🗂️ The Tenant Desk

Sunday, September 13, 2026

12 stories · Standard format

Generated with AI from public sources. Verify before relying on for decisions.

🎧 Listen to this briefing or subscribe as a podcast →

Threat groups are moving aggressively to exploit Microsoft's default passkey rollout, just as state regulators begin slamming the brakes on enterprise data center construction.

Cybersecurity

Passkey-Themed Phishing and Device Code Attacks Target Microsoft 365 Tenants

Expanding on the passkey vishing and Graph API data theft campaigns by Storm-3121 and Storm-3032 we covered over the past two days, Microsoft Threat Intelligence issued formal warnings regarding the activity on Wednesday, September 9, 2026. The advisory notes that threat cluster PREY-0058 has joined the ongoing operations, using the same combination of AiTM proxy sites, legitimate device code flows, and automated Node.js Graph API scripts to silently exfiltrate SharePoint and Exchange data.

Device code authentication flows do not enforce domain binding, allowing attackers to abuse legitimate Microsoft endpoints while user-side password managers and standard email filters fail to detect the intrusion. For M365 consultants and identity architects, protecting client tenants requires auditing Entra ID conditional access policies immediately, disabling unused device-code sign-in options, and establishing custom Graph API telemetry to catch automated data enumeration.

Verified across 2 sources: S-EDV · AsumeTech

Russian Actor GTG-20006 Uses AI to Automate Infrastructure and Device Code Phishing

A threat report published by Anthropic on Thursday, September 10, 2026, revealed that Russian state-sponsored actor GTG-20006 (associated with Midnight Blizzard) used Claude to automate operational infrastructure across 20 government and defense targets in Ukraine and Europe. Operating the Embassy Kit framework, the group used AI to continuously register fresh domains, construct phishing sites, and evade malware detection while executing OAuth 2.0 device-code phishing attacks against cloud email tenants.

AI-assisted infrastructure churn allows threat groups to burn through domains and bypass static domain blocklists faster than traditional email security gateways can update. Security teams must move away from static URL inspection and enforce conditional access policies that restrict device-code flows and inspect OAuth consent context in Entra ID.

Verified across 2 sources: AegisAI · Cybernoz

Microsoft 365 & SharePoint

Microsoft Purview eDiscovery Expands Support to User-Owned SharePoint Embedded Containers

Microsoft announced on Saturday, September 12, 2026, that Microsoft Purview eDiscovery will support user-owned SharePoint Embedded containers as active data sources for legal cases, searches, and holds starting in mid-September, with general availability slated for late October 2026. This allows compliance teams to directly index content generated within modern collaborative tools like Microsoft Loop, Copilot Pages, and Copilot Notebooks without administrative configuration. App-owned containers are excluded from this rollout.

Collaborative artifacts generated in Loop and Copilot Pages often bypass legacy SharePoint search scopes, exposing regulated enterprise clients—especially in life sciences—to legal compliance gaps. This update incorporates user-owned SharePoint Embedded storage directly into standard Purview eDiscovery workflows, ensuring legal holds cover modern M365 workloads seamlessly.

Verified across 1 sources: Pupuweb

Microsoft Adds 180-Day Planner Usage Metrics to Microsoft 365 Admin Center

Microsoft rolled out a native Planner usage report in the M365 Admin Center on Saturday, September 12, 2026. Available under Reports > Usage > Planner for accounts with the Reports Reader role, the feature tracks unique user metrics and daily active usage trends across Planner Basic and Premium plans over 7, 28, 90, or 180 days, using deliberate user interactions rather than background refreshes.

Administrators can now evaluate tenant-wide Planner adoption directly without running PowerShell scripts against Graph API endpoints. Having an integrated 180-day lookback simplifies license audits and usage tracking across corporate tenants.

Verified across 1 sources: Topedia

Copilot & Power Platform

Building Long-Running Business Processes in Copilot Studio Using Dataverse State Tables

A technical architectural guide published on Sunday, September 13, 2026, details how to build long-running enterprise processes—such as invoice processing and purchase order matching—using native Copilot Studio agent flows and Dataverse state tables without custom middleware. By anchoring workflows to persistent Dataverse state tables rather than ephemeral chat sessions, the design pattern enforces idempotency, structured error logging, multi-agent child task delegation, and human-in-the-loop approval checkpoints supported by Power BI observability dashboards.

Enterprise business processes operating over days or weeks degrade rapidly when tied to synchronous chat loops or unstructured memory. Shifting state governance into Dataverse provides Power Platform architects with an auditable, native blueprint to deploy production-grade agentic automation that recovers gracefully from execution errors.

Verified across 1 sources: DEV Community

Building a Custom GitHub Copilot Agent for Power BI Theme Audits in Fabric Workspaces

A technical walkthrough published on Sunday, September 13, 2026, details how to build a reusable GitHub Copilot custom agent in VS Code to automate Power BI theme audits across Microsoft Fabric workspaces. The agent utilizes powerbi-report-management skills to unpack PBIR report files, validate visual styling against an organization's JSON design tokens, generate timestamped log files, and enforce a workspace hook that prevents unauthorized auto-publishing back to Fabric.

Governing reporting templates manually across large Power BI or Fabric deployments is inefficient and error-prone. Encapsulating workspace management tools into version-controlled IDE agents with hard execution hooks allows development teams to enforce visual compliance automatically without risking production disruptions.

Verified across 1 sources: BI Insight

Enterprise AI

Four Enterprise Vendors Launch Standalone AI Agent Governance Products

Following the adoption of a standardized three-layer AI agent governance stack by major software vendors we tracked earlier this week, a wave of standalone governance products hit the market between late August and early September 2026. Okta launched Agent SSO utilizing short-lived tokens, IBM introduced watsonx Orchestrate AgentOps with an AI Gateway, Broadcom showcased AgentMinder for runtime traffic at VMware Explore, and Dataiku released a dedicated Agent Management tool.

Building on the high generative AI failure rates driven by governance gaps we noted previously, these specialized tools highlight a structural enterprise shift toward assigning unique, least-privilege digital identities and dedicated traffic controllers to autonomous agent fleets before scaling production usage.

Verified across 2 sources: Forkast · Yahoo Finance

Politics, Fact-Checked

Federal Court Blocks Partisan Loyalty Essay Requirement for Civil Service Job Applicants

U.S. District Judge George O'Toole in Boston issued a preliminary injunction on Friday, September 11, 2026, blocking the Office of Personnel Management from requiring career civil service job applicants to complete a written essay detailing how they would advance presidential executive orders. The lawsuit, brought by federal employee unions including AFGE, successfully argued that the prompt on USAJobs listings violated the Administrative Procedure Act and First Amendment by imposing an unconstitutional political test on nonpartisan roles.

The ruling temporarily halts an executive branch effort to introduce political alignment screenings into federal hiring workflows. Enjoining the requirement preserves statutory civil service protection standards while setting up higher-level judicial reviews regarding presidential control over the federal workforce.

Verified across 2 sources: Hoodline · Reuters

New England Beat

Massachusetts Executive Order Mandates Local Veto and Clean Energy Funding for 25MW+ Data Centers

Adding to Massachusetts Governor Maura Healey's September 8, 2026, executive order granting municipalities veto power over 25MW+ data centers, newly highlighted provisions pause applications for state sales tax exemptions. The order, responding to power grid capacity constraints noted by ISO-NE, also requires facility operators to pay into a dedicated ratepayer protection fund alongside the previously reported self-supplied clean energy mandates.

State power limits are quickly becoming primary siting constraints for enterprise AI and cloud infrastructure in New England. Enterprise architects must account for increased lead times, mandatory local public approvals, and behind-the-meter clean energy investments when planning regional data center capacity.

Verified across 2 sources: Stockpil · AI Intelligence Brief

EVs & Charging

Ionna Fast-Charging Network Reaches 1,500 Stalls with 36% NACS Port Ratio

Fresh off its top ranking in the J.D. Power U.S. EVX Public Charging Study we covered earlier this month, data updated in the Alternative Fuels Data Center on Saturday, September 12, 2026, shows the automaker-backed Ionna network has expanded to 1,526 DC fast-charging stalls across 178 U.S. locations. The growth stems from acquiring and upgrading Circle K sites to 400-kW peak power hardware, giving Ionna the lead among non-Tesla networks in NACS adoption, with native connectors deployed at 36% of its active stalls.

The rapid rollout of high-powered 400-kW chargers featuring native NACS connectors provides crucial non-Tesla charging capacity for NACS-equipped electric vehicles like the Nissan Ariya. Network expansion backed by major OEMs improves highway fast-charging reliability while driving competition on charging speeds and uptime.

Verified across 1 sources: EV Charging Stations

Science & Space

Rare Cortical Sst-Chodl Neurons Discovered to Synchronize Brain Activity and Drive Deep NREM Sleep

A study led by the Icahn School of Medicine at Mount Sinai published in Nature on Wednesday, September 9, 2026, identified a population of long-range cortical inhibitory neurons called Sst-Chodl neurons that account for 0.2% of cortical cells. The research proves these evolutionarily conserved neurons actively synchronize electrical oscillations across the neocortex to drive transitions into deep non-REM (NREM) sleep, overturning the view that the cortex plays a passive role in sleep regulation.

Demonstrating that specific cortical circuits actively orchestrate brain-wide sleep rhythms opens target pathways for treating chronic sleep fragmentation and neurodegenerative conditions. It provides sleep medicine researchers with a cellular marker for studying sleep pressure mechanisms.

Verified across 1 sources: Medical Xpress

Consumer Tech Quirks

Microsoft Confirms Windows 11 KB5124008 Update Triggers Code 10 Errors on USB Audio Devices

Adding to the Hyper-V, RDS, and Always On VPN regressions we tracked over the weekend, Microsoft officially confirmed on Sunday, September 13, 2026, that the September Patch Tuesday update (KB5124008) also breaks USB Audio Class 1.0 peripherals. The update causes Code 10 initialization errors in Device Manager across Windows 11 25H2 and 24H2, disabling external headsets and microphones until users apply temporary 2-channel mode workarounds.

Because the failure resides in the operating system update stack rather than peripheral drivers, standard device reinstalls fail to restore functionality. Technical support teams should advise users against driver re-installations and apply temporary audio channel workarounds until an out-of-band patch drops.

Verified across 2 sources: 9to5Windows · 9to5Windows


The Big Picture

Adversaries Target Identity Migration Friction Over Protocol Security Rather than attempting to break passkey cryptography or OAuth protocols directly, threat groups like Storm-3121, Storm-3032, and PREY-0058 are targeting administrative transition periods. By manipulating users via phone, SMS, and device-code flows, attackers leverage valid Microsoft endpoints to harvest access tokens and exfiltrate tenant data without triggering traditional endpoint alerts.

Standalone Control Planes Emerge for Autonomous AI Governance As enterprise deployments move from conversational assistants to multi-step agents, vendor architecture is shifting away from ad-hoc prompts toward explicit execution gateways, context lineage tracing, and dedicated identity controls like Agent SSO. Establishing clear boundaries between reasoning loops and execution APIs has become the core design baseline.

State Regulations Direct Clean Energy Costs onto Data Center Developers Governments in Massachusetts and Connecticut are moving away from data center tax subsidies toward stringent permitting guardrails. Mandating local municipal approval, ratepayer protection fees, and developer-funded renewable generation establishes physical power supply as the primary structural boundary for high-density compute.

Dataverse and Knowledge Graphs Replace Ephemeral Chat Runtimes Architects building long-running enterprise workflows are abandoning pure conversational LLM sessions in favor of persistent state tables and knowledge graphs. Utilizing Dataverse state tables for multi-step approval pipelines ensures idempotency, auditability, and reliable recovery across days-long process executions.

Deep Sleep Micro-Circuits Emerged as Non-Invasive Biomarkers for Cognitive Aging Neuroscience research continues to link synchronized slow-wave deep sleep directly to cellular micro-circuits and protein clearing mechanisms in the brain. Disruptions in traveling slow waves caused by frontal tau accumulation provide a concrete functional metric for measuring cognitive decline long before clinical symptoms appear.

What to Expect

2026-09-14 Apple officially releases iOS 27 to the public.
2026-10-01 Exchange Online enforces EWSAllowList restrictions ahead of complete EWS retirement; mandatory 75% state SNAP administrative cost-shift takes effect.
2026-10-16 Microsoft Dataverse column-based security filtering enters public preview under MC1465569.
2026-10-31 Microsoft Purview eDiscovery support for user-owned SharePoint Embedded containers reaches scheduled General Availability.
2026-11-03 U.S. Midterm Elections take place across 35 Senate seats, 36 governorships, and 435 House districts.

Every story, researched.

Every story verified across multiple sources before publication.

🔍

Scanned

Across multiple search engines and news databases

346
📖

Read in full

Every article opened, read, and evaluated

118

Published today

Ranked by importance and verified across sources

12

— The Tenant Desk

🎙 Listen as a podcast

Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.

Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste
Overcast
+ button → Add URL → paste
Pocket Casts
Search bar → paste URL
Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
Look for Add by URL or paste into search

Spotify isn’t supported yet — it only lists shows from its own directory. Let us know if you need it there.