Enterprise identity policies are moving aggressively toward mandatory passkey adoption, pairing with new granular consumption controls designed to rein in unmanaged AI spend across cloud environments.
Microsoft updated the Microsoft 365 admin center reporting suite on Monday, reducing Copilot usage data refresh lag to 48 hours and altering the default metrics window to 28 days. Autonomous agent usage metrics have been split into a separate report, while Microsoft Graph API endpoints were updated with new v2 parameters.
Why it matters
Custom PowerShell and Graph reporting scripts built to track M365 Copilot adoption will fail or return incomplete data if not updated to the v2 endpoint schemas. Separating agent usage metrics from standard chat prompts also requires consultants to update client governance dashboards to measure digital worker activity accurately.
Microsoft Purview rolled out new retention policies and adaptive labels on Sunday that trigger based on a file's last-accessed date across OneDrive and SharePoint Online. The feature allows automated archiving or deletion of stagnant content to prevent outdated files from clogging tenant search indexes.
Why it matters
Irrelevant, stale documentation severely degrades Copilot response accuracy and introduces legal risk. Leveraging last-accessed retention policies gives admins a deterministic, automated mechanism to clean up legacy data repositories before grounding generative AI models on them.
Microsoft began rolling out AI citations analytics in SharePoint Online on Monday for tenants holding at least 50 Copilot licenses. The feature gives site owners and content creators direct insights into how frequently their specific documents, news items, and site pages are cited in user Copilot queries.
Why it matters
This metric moves content optimization from guesswork to telemetry. Knowledge managers can now identify high-value operational documentation that grounds organizational decision-making, as well as outdated pages that need editing or removal to refine Copilot output.
Following yesterday's outline of the Copilot Credits billing model for autonomous agents, Microsoft detailed the corresponding administrative controls. Entering public preview on August 22, Power Platform admins will be able to monitor credit consumption down to individual user and agent levels, set per-user capacity limits, and enforce Pay-As-You-Go (PAYG) hard spending caps across environments.
Why it matters
Uncapped agent consumption has been a primary concern for client CFOs evaluating Power Platform deployments. Implementing these preview caps allows consultants to construct predictable cost-containment frameworks, assuring clients that expanding low-code agent creation won't generate surprise credit overage bills.
Alongside the general availability of Copilot Studio we covered yesterday, Microsoft deployed a major architectural overhaul to its underlying runtime engine. The new orchestration layer cuts evaluation times by roughly 20% and lowers token usage by ~50%, rolling out alongside real-time voice, Work IQ APIs, and general availability for web and desktop computer use.
Why it matters
Lowering token costs by half and speeding up multi-step execution changes the architectural feasibility of complex business process automation. Enterprise architects can now shift multi-step workflows into native Copilot Studio agents without relying as heavily on custom Azure OpenAI wrapper code.
An analysis published Tuesday examining Microsoft's updated case study on State Farm highlights the gap between total maker activity and production deployments. While the insurer successfully deployed 41 production builds across HR and underwriting using Copilot Studio, the widely cited figure of 3,000+ agent identities reflects development sandbox pipelines rather than autonomous operational workloads.
Why it matters
When advising executive leadership on low-code AI scaling, consultants must distinguish between total environment object counts and governed, production-grade deployments. Ungoverned developer pipelines swell identity counts rapidly, emphasizing the need for strict ALM policies to separate experimental prototypes from production business agents.
Microsoft has formalized the February 2027 telecom MFA phase-out we tracked over the weekend, adding a critical workaround for enterprise routing. While Microsoft-provided SMS and voice delivery will end as scheduled, tenants will be permitted to maintain telecom fallback by configuring custom customer-managed telecom gateways, offering a lifeline for those unable to complete passkey adoption before automated enrollment prompts begin on September 1.
Why it matters
This sets an unyielding operational deadline for your client roadmaps. To prevent widespread end-user lockout when telecom fallback vanishes, consultants must immediately design passwordless onboarding flows, establish hardware key provisioning for non-mobile workers, and implement Entra Verified ID Face Check for self-service account recovery.
Adding to the Windows Hello cryptographic key extraction vulnerability we tracked over the weekend, SpecterOps researchers disclosed another local WebAuthn risk: 'Pass-the-Passkey.' Attacker processes can capture and replay WebAuthn assertions without breaking underlying cryptography, exploiting a Windows event logging flaw (CVE-2026-34348) that improperly saved full cryptographic assertions alongside missing server-side counter checks during Entra ID validation.
Why it matters
This research demonstrates that implementing passkeys does not insulate an enterprise from endpoint compromise. Security teams must ensure CVE-2026-34348 OS patches are applied immediately to prevent attackers with local unprivileged access from extracting valid WebAuthn tokens directly from system logs.
As we've tracked the rise of AiTM toolkits like 'Kali365' bypassing Microsoft 365 MFA, new intelligence details the post-compromise playbook for these attacks. Threat group Storm-2755 is using compromised AiTM sessions to execute low-noise Microsoft Graph API queries via residential proxy networks, systematically searching payroll, executive HR, and financial mailboxes without raising standard perimeter alerts.
Why it matters
AiTM bypasses non-phishing-resistant MFA, and automated Graph API reconnaissance is difficult to detect using basic mailbox auditing. Security teams must implement conditional access location controls, restrict user consent for Graph API calls, and audit OAuth application permissions to catch post-compromise API activity.
Trump Media & Technology Group reported a $238 million net loss for Q2 on Monday, primarily driven by paper valuation drops on its cryptocurrency portfolio. SEC filings show the company is scrapping plans to expand into online sports gambling and digital asset services, shifting focus back to Truth Social and promoting paid financial API subscriptions.
Why it matters
The pivot underscores the financial fragility of media platforms dependent on digital asset holdings. Offering direct financial market API access to prominent platform accounts also creates ongoing ethics scrutinies and potential regulatory conflicts of interest for executive branch ethics monitors.
Tesla issued a service notification on Tuesday extending the warranty on the Power Conversion System (PCS) for early-production Cybertrucks to 8 years or 150,000 miles. The extension follows mounting owner reports of high-voltage charging failures and costly out-of-warranty replacement quotes.
Why it matters
Early adopters of 800V EV architectures face unique component reliability risks. Broadening factory warranty coverage on core power electronics helps protect resale valuations and mitigates financial exposure for high-mileage commercial or fleet owners.
Researchers at NYU Langone Health published preliminary findings Monday on a modified cochlear implant that simultaneously stimulates the vagus nerve. By tapping into the locus coeruleus to induce neuroplasticity, the device aims to help the adult brain decode electrical auditory signals significantly faster.
Why it matters
Traditional cochlear implants often require months or years of intensive auditory retraining for adult patients with long-term hearing loss. Coupling electrical stimulation with targeted neuroplasticity conditioning could dramatically shorten rehabilitation timelines and improve speech comprehension outcomes.
Passkey Mandates Force Hard Identity Deadlines Microsoft's decision to automate passkey enrollment and set a February 2027 deadline for telecom MFA deprecation is forcing identity architects to redesign tenant bootstrap policies immediately.
Granular Controls Target Shadow AI Consumption From Power Platform PAYG caps to Copilot usage Graph APIs, tenant governance is shifting from passive observation to active rate-limiting and unit-level attribution.
Operational Rigor Replaces Enterprise AI Hype Case studies and architectural updates show enterprise focus turning toward prompt-injection defenses, deterministic agent limits, and content pruning to fix retrieval accuracy.
What to Expect
2026-08-12—Total solar eclipse crosses Greenland, Iceland, and northern Spain alongside Perseid peak.
2026-08-22—Power Platform granular Copilot credit tracking and PAYG consumption caps enter public preview.
2026-09-01—Microsoft Entra ID begins automatic passkey enablement rollout for telecom-reliant users.
2026-10-01—Windows Hello for Business and macOS PSSO become standalone MFA factors in Entra ID.
2027-02-01—Microsoft-provided SMS and voice MFA in Entra ID fully retired.
How We Built This Briefing
Every story, researched.
Every story verified across multiple sources before publication.
🔍
Scanned
Across multiple search engines and news databases
356
📖
Read in full
Every article opened, read, and evaluated
89
⭐
Published today
Ranked by importance and verified across sources
12
— The Tenant Desk
🎙 Listen as a podcast
Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.
Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste