🗂️ The Tenant Desk

Wednesday, August 12, 2026

12 stories · Standard format

Generated with AI from public sources. Verify before relying on for decisions.

🎧 Listen to this briefing or subscribe as a podcast →

August's Patch Tuesday highlights severe authentication bypass risks across SharePoint environments, sharing the day's focus with federal courts drawing firm lines on executive authority.

Microsoft 365 & SharePoint

Rapid7 Discloses Critical SharePoint Authentication Bypass CVE-2026-55040

Security researchers at Rapid7 and Microsoft on Tuesday disclosed CVE-2026-55040, a critical JWT token validation bypass in SharePoint Server Subscription Edition that allows remote unauthenticated attackers to forge identity tokens and assume arbitrary user privileges.

The vulnerability is especially hazardous because researchers used AI assistance to chain it with an RCE flaw (CVE-2026-63520). With SharePoint 2016 and 2019 reaching end-of-support in July, on-premises farms must be updated immediately to prevent full farm compromise.

Verified across 7 sources: Stefan Gossner's Blog · The Hacker News · Rapid7 · Stefan Gossner's Blog · CrowdStrike · BleepingComputer · CloudFuze

Sherweb Details Microsoft Partner Incentive Shifts Toward Premium AI SKUs for FY27

Cloud distributor Sherweb published guidance on Tuesday detailing Microsoft's partner updates, confirming reduced CSP margins on legacy standalone products starting October 2026 alongside increased incentives for Copilot and security SKUs.

Consultants and CSP partners must adjust client licensing models. Margin cuts on legacy standalone subscriptions mean client renewals must be aligned with bundled M365 Business Premium or E5 offerings to maintain margin viability.

Verified across 2 sources: Sherweb · Microsoft Learn

Microsoft Purview Expands Daily Auto-Labeling Capacity to 500,000 Files Per Tenant

Microsoft announced on Tuesday that Purview Information Protection will increase its daily auto-labeling limit across SharePoint Online and OneDrive from 100,000 to 500,000 files per tenant, with rollout scheduled between September and October 2026.

Fivefold higher auto-labeling throughput helps large tenants clear data classification backlogs faster, ensuring sensitivity labels and access controls are applied before enabling Microsoft 365 Copilot broadly.

Verified across 1 sources: Pupuweb

Enterprise AI

Anthropic Makes Claude Code Auto Mode Default, Shifting Governance to Session Boundaries

Anthropic updated Claude Code on Monday, making 'Auto Mode' the default for Pro, Max, and Team users. The interface replaces step-by-step confirmation prompts with an automated classifier that intervenes only when destructive commands are detected.

This shift addresses approval fatigue in agentic coding workflows. Security controls for AI developers are moving away from interactive, prompt-by-prompt prompts toward hard sandbox constraints defined before execution starts.

Verified across 1 sources: WorkAI

Agent2Agent Protocol Hits v1.0 Under Linux Foundation to Standardize Cross-Vendor Workflows

The Agent2Agent (A2A) protocol reached version 1.0 on Tuesday under Linux Foundation governance, introducing cryptographically signed 'Agent Cards' to enable autonomous discovery and delegation across distinct AI frameworks.

While tools like Model Context Protocol (MCP) manage local data access, A2A establishes a standard communication layer for multi-agent execution across different SaaS platforms and organizational trust boundaries.

Verified across 1 sources: You.com

VentureBeat Survey Highlights Context Failures in Enterprise RAG Systems

A survey of 101 enterprise tech leaders released Wednesday by VentureBeat found that 68% experience recurring hallucination errors in AI agents caused by missing business context rather than base model defects.

The findings underscore that enterprise AI failures stem primarily from poor semantic layer integration and outdated document permissions rather than raw model capabilities, making structured Dataverse and SharePoint metadata essential.

Verified across 1 sources: VentureBeat

Politics, Fact-Checked

Federal Judge Enjoins Executive Order Restricting Postal Service Mail-In Voting Controls

A federal district judge on Tuesday blocked key provisions of President Trump's executive order that sought to establish a federal voter database and mandate specific operational limits on how the U.S. Postal Service handles mail-in ballots.

The injunction reasserts state authority over election administration under Article I of the Constitution, preventing unilateral federal administrative changes to mail ballot processing ahead of upcoming elections.

Verified across 1 sources: The Washington Post

Plaintiffs File Federal Court Challenge Against Revised Birthright Citizenship Executive Order

Civil rights attorneys returned to federal court on Tuesday to request an immediate injunction against the administration's August 6 executive order attempting to restrict 14th Amendment birthright citizenship for children of undocumented residents.

This filing challenges the scope of executive authority against established Fourteenth Amendment jurisprudence, setting up a fast-tracked appellate review regarding constitutional citizenship guarantees.

Verified across 1 sources: SCOTUSblog

Cybersecurity

Microsoft Sets September Timeline for Automatic Passkey Migration Ahead of 2027 Telephony Cutoff

Microsoft announced on Tuesday that starting September 1, 2026, Entra ID will begin automatically prompting users who rely on SMS or voice-based MFA to register passkeys ahead of the complete retirement of telecom delivery on February 1, 2027.

Administrators must map out user onboarding paths now. Leaving fallback mechanisms on SMS will lead to access disruptions next year, making FIDO2/passkey policy enforcement an immediate operational requirement.

Verified across 1 sources: Technovice

August 2026 Patch Tuesday Fixes 400 Flaws, Including Exploited Windows Zero-Day

Microsoft's August 2026 Patch Tuesday updates address 400 vulnerabilities, headlined by an actively exploited local privilege escalation zero-day in the Windows AFD.sys driver (CVE-2026-68820) attributed to North Korean threat actors.

Kernel-mode driver vulnerabilities are primary targets for post-exploitation persistence. Enterprise security teams need to prioritize patching endpoint OS builds alongside SharePoint servers to close active attack vectors.

Verified across 2 sources: BleepingComputer · CrowdStrike

New England Beat

Boston Subsidized Housing Production Hits Record Highs as Federal Funds Expire

City data released Monday shows Boston created over 6,200 income-restricted housing units during Mayor Wu's first term, financed largely through $560 million in pandemic ARPA grants that will expire by year-end.

With federal relief funds sunsetting and high interest rates slowing private construction, Boston faces a steep drop in affordable housing starts unless new municipal or state revenue mechanisms are established.

Verified across 1 sources: Connect CRE

Science & Space

Samsung Galaxy Buds Cleared by FDA as Over-the-Counter Hearing Aids

Samsung received FDA 510(k) clearance on Tuesday for its Galaxy Buds 3 Pro and 4 Pro to act as over-the-counter hearing aids, utilizing an integrated five-minute diagnostic test and the NAL-NL2 fitting algorithm.

The clearance brings clinical-grade hearing augmentation directly into mainstream consumer hardware, lowering financial and social barriers for individuals with mild-to-moderate hearing loss.

Verified across 1 sources: Tech Times


The Big Picture

On-Premises SharePoint Security Deadlines Expose Unpatched Farms August Patch Tuesday vulnerabilities, including AI-assisted exploit chains and active deserialization flaws, highlight severe risks for legacy on-premises SharePoint environments following July's end-of-support deadlines.

Hard Identity Transitions Eliminate Telephony MFA Reliance Microsoft's enforced September transition to passkeys and the hard February 2027 telecom deprecation force enterprise tenant admins to overhaul access controls immediately.

Agentic Governance Shifts to Pre-Execution Boundaries From Anthropic's Claude Code defaults to protocol standards like A2A, enterprise AI security is moving away from per-prompt manual approvals toward structured pre-session sandboxing.

Judicial Oversight Restrains Federal Executive Mandates Federal court rulings against postal voting restrictions and birthright citizenship orders signal swift judicial challenges to recent white house policy changes.

Regional Housing Supply Gaps Threaten Workforce Retention Rising municipal development costs and expiring pandemic-era subsidies in hubs like Boston and New York are accelerating local housing affordability challenges.

What to Expect

2026-08-20 Boston Public Improvements Commission votes on Bennington Street traffic-calming proposal.
2026-09-01 Microsoft begins automatically enabling passkeys for Entra ID users relying on SMS/voice MFA.
2026-10-01 Microsoft legacy CSP margin reductions take effect; EWS deprecation begins in Exchange Online.
2026-11-03 Entra ID officially ends preview support for 'MemberOf' dynamic group rules.
2027-02-01 Microsoft retires native SMS and voice MFA delivery across all Entra ID tenants.

Every story, researched.

Every story verified across multiple sources before publication.

🔍

Scanned

Across multiple search engines and news databases

359
📖

Read in full

Every article opened, read, and evaluated

76

Published today

Ranked by importance and verified across sources

12

— The Tenant Desk

🎙 Listen as a podcast

Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.

Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste
Overcast
+ button → Add URL → paste
Pocket Casts
Search bar → paste URL
Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
Look for Add by URL or paste into search

Spotify isn’t supported yet — it only lists shows from its own directory. Let us know if you need it there.