🗂️ The Tenant Desk

Thursday, September 17, 2026

12 stories · Standard format

Generated with AI from public sources. Verify before relying on for decisions.

🎧 Listen to this briefing or subscribe as a podcast →

Microsoft's identity architecture is confronting a new wave of stealthy persistence threats today, stretching from rogue OIDC providers to automated device-code phishing kits. We're also tracking Cisco's entry into the AI agent governance race and a massive $3.4 billion transmission upgrade moving forward in New England.

Microsoft 365 & SharePoint

Microsoft Entra Connect Sync v2.6.91.0 Enables Passwordless Authentication by Default

Pushing forward with the September 1 passkey enforcement mandate we've been tracking, Microsoft released Entra Connect Sync v2.6.91.0 on Wednesday. The update reaches general availability for phishing-resistant passwordless authentication and turns it on by default. It introduces Windows Web Account Manager support for passkeys and FIDO2 security keys alongside a guided migration wizard to transition hybrid environments to Microsoft Entra Cloud Sync.

Enabling passwordless auth by default in the sync engine removes manual registry configuration steps, accelerating passkey deployments across hybrid enterprise tenants. The inclusion of an automated migration workflow to Cloud Sync simplifies architectural overhauls for organizations facing legacy synchronization debt. Consultants should review Graph permissions and updated service accounts before deploying the update across regulated client environments.

Verified across 1 sources: Sonne's Cloud Blog

Purview DLM Integrates M365 Archive to Exclude Inactive Retention Files from Copilot Indexing

Microsoft Purview Data Lifecycle Management began rolling out an automatic archiving feature for SharePoint Online and OneDrive retention policies in mid-September. Under this update, inactive content migrated to Microsoft 365 Archive is automatically excluded from Microsoft Copilot indexing while remaining fully discoverable via Purview eDiscovery.

Excluding stale retention data from Copilot indexing addresses a primary pain point for enterprise AI deployments: poor answer relevance caused by outdated draft files. Additionally, automatically moving cold collaboration content into lower-cost M365 Archive tiers helps organizations control cloud storage costs without breaching regulatory retention mandates in life-sciences and financial tenants.

Verified across 1 sources: Hands On Tech

Copilot & Power Platform

Azure OpenAI Email Assistant Leak Exposes Retrieval Pipeline ACL Blind Spots

SynSphere Italia demonstrated that a production Azure OpenAI email assistant returned restricted SharePoint documents to low-privilege users. Although unit tests passed, the underlying Retrieval-Augmented Generation pipeline executed queries using the elevated permissions of the indexer's service account rather than passing the requesting user's identity token.

This vulnerability highlights a critical governance gap in custom RAG implementations built on top of Microsoft 365 data layers. When retrieval pipelines neglect query-time security trimming or fail to enforce Entra user token propagation, confidential corporate records can be exposed through routine conversational prompts. Architects must ensure custom retrieval pipelines explicitly mirror native SharePoint access control lists rather than relying on global service principles.

Verified across 1 sources: Glodaxia

Cisco Expands Agent Governance Stack with Build-Time Enforcement and Open-Source DefenseClaw

Joining the standalone AI governance push we tracked from Okta, IBM, and Broadcom earlier this month, Cisco introduced build-time policy enforcement for AI agents on Wednesday. The release embeds OWASP and NIST compliance specifications directly into runtime SDKs across Azure AI Foundry, AWS Bedrock, and Google Vertex. Simultaneously, Cisco released DefenseClaw, an open-source framework designed for runtime threat detection, Model Context Protocol (MCP) scanning, and AI Bill of Materials generation.

Enterprises struggle to move agentic AI past pilot stages due to unpredictable runtime drift and security ambiguity. Shifting governance controls to build-time SDKs and establishing open-source inspection tools allows security teams to enforce policy boundaries before agents execute actions. For systems consultants, this modular architecture provides a practical framework for governing cross-cloud agent deployments.

Verified across 1 sources: Forkast News

Politics, Fact-Checked

NewsGuard Launches Midterm Tracker Identifying 18 False Claims and 'Pink Slime' Sites

NewsGuard launched its 2026 Midterm Elections Misinformation Tracker on Wednesday, identifying 18 specific false claims and 47 sites circulating election falsehoods. Eleven tracked claims allege voter fraud, including fabricated stories regarding San Diego P.O. box registrations, while 21 newly identified partisan 'pink slime' outlets brought the total tracked nationwide to 1,129.

The proliferation of automated local news fronts and AI-generated media continues to strain public information ecosystems ahead of the midterms. Identifying specific false narratives and tracking clandestine partisan networks offers essential empirical baseline data for election administrators and media literacy researchers. Documenting these coordinated campaigns helps counter unverified claims before they alter voter behavior.

Verified across 2 sources: NewsGuard's Reality Check · NewsGuard

Working-Class Economy

House Passes Bipartisan Ratepayer Protection Act to Shift Data Center Power Infrastructure Costs

The U.S. House of Representatives passed the Ratepayer Protection Act (H.R. 9340) on Wednesday, requiring commercial data centers to pay the full cost of dedicated electricity generation and grid upgrades. The bipartisan bill aims to prevent utility companies from passing infrastructure expansion costs driven by AI power demands onto residential utility customers.

Rapid expansion of resource-heavy computing facilities has contributed to rising residential electricity bills in major technology hubs. By legally mandating that developers internalize transmission and power generation costs, the bill attempts to insulate working- and middle-class households from utility cost inflation. However, with the Senate calendar tight ahead of midterms, energy policy experts warn that legislative stalling could prolong regional rate spikes.

Verified across 1 sources: Political.org

Cybersecurity

Varonis Discloses 'TrustSink' Persistence Technique Abusing Entra External Auth Methods

On Wednesday, Varonis Threat Labs disclosed a credential-phishing technique called TrustSink that targets Microsoft Entra ID. Attackers with administrative privileges register a rogue OIDC provider within the External Authentication Method framework, inserting a pixel-accurate fake password prompt into legitimate sign-in flows. The rogue provider captures plaintext credentials while returning a valid signed JWT token to complete authentication without errors.

This technique presents a severe risk for M365 consultants because standard incident response playbooks fail to neutralize it. Because the credential capture occurs within a valid authentication chain, resetting a user's password does not remove the standing rogue provider. Administrators must explicitly audit Authentication Methods Policies and application registrations in Entra ID to ensure unauthorized OIDC providers have not been injected as persistent traps.

Verified across 1 sources: Varonis

GhostCode Phishing Kit Weaponizes Entra Device Enrollment for Primary Refresh Tokens

As we've tracked across recent adversary-in-the-middle and device-code exploits, threat actors are aggressively targeting Primary Refresh Tokens (PRTs) for persistent Entra ID access. Now, researchers at eSentire have detailed the GhostCode phishing kit, a new automated tool weaponizing the OAuth 2.0 device authorization grant. Initiated via HTML attachments and contact form lures, the kit directs users to legitimate Microsoft MFA pages and registers multiple Intune devices within 78 seconds of approval to secure a PRT without password harvesting.

The GhostCode campaign demonstrates how threat actors achieve long-term tenant access without triggering standard credential-reset alerts. Because the victim completes MFA on valid Microsoft URLs, email security gateways fail to flag the initial interaction, and the newly enrolled Intune devices survive session token revocations. Mitigation requires restricting device-code authentication via Conditional Access and continuously monitoring for unauthorized Intune device registrations.

Verified across 3 sources: Cyber Security News · GBHackers · Zero Hour

EVs & Charging

Tesla Deploys Modular 'Accordion' Supercharger Stalls to Accelerate Site Installs

Tesla deployed its first pre-assembled 'Accordion' Supercharger unit on Wednesday, packing 16 stalls onto a single transport rig. The prefab hardware installs 20% cheaper than traditional layouts and is specifically engineered to fit within existing parking spaces without requiring behind-the-curb concrete foundations.

Civil engineering and permitting delays remain primary obstacles to scaling public fast-charging networks. By shifting hardware assembly entirely to factory environments, site developers can bypass extensive underground utility work and deploy high-density charging hubs in days rather than weeks. This modular approach helps restore installation momentum across highway and retail corridors.

Verified across 1 sources: Electrek

New England Beat

ISO New England Selects Eversource and Avangrid's TIDE Project for Regional Grid Upgrades

ISO New England selected the Transmission Initiative Down East (TIDE) proposal from Eversource and Avangrid on Thursday as its preferred long-term grid solution. The project includes an 18-mile, 345-kilovolt transmission line in New Hampshire and infrastructure upgrades across Maine and Massachusetts to integrate 1,200 megawatts of future onshore wind with construction planned for 2029.

Grid transmission limits represent one of the steepest bottlenecks for clean energy integration and data center expansion across New England. By leveraging existing utility rights-of-way, the $3.41 billion project bypasses traditional land-use disputes to unlock northern wind power and lower regional congestion costs. For regional IT leaders, long-term grid stabilization provides clearer capacity forecasts for future infrastructure and cloud facility planning.

Verified across 2 sources: Construction Review Online · Globe Newswire

Boston Mayor Wu Details $100M Housing Tax Abatements and Permit Streamlining

Speaking to the Greater Boston Chamber of Commerce on Wednesday, Mayor Michelle Wu outlined five municipal tools to unfreeze stalled housing developments, including $100 million in combined tax breaks. The city named four initial projects receiving $31.5 million in tax abatements to construct 1,400 units, while introducing a streamlined single-point-of-contact permitting process launching October 1.

High construction costs and elevated interest rates have severely curtailed residential construction starts across Greater Boston. Tying tax relief directly to strict ground-breaking deadlines represents an aggressive push to force private capital into motion without waiving inclusionary zoning requirements. The success of these pilot abatements will dictate whether urban housing supply can keep pace with regional workforce demand.

Verified across 4 sources: WBUR · Axios · Boston Globe · Boston Business Journal

Consumer Tech Quirks

Microsoft Edge 153 Bug Causes Web Application Freezes and Rendering Locks

A regression bug in Microsoft Edge version 153 is causing web applications to freeze during routine user interactions. The issue originates from an upstream Chromium 153 flaw that Google has already patched for Chrome. Microsoft has acknowledged the issue without providing an immediate fix date, advising users to temporarily roll back to version 152.

Browser freezes directly interrupt daily line-of-business applications and SaaS portals across corporate fleets. Because Microsoft's patch cycle trails upstream Chromium hotfixes, IT administrators face the operational burden of deploying command-line downgrades or instructing users to switch browsers. System architects should monitor rollout channels to prevent automated updates from breaking critical web workflows.

Verified across 1 sources: PiunikaWeb


The Big Picture

OAuth and Device Flows Evolve Into Long-Term Persistence Vectors Threat campaigns are shifting beyond simple credential harvesting to exploit native Microsoft Entra registration features. By leveraging device-code authorization and external authentication methods to register Primary Refresh Tokens and rogue identity providers, adversaries maintain persistent tenant access that resists standard password resets and session revocations.

Build-Time Rules and Cryptographic Proof Edge Out Post-Hoc Tracing Enterprise AI platforms are moving security enforcement directly into runtime SDKs and authorization proxies. Vendors are prioritizing deterministic guardrails, short-lived tokens, and cryptographic identity verification over vendor-signed audit logs to contain non-deterministic agent workflows before execution occurs.

Regional Grid Expansion Mobilizes to Unblock Energy Deadlocks Transmission planning and ratepayer protection initiatives are accelerating to keep pace with soaring energy demands. High-voltage regional upgrades across New England and federal cost-allocation bills highlight an urgent effort to insulate residential utility bills while integrating large-scale renewable generation.

Low-Code Development Demands Strict Dataverse and Purview Boundary Scoping The rapid expansion of natural-language app building and Copilot Studio skills is exposing fundamental gaps in underlying tenant permissions. Organizations are being forced to implement automated archiving and explicit retrieval boundaries to prevent outdated historical records or over-permissioned service accounts from leaking sensitive data.

Prefabrication and Integrated Storage Circumvent Charging Infrastructure Delays Electric vehicle infrastructure providers are bypassing protracted utility queue timelines and heavy civil engineering through modular solutions. Deploying pre-assembled Supercharger units and pairing megawatt chargers with on-site battery storage allows operators to scale fast-charging capacity in dense urban centers without waiting for local grid overhauls.

What to Expect

2026-09-22 Boston Fintech Week 2026 opens community programming focused on AI, data trust, and financial services.
2026-10-15 Microsoft Purview begins rolling out 3 TB auto-expanding archive support for eligible Exchange Online mailboxes.
2026-10-16 Microsoft Dataverse launches public preview for column-based security filtering on record-level access.
2026-11-01 Microsoft Purview previews upgraded inline DLP protection for Entra-managed apps in Edge for Business.
2026-12-10 Australia's automated decision-making transparency rules take effect for AI agents operating in Dynamics 365.

Every story, researched.

Every story verified across multiple sources before publication.

🔍

Scanned

Across multiple search engines and news databases

440
📖

Read in full

Every article opened, read, and evaluated

132

Published today

Ranked by importance and verified across sources

12

— The Tenant Desk

🎙 Listen as a podcast

Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.

Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste
Overcast
+ button → Add URL → paste
Pocket Casts
Search bar → paste URL
Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
Look for Add by URL or paste into search

Spotify isn’t supported yet — it only lists shows from its own directory. Let us know if you need it there.