🗂️ The Tenant Desk

Friday, August 7, 2026

12 stories · Standard format

Generated with AI from public sources. Verify before relying on for decisions.

🎧 Listen to this briefing or subscribe as a podcast →

We're looking at a wave of forced migrations and deprecations hitting Microsoft 365 and Entra ID this fall, requiring administrators to overhaul how they handle identity and access. Alongside those hard deadlines, we are tracking an escalation in Phishing-as-a-Service attacks built specifically to subvert modern authentication.

Microsoft 365 & SharePoint

Microsoft to Retire 'MemberOf' Rule for Entra ID Dynamic Groups, Affecting Access and Licensing

Microsoft has announced it is ending the preview of the 'MemberOf' rule operator for dynamic groups in Entra ID. After November 3, 2026, any dynamic groups, administrative units, or entitlement management access packages using this rule will stop updating. A related change on October 27, 2026, will quarantine automatic assignment policies in Entitlement Management that use 'memberOf'.

This is a critical deprecation forcing immediate action from administrators. Organizations relying on the 'MemberOf' operator for dynamic group management, app assignments, licensing, or Conditional Access policies must migrate to alternative methods, like filtering on user attributes or using automated scripts, to avoid stale permissions, compliance gaps, and significant disruption to user access.

Verified across 2 sources: LazyAdmin.nl · Daily Entra News

Microsoft Begins Phasing Out Exchange Web Services Starting October 1

Microsoft is formally beginning the deprecation of Exchange Web Services (EWS) for Exchange Online. A gradual shutdown will start on October 1, 2026, with full deactivation scheduled for April 1, 2027. To manage the transition, companies must migrate applications that rely on EWS to the Microsoft Graph API and can use an 'EWSAllowedAppIDs' allowlist for specific applications.

This is a significant architectural shift that impacts any organization with custom applications, scripts, or third-party tools that integrate with Exchange Online. For consultants, this is a major migration project that requires auditing all tenant integrations, rewriting code to use the Graph API, and careful planning to avoid disruption to critical business functions like calendar sync, automated mail processing, and mobile client features.

Verified across 1 sources: IT BOLTWISE

Microsoft Simplifies Copilot Service Plan Controls, Deprecates 'Personal Content Mode'

Microsoft is remapping its Microsoft 365 Copilot service plans to simplify administration. Starting in late August 2026, the 'Microsoft Copilot with Graph-grounded chat' plan will become the primary toggle for all Copilot experiences. As part of this change, the little-used 'Personal Content Mode' will be deprecated.

This change requires administrators to review and potentially adjust their service plan assignments to ensure licensed users retain the intended level of access. While the goal is to streamline Copilot management, the deprecation of a specific mode and the re-mapping of controls necessitate proactive validation to prevent unexpected changes to user experience and functionality.

Verified across 1 sources: MWPro

Copilot & Power Platform

Biopharma Firm Implements GenAI Governance Framework for Microsoft Copilot

Clarkston Consulting detailed its work with a biopharmaceutical company to establish a formal generative AI governance framework for the safe adoption of Microsoft Copilot. The framework includes an acceptable use policy, a risk matrix for use cases, requirements for human-in-the-loop validation, and an incident escalation plan.

This is a valuable case study for any consultant helping clients in regulated industries deploy Copilot. It provides a practical, real-world example of the specific policies and controls required—moving beyond generic advice to a concrete template for risk management, employee training, and strategic use case prioritization that is necessary for compliance.

Verified across 1 sources: Clarkston Consulting

Enterprise AI

Microsoft Details 'Agent 365' Platform for Internal AI Agent Governance

As a practical answer to the enterprise 'agent sprawl' and governance gap we've been tracking, Microsoft has revealed an internal platform called 'Agent 365' to manage its own population of over 500,000 AI agents. The system provides a centralized inventory, integrates with security tools, governs the agent lifecycle, and generates risk signals.

This provides a practical blueprint for how a large, sophisticated enterprise is tackling the real-world problem of 'agent sprawl' and AI governance. As Microsoft's internal solution, Agent 365 offers a credible model for other companies, and its potential release to external customers would make it a key product for consultants to manage client AI deployments, security, and compliance at scale.

Verified across 1 sources: Microsoft Inside Track

Report: Enterprises Widely Deploying AI but Struggle to Measure ROI

A survey by Plug and Play of Fortune 500 and Forbes Global 2000 companies found that while 74% have at least one AI solution in production, half of them cannot consistently measure its return on investment. The primary barriers to scaling AI and demonstrating value were identified as poor data foundations (71%), governance friction (53%), and legacy system integration (26%).

This data highlights the maturity gap in enterprise AI: deployment is happening, but value realization is not. The focus is now shifting from simply getting models into production to building the underlying data architecture, governance, and measurement capabilities needed to prove business impact. For consultants, this means the opportunity is less about AI evangelism and more about the foundational work of data practice and integration.

Verified across 2 sources: efficientlyconnected.com · Yahoo Finance

Politics, Fact-Checked

Senate Committee Votes to Hold Dr. Fauci in Contempt of Congress

On Thursday, the Senate Homeland Security and Governmental Affairs Committee voted along party lines to hold Dr. Anthony Fauci in contempt of Congress. The move came after Fauci invoked his Fifth Amendment right against self-incrimination during a hearing last week regarding the government's COVID-19 response. Committee Chairman Rand Paul stated the vote was for refusal to answer, while Fauci cited concerns of being trapped into a perjury charge.

This action represents a significant escalation in the political conflict surrounding the COVID-19 response. It raises fundamental constitutional questions about the balance between congressional oversight powers and the rights of witnesses, particularly in a highly polarized environment. The Department of Justice will now have to decide whether to pursue a prosecution.

Verified across 3 sources: NPR · AP News · NBC News

Cybersecurity

'Greatness' and 'Kali365' Phishing Services Bypass Microsoft 365 MFA Using Device Code Flow

Adding to the 'Greatness' Phishing-as-a-Service threat we tracked recently, a second platform named 'Kali365' is now driving widespread campaigns against Microsoft 365 users. Both exploit the OAuth 2.0 device code authentication flow, tricking users into entering a code on the real Microsoft login page to grant attackers persistent session tokens without stealing passwords.

The commercialization of these advanced phishing kits significantly lowers the barrier for sophisticated attacks that subvert modern authentication. For consultants, this reinforces the need to advise clients to implement stricter Conditional Access policies that restrict or block device code flow, enhance user training to recognize these lures, and deploy phishing-resistant MFA methods to defend M365 tenants.

Verified across 4 sources: Rescana · Xcitium ThreatLabs News · Hackernoon · CyberPress

Vishing Campaign Targets Financial Firms to Steal Microsoft 365 and Okta Sessions

An extortion crew known as UNC6671 (formerly associated with BlackFile) has launched a sophisticated voice phishing (vishing) campaign targeting private equity firms, law firms, and financial services companies. Attackers impersonate IT help desks to trick employees into providing credentials or enrolling FIDO2 passkeys on adversary-in-the-middle (AiTM) proxies, allowing the attackers to steal live session tokens for Microsoft 365 and Okta tenants.

This campaign demonstrates that even strong authentication methods like FIDO2 are vulnerable to sophisticated social engineering. For consultants, it's a stark reminder that technical controls must be paired with robust procedural safeguards and continuous user education. The key is not just preventing credential theft, but also detecting anomalous post-authentication activity, such as bulk file access from unusual scripting agents.

Verified across 2 sources: SiliconANGLE · Google Threat Intelligence Blog

New England Beat

Massachusetts to Receive Hydropower from Québec as Contested NECEC Line Goes Live

This Friday, Massachusetts is scheduled to begin receiving 1,200 megawatts of hydropower from Québec through the New England Clean Energy Connect (NECEC) transmission line. The $1 billion project, which has faced significant legal and political opposition in Maine over its environmental impact, is a cornerstone of Massachusetts' strategy to meet its clean energy goals.

The activation of the NECEC line marks a major, albeit controversial, milestone in New England's energy transition. It promises to provide a substantial and stable source of clean energy, potentially lowering costs and reducing carbon emissions for Massachusetts ratepayers. However, the project's difficult history highlights the complex trade-offs between regional energy needs and local environmental concerns.

Verified across 1 sources: Jandetrick.com

Science & Space

Wearable Ultrasound Patch Improves REM Sleep Without Drugs, Study Finds

Researchers at the University of Texas at Austin have developed a soft, wearable patch called NEUSLeeP that uses gentle ultrasound stimulation to enhance REM sleep. A study of 28 participants showed the device significantly shortened the time it took to enter REM sleep and extended its duration, without drugs or surgery.

This non-invasive technology could offer a new approach for treating sleep disorders and mental health conditions linked to disrupted REM sleep, such as PTSD and depression. By offering a way to directly modulate a specific sleep stage, it opens the door to more personalized and targeted therapies for improving sleep quality and cognitive health.

Verified across 1 sources: ScienceDaily

Consumer Tech Quirks

WebKit Vulnerability Exposes Real IP Address in Safari, Even with Private Relay

Security researchers have identified several features in WebKit, the browser engine for Safari and all iOS browsers, that can leak a user's real IP address, bypassing Apple's iCloud Private Relay. The leaks can occur through DNS prefetching, WebAuthn requests (used with passkeys), and WebTransport connections. Apple has reportedly confirmed it is investigating.

This bug undermines a core privacy feature that users rely on for anonymity. For technically-aware users, it's a reminder that platform-level privacy protections are not infallible and can have unexpected holes, especially when interacting with other modern web technologies like passkeys. It highlights the constant tension between performance-enhancing features and robust privacy.

Verified across 7 sources: NCSA Webboard · X · mysk.blog · The Hacker News · Malwarebytes · TechPulse · Tweakers.net


The Big Picture

Microsoft 365 and Entra ID face a season of critical deprecations. Multiple deadlines are looming for administrators, including the retirement of the 'MemberOf' rule in Entra ID dynamic groups, the end of Exchange Web Services, and changes to Copilot service plan controls, requiring proactive migration and policy updates.

Phishing-as-a-Service platforms now systematically bypass MFA. Threat actors are widely using commercialized PhaaS toolkits like 'Greatness' and 'Kali365' that exploit device code flows and OAuth consent to steal session tokens from Microsoft 365 users, rendering traditional MFA methods insufficient.

AI governance moves from theory to practical implementation. Enterprises are implementing concrete governance frameworks for AI agents. Microsoft's internal 'Agent 365' platform and a case study from a biopharma company show a focus on risk management, human-in-the-loop validation, and centralized inventories.

The debate on AI agent adoption is over; the focus is on guardrails. Surveys show a vast majority of enterprises are already using or willing to use autonomous AI agents in production. The primary barrier is no longer feasibility but establishing security, compliance, and architectural guardrails to ensure trustworthy operation.

Massachusetts' energy landscape is being reshaped by large-scale clean energy projects. The state is beginning to receive hydropower from Québec via the long-contested NECEC transmission line, a major step in its clean energy transition. Simultaneously, local leaders are championing fare-free public transit as a parallel strategy for reducing emissions and costs.

What to Expect

2026-08-11 Mountainlands Community Housing Trust unveils resident-built affordable homes in Heber, Utah.
2026-08-12 A partial solar eclipse and the Perseid meteor shower will be visible over Massachusetts.
2026-09-01 Microsoft makes passkeys the default authentication method for Entra ID users currently enabled for SMS or voice.
2026-10-01 Microsoft begins gradual shutdown of Exchange Web Services (EWS).
2026-11-03 Entra ID dynamic groups using the 'MemberOf' rule will stop updating.

— The Tenant Desk

🎙 Listen as a podcast

Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.

Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste
Overcast
+ button → Add URL → paste
Pocket Casts
Search bar → paste URL
Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
Look for Add by URL or paste into search

Spotify isn’t supported yet — it only lists shows from its own directory. Let us know if you need it there.