We're looking at a wave of forced migrations and deprecations hitting Microsoft 365 and Entra ID this fall, requiring administrators to overhaul how they handle identity and access. Alongside those hard deadlines, we are tracking an escalation in Phishing-as-a-Service attacks built specifically to subvert modern authentication.
Microsoft has announced it is ending the preview of the 'MemberOf' rule operator for dynamic groups in Entra ID. After November 3, 2026, any dynamic groups, administrative units, or entitlement management access packages using this rule will stop updating. A related change on October 27, 2026, will quarantine automatic assignment policies in Entitlement Management that use 'memberOf'.
Why it matters
This is a critical deprecation forcing immediate action from administrators. Organizations relying on the 'MemberOf' operator for dynamic group management, app assignments, licensing, or Conditional Access policies must migrate to alternative methods, like filtering on user attributes or using automated scripts, to avoid stale permissions, compliance gaps, and significant disruption to user access.
Microsoft is formally beginning the deprecation of Exchange Web Services (EWS) for Exchange Online. A gradual shutdown will start on October 1, 2026, with full deactivation scheduled for April 1, 2027. To manage the transition, companies must migrate applications that rely on EWS to the Microsoft Graph API and can use an 'EWSAllowedAppIDs' allowlist for specific applications.
Why it matters
This is a significant architectural shift that impacts any organization with custom applications, scripts, or third-party tools that integrate with Exchange Online. For consultants, this is a major migration project that requires auditing all tenant integrations, rewriting code to use the Graph API, and careful planning to avoid disruption to critical business functions like calendar sync, automated mail processing, and mobile client features.
Microsoft is remapping its Microsoft 365 Copilot service plans to simplify administration. Starting in late August 2026, the 'Microsoft Copilot with Graph-grounded chat' plan will become the primary toggle for all Copilot experiences. As part of this change, the little-used 'Personal Content Mode' will be deprecated.
Why it matters
This change requires administrators to review and potentially adjust their service plan assignments to ensure licensed users retain the intended level of access. While the goal is to streamline Copilot management, the deprecation of a specific mode and the re-mapping of controls necessitate proactive validation to prevent unexpected changes to user experience and functionality.
Clarkston Consulting detailed its work with a biopharmaceutical company to establish a formal generative AI governance framework for the safe adoption of Microsoft Copilot. The framework includes an acceptable use policy, a risk matrix for use cases, requirements for human-in-the-loop validation, and an incident escalation plan.
Why it matters
This is a valuable case study for any consultant helping clients in regulated industries deploy Copilot. It provides a practical, real-world example of the specific policies and controls required—moving beyond generic advice to a concrete template for risk management, employee training, and strategic use case prioritization that is necessary for compliance.
As a practical answer to the enterprise 'agent sprawl' and governance gap we've been tracking, Microsoft has revealed an internal platform called 'Agent 365' to manage its own population of over 500,000 AI agents. The system provides a centralized inventory, integrates with security tools, governs the agent lifecycle, and generates risk signals.
Why it matters
This provides a practical blueprint for how a large, sophisticated enterprise is tackling the real-world problem of 'agent sprawl' and AI governance. As Microsoft's internal solution, Agent 365 offers a credible model for other companies, and its potential release to external customers would make it a key product for consultants to manage client AI deployments, security, and compliance at scale.
A survey by Plug and Play of Fortune 500 and Forbes Global 2000 companies found that while 74% have at least one AI solution in production, half of them cannot consistently measure its return on investment. The primary barriers to scaling AI and demonstrating value were identified as poor data foundations (71%), governance friction (53%), and legacy system integration (26%).
Why it matters
This data highlights the maturity gap in enterprise AI: deployment is happening, but value realization is not. The focus is now shifting from simply getting models into production to building the underlying data architecture, governance, and measurement capabilities needed to prove business impact. For consultants, this means the opportunity is less about AI evangelism and more about the foundational work of data practice and integration.
On Thursday, the Senate Homeland Security and Governmental Affairs Committee voted along party lines to hold Dr. Anthony Fauci in contempt of Congress. The move came after Fauci invoked his Fifth Amendment right against self-incrimination during a hearing last week regarding the government's COVID-19 response. Committee Chairman Rand Paul stated the vote was for refusal to answer, while Fauci cited concerns of being trapped into a perjury charge.
Why it matters
This action represents a significant escalation in the political conflict surrounding the COVID-19 response. It raises fundamental constitutional questions about the balance between congressional oversight powers and the rights of witnesses, particularly in a highly polarized environment. The Department of Justice will now have to decide whether to pursue a prosecution.
Adding to the 'Greatness' Phishing-as-a-Service threat we tracked recently, a second platform named 'Kali365' is now driving widespread campaigns against Microsoft 365 users. Both exploit the OAuth 2.0 device code authentication flow, tricking users into entering a code on the real Microsoft login page to grant attackers persistent session tokens without stealing passwords.
Why it matters
The commercialization of these advanced phishing kits significantly lowers the barrier for sophisticated attacks that subvert modern authentication. For consultants, this reinforces the need to advise clients to implement stricter Conditional Access policies that restrict or block device code flow, enhance user training to recognize these lures, and deploy phishing-resistant MFA methods to defend M365 tenants.
An extortion crew known as UNC6671 (formerly associated with BlackFile) has launched a sophisticated voice phishing (vishing) campaign targeting private equity firms, law firms, and financial services companies. Attackers impersonate IT help desks to trick employees into providing credentials or enrolling FIDO2 passkeys on adversary-in-the-middle (AiTM) proxies, allowing the attackers to steal live session tokens for Microsoft 365 and Okta tenants.
Why it matters
This campaign demonstrates that even strong authentication methods like FIDO2 are vulnerable to sophisticated social engineering. For consultants, it's a stark reminder that technical controls must be paired with robust procedural safeguards and continuous user education. The key is not just preventing credential theft, but also detecting anomalous post-authentication activity, such as bulk file access from unusual scripting agents.
This Friday, Massachusetts is scheduled to begin receiving 1,200 megawatts of hydropower from Québec through the New England Clean Energy Connect (NECEC) transmission line. The $1 billion project, which has faced significant legal and political opposition in Maine over its environmental impact, is a cornerstone of Massachusetts' strategy to meet its clean energy goals.
Why it matters
The activation of the NECEC line marks a major, albeit controversial, milestone in New England's energy transition. It promises to provide a substantial and stable source of clean energy, potentially lowering costs and reducing carbon emissions for Massachusetts ratepayers. However, the project's difficult history highlights the complex trade-offs between regional energy needs and local environmental concerns.
Researchers at the University of Texas at Austin have developed a soft, wearable patch called NEUSLeeP that uses gentle ultrasound stimulation to enhance REM sleep. A study of 28 participants showed the device significantly shortened the time it took to enter REM sleep and extended its duration, without drugs or surgery.
Why it matters
This non-invasive technology could offer a new approach for treating sleep disorders and mental health conditions linked to disrupted REM sleep, such as PTSD and depression. By offering a way to directly modulate a specific sleep stage, it opens the door to more personalized and targeted therapies for improving sleep quality and cognitive health.
Security researchers have identified several features in WebKit, the browser engine for Safari and all iOS browsers, that can leak a user's real IP address, bypassing Apple's iCloud Private Relay. The leaks can occur through DNS prefetching, WebAuthn requests (used with passkeys), and WebTransport connections. Apple has reportedly confirmed it is investigating.
Why it matters
This bug undermines a core privacy feature that users rely on for anonymity. For technically-aware users, it's a reminder that platform-level privacy protections are not infallible and can have unexpected holes, especially when interacting with other modern web technologies like passkeys. It highlights the constant tension between performance-enhancing features and robust privacy.
Microsoft 365 and Entra ID face a season of critical deprecations. Multiple deadlines are looming for administrators, including the retirement of the 'MemberOf' rule in Entra ID dynamic groups, the end of Exchange Web Services, and changes to Copilot service plan controls, requiring proactive migration and policy updates.
Phishing-as-a-Service platforms now systematically bypass MFA. Threat actors are widely using commercialized PhaaS toolkits like 'Greatness' and 'Kali365' that exploit device code flows and OAuth consent to steal session tokens from Microsoft 365 users, rendering traditional MFA methods insufficient.
AI governance moves from theory to practical implementation. Enterprises are implementing concrete governance frameworks for AI agents. Microsoft's internal 'Agent 365' platform and a case study from a biopharma company show a focus on risk management, human-in-the-loop validation, and centralized inventories.
The debate on AI agent adoption is over; the focus is on guardrails. Surveys show a vast majority of enterprises are already using or willing to use autonomous AI agents in production. The primary barrier is no longer feasibility but establishing security, compliance, and architectural guardrails to ensure trustworthy operation.
Massachusetts' energy landscape is being reshaped by large-scale clean energy projects. The state is beginning to receive hydropower from Québec via the long-contested NECEC transmission line, a major step in its clean energy transition. Simultaneously, local leaders are championing fare-free public transit as a parallel strategy for reducing emissions and costs.
What to Expect
2026-08-11—Mountainlands Community Housing Trust unveils resident-built affordable homes in Heber, Utah.
2026-08-12—A partial solar eclipse and the Perseid meteor shower will be visible over Massachusetts.
2026-09-01—Microsoft makes passkeys the default authentication method for Entra ID users currently enabled for SMS or voice.
2026-10-01—Microsoft begins gradual shutdown of Exchange Web Services (EWS).
2026-11-03—Entra ID dynamic groups using the 'MemberOf' rule will stop updating.
— The Tenant Desk
🎙 Listen as a podcast
Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.
Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste