🗂️ The Tenant Desk

Thursday, September 10, 2026

12 stories · Standard format

Generated with AI from public sources. Verify before relying on for decisions.

🎧 Listen to this briefing or subscribe as a podcast →

State-level veto power over digital infrastructure takes center stage in New England today, alongside an escalation in browser-resident attacks and cloud data extortion targeting Microsoft tenants.

Microsoft 365 & SharePoint

Microsoft Expands Graph API to Archive Mailboxes as Exchange Online Restricts EWS Access

Advancing the Exchange Web Services (EWS) retirement milestones we've been tracking, Microsoft updated documentation confirming that starting October 1, 2026, Exchange Online will enforce the EWSAllowedAppIDs control, automatically generating allowed application lists based on 60 days of prior telemetry. Tenants with EWSEnabled set to Null will see that property automatically switch to False on October 1, blocking unmanaged EWS traffic ahead of the April 2027 final retirement. Simultaneously, Microsoft issued MC1469565 announcing native Microsoft Graph API support for archive mailboxes, arriving by November to replace legacy EWS workflows.

This dual milestone marks the point where legacy EWS access transitions from a soft deprecation notice to active tenant enforcement. Misconfigured EWSEnabled default settings or reliance on auto-generated EWSAllowedAppIDs lists risk silently severing eDiscovery, third-party backup, and compliance archiving workflows that target archive mailboxes. Consultants managing life-sciences or regulated tenants must audit custom scripts and vendor integrations immediately to migrate calls to Microsoft Graph before October's automated enforcement phase begins.

Verified across 4 sources: Microsoft Tech Community · Handsontek M365 Admin · MWPro · MWPro

Microsoft Whiteboard Sets Firm Cutoff Date for Legacy Azure Storage Migration

Microsoft issued updated retirement guidance on Thursday, September 10, 2026, confirming that migration tooling for moving legacy Azure-backed whiteboards to OneDrive-backed storage will be officially retired on September 25, 2026. Following this cutoff, any remaining Azure-based whiteboards will convert to read-only status and can only be exported until October 16, 2026, after which they will be permanently deleted. The underlying legacy Azure Whiteboard infrastructure will fully shut down on November 30, 2026.

Administrators who have not yet executed tenant-wide whiteboard migrations face irreversible data loss once the September 25 tooling retirement date passes. Because manual recovery is unsupported after mid-October, IT teams must immediately run the WhiteboardAdmin PowerShell module to audit legacy storage repositories. Ensuring all user whiteboards are transitioned to OneDrive is essential for preserving historical project collaboration data.

Verified across 1 sources: MWPro

Copilot & Power Platform

Cisco Scales MyAgent AI Assistant Across 90,000 Employees Using Multi-Tier Model Routing

Cisco announced details regarding its internal MyAgent deployment, an AI assistant powered by its Circuit platform now available to all 90,000 employees. The architecture orchestrates over 800 domain-specific subagents executing multi-step tasks across Outlook, Webex, Jira, and SharePoint with persistent memory. To control operational token costs, Cisco implemented a three-tier routing model: 50% to 60% of user requests are routed to open-weight models, 20% to 30% are handled by deterministic software automation, and only complex tasks are escalated to expensive commercial frontier LLMs.

Cisco's deployment provides an enterprise blueprint for managing runaway token costs in large-scale AI implementations. Defaulting every employee prompt to a top-tier frontier model creates unsustainable operational overhead for large enterprises. By using deterministic automation and open-weight models as the primary tier, organizations can deliver broad ambient AI functionality while preserving budget for complex agentic workflows.

Verified across 1 sources: WithO2

Copilot Studio Agent Builder Update Modularizes Agent Roles and Granular Skill Sets

Building on the reusable YAML skill definitions introduced to Copilot Studio earlier this week, an Agent Builder update released Wednesday restructures the Microsoft 365 Copilot authoring flow to strictly separate agent identities ('who') from granular task skills ('how'). The interface introduces a live 'Try it' testing toggle, expanded knowledge sources including OneNote endpoints, and a direct 'Copy to Copilot Studio' path for transitioning low-code prototypes into full developer environments.

For Power Platform architects and M365 consultants, this update formalizes a modular design pattern that separates top-level agent roles from discrete execution skills. This separation prevents makers from building monolithic, hard-to-maintain topic flows by encouraging reusable skill modules across multiple enterprise agents. The direct export path to Copilot Studio streamlines how consulting teams promote user-built prototypes into governance-tested production environments.

Verified across 1 sources: HubSite 365

Enterprise AI

Meta Outlines Four-Layer 'Organizational Second Brain' Agent Architecture for Compliance Logic

Meta published technical details on Wednesday, September 9, 2026, describing an AI agent architecture termed an 'organizational second brain', engineered to capture expert compliance logic without embedding business rules directly into LLM weights. The system utilizes a four-layer design comprising a version-controlled knowledge base of 200+ structured files, a reasoning pipeline executing composable 'recipes', an evaluation framework, and an automated regression test loop. Meta reports the design reduced compliance assessment lead times from days to minutes while preventing model drift.

This architectural pattern addresses a major hurdle in enterprise AI adoption: preserving regulatory and audit logic outside opaque model parameters. By storing business rules in version-controlled text files and enforcing compliance via deterministic evaluation recipes, organizations maintain complete visibility and control over decision-making. Consultants can adapt this pattern for clients in highly regulated industries like life sciences to build inspectable AI workflows.

Verified across 1 sources: InfoQ

Working-Class Economy

Chicago Opens First 'LaSalle Street Reimagined' Office-to-Residential Conversion

Developers officially opened The Bellwether at 79 W. Monroe St. on Wednesday, September 9, 2026, marking the first completed project under Chicago's 'LaSalle Street Reimagined' adaptive reuse initiative. Supported by $28 million in Tax Increment Financing (TIF) toward a $64 million total conversion, the historic 7-story Rector Building was transformed into 117 apartments, including 41 units strictly reserved as affordable housing. The broader municipal program aims to deliver over 1,700 residential units across six historic commercial high-rises in the central financial district.

This completion provides a real-world test case for urban adaptive reuse, demonstrating how public TIF subsidies can convert vacant commercial office space into mixed-income housing. For municipal leaders and urban policy analysts, the project measures whether targeted tax incentives can successfully revitalize single-use business districts into residential neighborhoods while expanding affordable housing inventory near public transit.

Verified across 1 sources: Block Club Chicago

Cybersecurity

Browser-Resident Blob URL Phishing Weaponizes Microsoft Cloud Routing to Evade Gateways

Security researchers at Barracuda detailed an active phishing campaign on Wednesday, September 9, 2026, that bypasses email security gateways by constructing malicious login forms entirely within local browser memory using temporary blob URLs. The attack vectors route targets through legitimate Microsoft infrastructure—including Microsoft OAuth endpoints and Teams invitation links—before registering local background service workers and sandboxed iframes. Because the payload renders dynamically on the client side using local memory structures rather than connecting to a hosted malicious domain, traditional web-reputation blocklists fail to detect or block the landing page.

By relying on client-side memory rendering and trusted Microsoft cloud paths, this attack vector renders traditional URL-based perimeter filtering and gateway inspection obsolete. For identity and security consultants, this campaign underscores the urgency of pivoting client defenses toward behavioral runtime protections and phishing-resistant FIDO2 passkeys. Relying on network-level URL blocklists leaves M365 tenants exposed to stealthy credential harvesting that leverages trusted Microsoft domains.

Verified across 3 sources: Barracuda · SecurityBrief Australia · Cyber Security Intelligence

Microsoft Threat Analysts Detail Storm Clusters Targeting M365 via Passkey Vishing and Graph API Theft

Adding to the wave of passkey-themed vishing and AiTM campaigns we've tracked from groups like 'Pink' and PREY-0058, Microsoft threat intelligence reports that clusters Storm-3121 and Storm-3032 are now actively manipulating passkey enrollment workflows. Once initial access is granted via voice phishing, the actors deploy custom Node.js tools and residential proxies to query Microsoft Graph APIs below standard rate thresholds, stealthily extracting bulk assets from SharePoint and Exchange Online without deploying traditional endpoint malware.

This campaign illustrates that transitioning to multi-factor authentication is insufficient if administrative enrollment workflows remain vulnerable to voice-phishing social engineering. By utilizing legitimate Graph API calls for exfiltration, attackers bypass EDR agents and network perimeters entirely. Security teams must enforce strict conditional access policies, restrict unmanaged device code flows, and establish audit rules that alert on anomalous bulk Graph API data requests.

Verified across 2 sources: Security Online · RH-ISAC

EVs & Charging

US Fast-Charging Power Expands 47% as Non-Tesla Networks Accelerate NACS Deployments

Federal Alternative Fuels Data Center statistics updated through September 1, 2026, show the United States public DC fast-charging network reached over 76,000 total ports, with total available charging power increasing 47% year-over-year from 14.1 GW to 20.7 GW. Non-Tesla charging networks installed over 2,700 NACS connectors in the first eight months of 2026, outpacing Tesla's own deployment of 2,300 Supercharger ports during the same period. Over the same timeframe, CCS1 ports grew by roughly 6,000, while legacy CHAdeMO ports declined by 450 to 8,426.

The deployment data confirms that non-Tesla infrastructure operators are now leading the physical rollout of NACS connectors, accelerating the industry's transition toward a single North American plug standard. As third-party networks expand NACS capacity, EV drivers gain broader access to reliable fast-charging options outside the Supercharger ecosystem. Tracking these hardware ratios helps fleet operators and individual EV owners plan long-distance transit routes without relying exclusively on adapter hardware.

Verified across 4 sources: EV Charging Stations · HERE · HERE Technologies · EV Engineering Online

Tesla Opens Massachusetts Turnpike and I-95 Superchargers to All EV Brands

Tesla has expanded Magic Dock non-Tesla access to its Supercharger stations along the Massachusetts Turnpike (I-90) and Interstate 95, opening stalls at service plazas in Charlton, Lexington, and Newton on Wednesday, September 9, 2026. The expansion helps mitigate a public charging deficit created after MassDOT's $750 million service plaza redevelopment contract with Applegreen stalled, alongside delays in state deployment of federal National Electric Vehicle Infrastructure (NEVI) funds. Massachusetts currently remains approximately 2,000 public fast-charging ports short of its near-term EV adoption targets.

The opening of key highway Supercharger locations provides immediate fast-charging relief along heavily traveled Massachusetts transit corridors where state-funded plaza overhauls have stalled. For New England EV drivers and fleet operators, this move addresses critical coverage gaps on I-90 and I-95. It highlights how private charging concessions continue to bridge infrastructure shortfalls caused by public procurement and federal fund distribution delays.

Verified across 1 sources: Hoodline

New England Beat

Massachusetts Executive Order Subjects 25MW+ Data Centers to Local Veto and Clean Energy Mandates

Yesterday we covered Governor Maura Healey's move to grant local municipalities a veto over 25MW data center projects; today, the full text of Executive Order No. 658 reveals additional mandates. The order bans non-disclosure agreements between developers and public entities, requires facilities to meet 100% of their electricity demand through self-supplied clean energy, and establishes a Ratepayer Protection Fund for alternative compliance payments if clean generation targets fall short.

This executive order establishes a precedent in regional power grid governance by giving host municipalities absolute veto power over high-density computing developments. For consultants advising clients on data center site selection or AI infrastructure expansion in New England, technical viability now hinges on local political negotiation and direct clean-energy procurement rather than standard utility interconnect filings. The policy effectively halts speculative computing facility builds that rely on regional ratepayer-subsidized energy capacity.

Verified across 6 sources: news-usa.today · TechCrunch · iTech Post · Daniel Walters Blog · Daily Hampshire Gazette · Bisnow

Consumer Tech Quirks

Google Shortens Chrome Major Release Cadence to Two Weeks Amid AI Defect Discovery

Following the emergency Chrome V8 patch we covered earlier this week, Google accelerated Chrome's major release schedule on Tuesday, cutting the interval from four weeks to two starting with Chrome 153. Google attributes this rapid cadence to internal AI-assisted vulnerability scanning tools, which have sharply increased defect discovery rates. Chrome 153 concurrently addresses 230 security flaws, including a newly discovered, actively exploited out-of-bounds write zero-day in the V8 engine tracked as CVE-2026-87491.

A compressed two-week major browser release cycle forces enterprise IT teams and downstream Chromium browser developers to double their patch validation and regression testing pace. While Google offers an eight-week Extended Stable channel for managed enterprise endpoints, unmanaged devices and tech-support contacts face continuous updates. Managing this accelerated shipping tempo is essential for preventing zero-day exploitation across client endpoints.

Verified across 3 sources: Business Model Analyst · SecurityWeek · Security Affairs


The Big Picture

State Energy Policies Reclaim Local Veto Power Over High-Density Infrastructure Massachusetts Executive Order No. 658 requires data center projects exceeding 25MW to secure local municipal approval, sign community benefit agreements, and source 100% clean power or fund a Ratepayer Protection Fund. This state-level intervention shifts site selection leverage back to host cities while establishing direct financial liability for regional grid impacts.

Memory-Resident Phishing Bypasses Gateway Scanners via Trusted Cloud Paths Attackers are abandoning hosted phishing domains to build dynamic landing pages directly in local browser memory using temporary blob URLs. By routing users through trusted Microsoft OAuth and Teams infrastructure before executing sandboxed script payloads, threat actors exploit the gap between network-level reputation checks and client-side execution.

Exchange EWS Retirement Deadlines Pressure Legacy Governance Frameworks Microsoft's impending retirement of Exchange Web Services (EWS) by April 2027—coupled with mandatory EWSAllowedAppIDs auto-generation in October 2026 and new Microsoft Graph support for Purview archive mailboxes—forces enterprise administrators to complete immediate script and tenant access audits to prevent sudden application failures.

Multi-Tiered Cost Routing Limits Token Overhead in Enterprise AI Deployments Large-scale enterprise agent rollouts like Cisco's MyAgent are adopting three-tier routing architectures that direct over 50% of prompt traffic to open-weight models and deterministic automation. This operational pattern allows organizations to scale ambient AI access to tens of thousands of users without incurring exponential frontier-model token fees.

Municipal Housing Initiatives Combine Direct Subsidies with Land-Use Conversions Cities like Chicago and Buffalo are executing targeted housing interventions by pairing Tax Increment Financing with adaptive reuse of commercial high-rises and municipal property lot transfers. These initiatives convert downtown office vacancy and urban blight into income-restricted residential inventory.

What to Expect

2026-09-16 Nio Eurasia 20,000-km challenge departs Xi'an using Silk Road battery swap route.
2026-09-22 Jacksonville City Council votes on $4.9M Affordable Housing Trust Fund budget amendment.
2026-09-25 Microsoft Whiteboard legacy Azure-backed migration tools reach retirement cutoff.
2026-09-30 Application deadline for Seattle's $2.5M direct childcare worker retention grant.
2026-10-01 Exchange Online begins automatically applying EWSAllowedAppIDs access controls.

Every story, researched.

Every story verified across multiple sources before publication.

🔍

Scanned

Across multiple search engines and news databases

428
📖

Read in full

Every article opened, read, and evaluated

138

Published today

Ranked by importance and verified across sources

12

— The Tenant Desk

🎙 Listen as a podcast

Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.

Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste
Overcast
+ button → Add URL → paste
Pocket Casts
Search bar → paste URL
Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
Look for Add by URL or paste into search

Spotify isn’t supported yet — it only lists shows from its own directory. Let us know if you need it there.