Hey everyone, and welcome back to The Modern .NET Show; the premier .NET podcast, focusing entirely on the knowledge, tools, and frameworks that all .NET developers should have in their toolbox. I'm your host Jamie Taylor, bringing you conversations with the brightest minds in the .NET ecosystem.
Today's episode is another one without a guest; it's just me again. This is part two of the series I started at the top of the season, Bridging the Gap, and if you're wondering where part two got to, we had a standard episode in between. That'll keep happening. The series numbers and the season numbers are going to drift apart, and I'll say which part we're on every time so nobody has to do arithmetic..
Anyway, without further ado, let's sit back, open up a terminal, type in `dotnet new podcast` and we'll dive into the core of Modern .NET.
The full show notes, including links to some of the things we discussed and a full transcription of this episode, can be found at: https://dotnetcore.show/season-9/you-might-not-need-to-upgrade-the-case-for-staying-put/
Remember to rate and review the show on Apple Podcasts, Podchaser, or wherever you find your podcasts, this will help the show's audience grow. Or you can just share the show with a friend.
And don't forget to reach out via our Contact page. We're very interested in your opinion of the show, so please get in touch.
You can support the show by making a monthly donation on the show's Patreon page at: https://www.patreon.com/TheDotNetCorePodcast.
Music created by Mono Memory Music, licensed to RJJ Software for use in The Modern .NET Show.
Editing and post-production services for this episode were provided by MB Podcast Services.
This week, we discuss Google Docs finally getting Markdown, Cloudflare's CF CLI, Gartner's agentic AI abandonment stat, and forward deployed engineers. Plus, Coté forgets his laptop.
Watch the YouTube Live Recording of Episode 593
Runner-up Titles:
If you manage Azure resources from a Mac today, az login opens a browser tab, you sign in, and a token comes back to the CLI. That's worked well for a long time. As security requirements become more stringent, many enterprise organizations are adopting secure authentication brokers to strengthen identity protection and reduce authentication-related risks.
Many organizations require broker-based authentication as a matter of security policy. A broker is the operating system's own credential broker — on Windows this is the Web Account Manager (WAM), and it's what lets az login reuse your existing signed-in Windows account instead of opening a browser every time. Depending on the broker, device configuration, and policies applied by the organization, broker-based authentication can provide:
Azure CLI has supported broker authentication on Windows for a while. Beginning with Azure CLI 2.91.0, organizations with stringent security requirements can also use broker-based authentication with Azure CLI on macOS.
Beginning with Azure CLI 2.91.0, broker-based authentication is available in preview on macOS. The feature uses MSAL's native macOS broker support and is disabled by default, so you remain in control of when to enable it.
After you opt in and run az login, Azure CLI opens a native macOS account picker instead of starting the sign-in flow in a browser. You can select an account already known to the broker or add another account. If a compatible broker isn't available, Azure CLI falls back to the existing browser-based sign-in flow.
The core MSAL library is open source, but the macOS broker runtime is not. It is subject to strict internal compliance and intellectual property protection requirements and must also satisfy Apple-specific requirements such as notarization.
Azure CLI is now available through Homebrew Cask, a supported installation method that can accommodate these requirements and support broker-based authentication on macOS. The familiar package name continues to work for new installations:
brew update
brew install azure-cli
You can also select the Cask explicitly:
brew update
brew install --cask azure-cli
We tested the migration on a Mac that had Azure CLI 2.90.0 installed through the former Homebrew Formula. After brew update, Homebrew detected that azure-cli had moved to homebrew/cask, unlinked the existing Formula, downloaded Azure CLI 2.91.0 or later, and linked the az executable and shell completions from the Cask. The final output confirmed:
azure-cli was successfully installed!
azure-cli has been moved to homebrew/cask.
The existing keg has been unlinked.
Homebrew detects the package migration, installs Azure CLI from Cask, and preserves the az command.
Homebrew also recommended removing the old Formula record when convenient:
brew uninstall --formula --force azure-cli
This means scripts that use brew install azure-cli can continue to use the same package name. If you previously used the Azure CLI preview tap and Homebrew still resolves stale Formula metadata, remove that tap and retry:
brew untap azure/azure-cli
brew update
brew install azure-cli
az config set core.enable_broker_on_mac=true
az account clear
You can confirm the setting with:
az config get core.enable_broker_on_mac
3. Start a new sign-in:
az login
4. Azure CLI opens the native single sign-on account picker. Select an existing account and choose Continue or use the add-account button to sign in with another account.
After broker authentication is enabled, az login opens the native account picker instead of starting in a browser.
5. Run az account show to confirm that you're signed in with the expected account and tenant.
The broker changes how Azure CLI acquires credentials; it doesn't change Azure CLI's subscription or tenant selection model. If your account belongs to multiple tenants, you might still need to select the intended tenant explicitly:
az login --tenant <tenant-id>
To opt out and return to browser-based authentication:
az account clear
az config set core.enable_broker_on_mac=false
az login
If a compatible broker isn't installed or available, Azure CLI automatically falls back to browser-based authentication.
This is one part of a broader push to bring Azure CLI's macOS experience up to parity with Windows and Linux — including packaging improvements (to keep pace with Apple's tightening notarization requirements). If you run Azure CLI on macOS in an enterprise environment, we'd love to hear from you — file feedback or ask questions at Azure/azure-cli on GitHub.
I’ve spent this week at next.app devCon in Berlin, which has been a reminder of why conferences are worth the trip. The talks are good. The hallway, the expo floor and the dinners afterwards are better. And one talk, on Monday, put words to something I’ve watched happen for most of my career.
Janina Kutyn’s talk was called “Driving User Engagement”, and it was a gambit. What she actually gave us was a reflection on how much of people’s lives now happens around a phone they didn’t mean to pick up, and on how small changes to a journey can give someone a sense of being done instead of a reason to stay.
It usually goes like this. A team wants to know whether the app is useful. Usefulness is hard to count, so someone picks a proxy, usually sessions or minutes. The proxy goes on a dashboard. Two reorganisations later nobody remembers it was a proxy, and the roadmap is full of features whose only job is to move it. Nobody decided to build something that keeps people stuck. It settled there, one sensible quarter at a time.
None of that makes the people involved villains. Product managers are asked to show growth, and minutes are what the analytics tools hand you by default.
For most of what we build, time in app is the wrong number. Games and reading apps are the honest exception, because there the minutes are the product. Everywhere else, the fix isn’t a lecture. It’s a better number. Count finished tasks, and how quickly someone gets from opening the app to the thing they opened it for. Apple is already handing families better tools to see and limit screen time. Once people can see the minutes, the minutes stop being a compliment.
I asked Janina after the talk whether there was anything written to share with you. Not yet, so watch this space. In the meantime, if your dashboard can’t tell the difference between someone who loves your app and someone who can’t put it down, change the dashboard.
See you next week.
– Juan Marin
Faster macOS builds with better hardware, unlimited concurrency, no queueing delays, and no commitments. Get started in 5 minutes with code iosdev2026 to try it with $50 in free credits.
Apple’s notice on Full Disk Access reads like a response to a story rather than to a bug. It promises tighter controls for an “extraordinary level of access”, points at AI agents, and stops there: no API, no timeline. Jeff Johnson thinks he knows what prompted it. He recorded Meta Muse’s first run and found nothing that grants the permission behind your back. The app can only open the Settings pane, and going further takes an admin password, which, he argues, makes the viral account of Muse reading someone’s messages unasked look like a forgotten setup screen.
His worry is the right one for us. Permissions tightened in response to a headline land on the developers who were using them properly, and nobody wants macOS to turn into the Vista parody Apple once used to sell Macs.
Certificate expiries are the dullest kind of news and the most expensive to miss. The original Developer ID intermediate runs out on 1 February 2027, and the line Apple has drawn is worth understanding. Notarised apps with a secure timestamp are fine, because the timestamp proves they were signed while the certificate was valid. Installer packages get no such grace: a .pkg signed with an affected certificate simply stops installing.
That asymmetry is the reason to act now if you ship a .pkg, plug-ins and enterprise tools especially. Generate the replacement from the G2 authority, choose G2 Sub-CA when asked, and remember that Apple says the new certificates still expire every year.
Most of Apple’s new-hardware announcements are invitations. This one comes with a deadline. Duo-optimised builds can go in now with Xcode 27.1, the phone ships on 23 October, and from April 2027 any app or game submitted needs iPhone Duo screenshots.
That’s Apple turning adoption into policy, and I think it’s a fair move. A new device stands or falls on whether the store looks right on it, and, as the platform citizens piece in Articles explains, big apps have every reason to wait. Screenshots are a modest ask, unless you localise into twenty languages. They also mean that by spring someone on every team will have opened their app on the inner screen and looked properly.
Maciej Szamowski profiled his Mac calendar with 100,000 events and found the main thread busy updating SwiftUI’s graph (about 577 ms of one 762 ms hang) while the database contributed half a millisecond. The hover effect he removed is the detail people will remember. The wider point is how much work quietly hangs off small interaction details in a dense view.
He’s also frank about the tools. Instruments only became usable for this in Xcode 27, and recordings over about 50 seconds could churn for an hour and then crash on his M5.
Jeroen Leenarts starts from the assumption that the model won’t be there. His note editor has to work on a phone without Apple Intelligence, or while the model is still downloading, and the suggested tag and title are an optional layer on top.
That framing changes the code in small, sensible ways. A @Generable struct whose @Guide steers the tag towards a fixed list (with a check in code in case it strays), a half-window token guard, every error returning nil because the user’s words are already on screen, and an Evaluations test with a 0.8 bar on twenty notes he tagged himself. The line to pin up comes near the end: “Build the screen that works with the model turned off.”
Every sponsor and attendee I could find this week whose product is built on top of the simulator, the UI testing and automation tools so many of us depend on, got the same question: what did Device Hub do to you? I watched a few smiles switch off before anyone answered, and nobody had to tell me how many late nights their summer had cost them. What came back was a pattern. Compromises, shorter feature lists and, more than once and a little quieter, “we’re thinking about whether to keep the product at all”.
What’s left is a game of cat and mouse. Developers are rebuilding the shape their muscle memory knew for a decade. Samuel Abada’s OpenDeviceHub puts back a window per device and the old shortcuts, and Vadim Katenin’s SimParcel restores drag and drop. For headless runs, tddworks’ Baguette covers what idb lost when its input call stopped working in iOS 26. Apple is putting pieces back as well, and Xcode 27.2 beta 2 already fixes modifier keys and input on simulators older than iOS 18. But OpenDeviceHub and Baguette both load private frameworks from Xcode, so the next release can undo them too, and a documented layer under the simulator is the only way the chase ends.
Scott Berrevoets explains why the apps with the biggest teams are often the last to adopt anything new, and it isn’t a lack of skill. LinkedIn took two years to ship dark mode. Big companies plan quarterly or twice a year, well before Apple rolls out its updates, and a platform feature has to show it moves a company goal without hurting another metric. Most can’t, because people who can’t book a ride through Siri just open the app.
I hope you never have to argue for something your users plainly want against a spreadsheet that can’t see it. His closing point is the one I’d keep: at larger companies, craft tends to come from individual engineers doing it as a passion project.
This is the deep dive of the week, so give it an unhurried hour. Most of us learnt SwiftUI modifier order by trying both and keeping whichever looked right. For offset, rotationEffect and scaleEffect, Mihaela Mihaljević Jakić replaces that habit with a rule: the modifier closest to the view applies first. It’s the Core Graphics law read from the other end, which is why .offset then .rotationEffect orbits in SwiftUI while “translate, rotate” spins in place in Core Graphics.
She ends with four rules you can use without the maths. Put .offset after a scale if you want the distance in the parent’s points, and remember that a .frame before a rotation moves the pivot. Keep it bookmarked for the next animation that ends up somewhere you didn’t expect.
Swift’s Float.pi has been a hair too small, on purpose, since the very beginning, and this week Stephen Canon’s proposal to round it properly was accepted. It opens with Indiana’s 1897 attempt to set pi by law, and somehow, 129 years later, nobody thought to hold out for Pi Day. 🥧