Microsoft is fundamentally restructuring Copilot today, splitting the platform into a unified hub and introducing the metered credit model we've been tracking. Also on the docket: the U.S. Supreme Court clears the way for an expanded federal voter database, and Anthropic locks in a massive edge computing deal to crush agent latency.
Formalizing the shift to metered Copilot execution we've tracked over the past month, Microsoft announced a structural revamp on Friday, September 25. The update splits the suite into a unified application hub (featuring Home, Code, and Autopilot) and bifurcates its commercial model into flat user subscriptions alongside metered consumption. Advanced agentic tasks will now consume Copilot Credits priced at $0.01 per unit. To govern these workloads, Microsoft launched the public preview of Copilot Managed Runtime, providing secure tenant-side hosting, Git versioning, Entra identity boundaries, and FinOps spending controls within the M365 Admin Center.
Why it matters
The transition to consumption-based billing for autonomous, background AI agents fundamentally alters enterprise M365 financial planning, exposing tenants to budget variance if persistent agents execute runaway loops. M365 consultants and architects must immediately guide clients in setting strict budget caps and spending limits in the M365 Admin Center before enabling agentic features. Furthermore, the Copilot Managed Runtime provides an essential enterprise boundary that allows citizen developers to build and host custom web applications without generating unmanaged shadow IT.
Microsoft announced on Thursday, September 24, that Security Copilot capabilities and autonomous security agents are now natively included in Microsoft 365 E5 and E7 subscriptions at no extra base cost. Eligible tenants automatically receive a monthly allocation of 400 Security Compute Units (SCUs) per 1,000 licensed users (capped at 10,000 SCUs monthly) across Defender, Entra, Intune, and Purview. Concurrently, Microsoft introduced network-layer Data Loss Prevention (DLP) via Entra Global Secure Access to monitor and protect on-behalf-of (OBO) agentic traffic across enterprise network pathways.
Why it matters
Bundling SCUs directly into E5 and E7 tiers eliminates the licensing friction that previously prevented security teams from deploying AI-assisted triage and investigation workflows. Shifting DLP enforcement to the network layer via Global Secure Access ensures that autonomous agents acting on behalf of users cannot exfiltrate sensitive data through unmonitored API calls. Enterprise architects should audit current SCU usage patterns and deploy Global Secure Access in audit mode to baseline agentic traffic before enforcing block rules.
Advancing the transition toward the February 2027 SMS and voice MFA retirement we've been tracking, Microsoft published technical documentation on Friday detailing its 'Choose Your Own Telephony Provider' framework for Entra ID. Under the new architecture, organizations requiring telecom-based MFA fallback must contract directly with approved providers like Soprano or Telesign in the Microsoft Security Store by October 30, 2026, and route messages via Azure routing functions. Unconfigured tenants will automatically prompt unmigrated users to register passkeys upon login after the 2027 cutoff.
Why it matters
This update represents an important shift in operational responsibility and cost, transferring the financial burden of telecom MFA directly to enterprise IT budgets. M365 consultants must urgently review client authentication dependency logs to identify remaining SMS/Voice users, configure external provider integrations if necessary, or accelerate FIDO2 passkey rollouts to avoid user login blocks when the native cutoffs take effect.
Microsoft announced that SharePoint Online will roll out native support for creating, editing, and publishing HTML pages alongside traditional ASPX pages under Roadmap ID 569208. Public preview begins in early October 2026, with general availability scheduled through December. The update includes Copilot-assisted HTML page generation directly stored in the Site Pages library under existing site permissions, while removing the site-scoped Agent creation shortcut from the + New menu.
Why it matters
Allowing direct HTML page authoring provides organizations with greater flexibility for customized intranet layouts and web content display without requiring complex custom SPFx web parts. However, because Copilot can automatically generate HTML pages from natural language prompts, SharePoint architects must verify that site permissions and page library approval workflows are properly configured to prevent unauthorized content updates.
On Saturday, September 26, reports detailed a seven-year, $11.6 billion cloud infrastructure agreement between Anthropic and Akamai Technologies centered on edge CPU orchestration rather than GPU training clusters. The contract includes an equity warrant granting Anthropic a ~5% stake in Akamai and leverages Akamai's 4,400-node global edge network. Concurrently, Anthropic released new engineering documentation for Claude Code, advising developers to isolate research tasks using subagents and maintain persistent project instructions in CLAUDE.md files to prevent context window degradation.
Why it matters
As autonomous AI agents shift from static chat prompts to executing multi-step tool calls, processing bottlenecks move from GPU-heavy matrix multiplication to CPU-bound API orchestration and network routing. Utilizing distributed edge CPU nodes dramatically reduces per-hop latency for complex agent tool chains. Engineering teams building agentic software must focus on context window management and edge routing to maintain responsiveness in production applications.
Building on the DHS voter-file probes we tracked earlier this month, the U.S. Supreme Court issued an unsigned per curiam order on Friday, September 25, staying a lower-court injunction. The ruling allows the Trump administration to resume state access to an expanded Systematic Alien Verification for Entitlements (SAVE) database. The updated system combines Department of Homeland Security immigration records with Social Security administration data to flag potential noncitizen voter registrations. While the majority concluded the executive branch is authorized to share cross-agency eligibility data, dissenting justices led by Justice Ketanji Brown Jackson warned that systemic error rates and stale records risk disenfranchising lawful naturalized citizens during the 90-day pre-election window.
Why it matters
This ruling establishes a significant administrative precedent regarding how federal data feeds can be merged and utilized by state election officials just weeks before a federal election. The operational challenge hinges on distinguishing permissible 'individualized inquiries' from prohibited mass election-day purges under the National Voter Registration Act. For data systems specialists, the case underscores the severe compliance and auditability risks of aggregating disparate government databases where false positives can deny statutory rights.
Yesterday we covered LevelBlue's disclosure of the Entra ID Self-Service Password Reset (SSPR) enumeration vulnerability; today, further technical details confirm exactly how the exploit operates. By analyzing distinct server responses and `CurrentViewName` telemetry fields, attackers can verify whether target accounts exist, distinguish regular accounts from high-privilege administrators, and identify registered MFA methods such as SMS or authenticator apps. Proof-of-concept tooling now demonstrates automated scanning to map tenant attack surfaces.
Why it matters
Public authentication portals that expose account status and configured verification methods provide threat actors with precise intelligence before launching targeted phishing or credential-spraying campaigns. Identity administrators should immediately audit SSPR scope settings, restrict public SSPR visibility where feasible, and implement strict Conditional Access monitoring for unusual password reset validation attempts.
Security alerts issued on Friday, September 25, warn of active exploitation targeting CVE-2026-55040, a critical 9.1-severity vulnerability in Microsoft SharePoint Server. Following the public release of proof-of-concept exploit code, attackers are actively forging JWT tokens using 'alg: none' signatures to bypass authentication controls and impersonate legitimate users across unpatched on-premises and hybrid SharePoint deployments.
Why it matters
Unauthenticated remote token forgery allows malicious actors to completely bypass identity boundaries, access restricted document repositories, and execute arbitrary commands within on-premises SharePoint farms. System administrators who have not yet deployed Microsoft's July 2026 security updates must patch immediately and review IIS logs for abnormal JWT token validation errors.
Boston Mayor Michelle Wu announced the launch of the Housing Accelerator Fund on Friday, September 25, making up to $35 million in low-cost construction loans and equity investments available for ready-to-build residential projects containing affordable housing. Administered via a Request for Proposals by the Boston Housing Authority, the fund offers up to $20 million per project in subordinate construction financing for developments of 100+ units capable of breaking ground by September 2027.
Why it matters
High interest rates and tight commercial lending standards have stalled multi-family housing projects across Greater Boston, creating financing gaps that private capital cannot fill. By providing subordinate, below-market rate capital that recycles back into a revolving fund upon repayment, the city can unfreeze stalled residential construction and expand workforce housing inventory. This mechanism serves as a model for municipal interventions aiming to maintain housing production during economic downturns.
The MassDOT Board of Directors approved a $600 million transportation funding package on Thursday, September 24, including $200 million dedicated to modernizing the MBTA's commuter rail fleet. Authorized via Chapter 90 legislation and the state's Capital Investment Plan, the procurement includes 10 new diesel-electric locomotives and 10 battery/catenary dual-mode locomotives to replace aging equipment across the regional transit network.
Why it matters
Transitioning the MBTA commuter rail to battery/catenary locomotives addresses long-standing mechanical unreliability while reducing diesel emissions along high-density residential corridors. For New England regional development, dependable rail transit is a prerequisite for supporting transit-oriented housing mandates across suburban communities. The dual-mode architecture allows incremental electrification without waiting for full catenary infrastructure builds across every branch line.
On Friday, September 25, Geely introduced its Geely Smart Charge technology in Ningbo, featuring a peak single-connector output of 2,250 kW (2.25 MW) paired with 12C ultra-short blade lithium batteries. Utilizing predictive AI thermal management via its Xingrui PowerMind system, Geely demonstrated charging sessions from 10% to 70% state-of-charge in 4 minutes and 30 seconds, with plans to deploy 100,000 high-power charging stalls by late 2027.
Why it matters
Megawatt-class charging combined with high-C-rate battery chemistries shifts the primary EV usability benchmark from total vehicle range to ultra-fast replenishment rates that rival liquid fuel fill-ups. The technical bottleneck in multi-megawatt charging is active thermal management, which Geely addresses through real-time predictive cooling models. If deployed successfully at scale, these charge rates will set new performance expectations across global EV charging standards.
Following the rollout of Google's September 2026 security update, multiple Pixel device owners reported being locked out of their phones due to a severe bug in lock screen authentication. The issue causes pattern unlock lines to disappear mid-gesture and triggers incorrect PIN errors after entering a single digit, with affected users forced to perform full factory resets to regain device access.
Why it matters
A monthly OS security patch that corrupts local authentication state represents a critical quality assurance breakdown, causing complete user lockout and potential unbacked data loss. Technical administrators and power users managing fleet or family devices should pause automatic system updates on Android hardware until Google releases a confirmed hotfix.
Consumption Models Reach the M365 Administration Plane Microsoft's introduction of Copilot Credits for long-running agentic workloads forces enterprise IT departments to build FinOps disciplines into traditional tenant administration routines.
Agentic Governance Shifts to Network and Boundary Control As AI agents gain autonomous API access and write-back capabilities, governance mechanisms are migrating from static prompt limits toward network-layer DLP and managed execution runtimes.
High-Stakes Identity Systems Face Escalating Verification Scrutiny From federal voter eligibility databases to enterprise Entra ID authentication flows, cross-referencing disparate records introduces severe accuracy risks and error-handling requirements.
Direct Capital Interventions Target Local Economic Friction Municipalities and local partnerships are increasingly deploying targeted micro-grants and revolving debt funds to unfreeze housing construction and stabilize working-class households.
Mobile Patch Regressions Trigger Core Operational Disruptions Recent updates across major consumer mobile platforms demonstrate how software regressions in base authentication and biometric layers can completely lock out users.
What to Expect
2026-09-30—Final retirement deadline for Microsoft Project Online; all project access and stored data will cease.
2026-10-01—Public preview begins for SharePoint Online HTML page creation and Copilot-assisted publishing.
2026-10-20—SharePoint Online begins including document library field data in 1 TB site metadata calculations.
2026-10-30—Deadline for Entra ID tenants requiring SMS/voice MFA to contract external telephony vendors in the Security Store.
2026-11-03—U.S. Midterm Elections and Massachusetts statewide vote on Question 7 zoning reform.
How We Built This Briefing
Every story, researched.
Every story verified across multiple sources before publication.
🔍
Scanned
Across multiple search engines and news databases
371
📖
Read in full
Every article opened, read, and evaluated
115
⭐
Published today
Ranked by importance and verified across sources
12
— The Tenant Desk
🎙 Listen as a podcast
Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.
Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste