See the repository README for the current Preview.
Highlights
- Advanced managed-identity, certificate, and workload-federation profiles with credential and token-cache isolation from developer tools and interactive accounts.
- Read-only workload authorization evidence and deterministic provisioning previews without Azure identity, RBAC, or Key Vault mutation.
- Local encrypted-data recovery, all-or-rollback key rotation, explicit purge controls, and expanded fail-closed corruption and tamper handling.
- Preview CyberArk Privilege Cloud metadata discovery and explicit verified retrieval with separately protected provider credentials.
- Preview browser-fill/native-host safeguards with explicit origin/field mappings and one-time desktop confirmation.
- Machine-managed enterprise policy with packaged ADMX/ADML templates.
- Native iOS/Android prototypes and fail-closed credential/autofill boundaries validated in CI; mobile binaries are not included in this Windows release.
- Integrated performance, legal/privacy, operational-readiness, packaging, and policy gates.
Verification
ADO CI build 284 passed from exact source commit c7c8cb3191e392901f1dc0c8271ab62a0947e758, including 370 Windows/shared tests, 44 managed mobile tests, native iOS application and credential-provider extension builds, Android Release App Bundle packaging, full-history secret scanning, dependency inspection, and Windows package gates.
ADO release build 287 created the release packages, checksums, SPDX SBOM, and Key Vault-backed Cosign bundles. All four package hashes and bundles were verified before publication. A credential-free download check then matched every one of the 13 public assets to the retained ADO artifact.
The exact public MSI passed all 27 installer-lifecycle gates on isolated Windows 11 Enterprise Evaluation 25H2: upgrade from 0.1.1-preview.1, deliberate post-InstallFiles failure rollback, successful upgrade, repair, downgrade rejection, uninstall cleanup, and retained local state.
Package hashes
| Package | SHA-256 |
|---|---|
| MSI | DC15AF609EE6D55933551D24339DB914060E9616D40604D2AD9F10E7625EA4F2 |
| Portable ZIP | 0C4017FC532704E5D3B86339A202C2A31E00D166972546216B5539A82F8F66F8 |
| Chocolatey NUPKG | D2C1A22C3CA13083B1C68D06D36D816326BC9505F90DD4BA9975499D61D584F9 |
| WinGet manifest archive | 00EF9ED0DA0E56C9FB8FF43F9529A10FEDC13F335CC2899805520D41418F1DA2 |
| SPDX SBOM | 4211191E9CB0FE67D380F3358EDE333AA470E1C62AB3DEDB81B8030AD68DFA80 |
Install and upgrade
- Download
VaultProspector-0.2.0-preview.1-win-x64.msi, its.sha256, and its.sigstore.jsonfrom the public release page. - Verify the SHA-256 and Cosign bundle as described in the release verification guide.
- Run the MSI and approve the administrator prompt.
- Windows displays Unknown Publisher because this Preview is intentionally unsigned.
The MSI ProductVersion is 0.2.1, with a new ProductCode and the stable Vault Prospector UpgradeCode. It upgrades 0.1.1-preview.1 (0.1.101). Uninstall retains %LOCALAPPDATA%\VaultProspector; delete that directory only when all local state should be removed.
Distribution status
- Direct public MSI and ZIP downloads are available.
- WinGet submission
microsoft/winget-pkgs#407541is open; catalog acceptance remains external and pending. - Two authenticated Chocolatey submissions returned HTTP 504. The package is not in the Chocolatey catalog, so
choco installavailability is not claimed.
Known Preview limitations
- Use non-production resources. Live Azure/CyberArk matrices and independent security review are incomplete.
- Trusted Authenticode signing remains required for stable/GA.
- Browser integrations are validation-preview features and are not browser-store approved.
- iOS and Android are source/CI prototypes only; no mobile app is distributed by this release.
- Representative physical-device, accessibility, usability, legal/privacy approval, operational exercises, and stability windows remain open as listed in the readiness matrix.
- Project-controlled telemetry is disabled. Do not include credentials, tokens, secret values, or sensitive identifiers in feedback.
See the user guide, Preview scope, release evidence, and release-readiness matrix.