🗂️ The Tenant Desk

Thursday, October 1, 2026

11 stories · Standard format

Generated with AI from public sources. Verify before relying on for decisions.

🎧 Listen to this briefing or subscribe as a podcast →

Today on The Tenant Desk: We are tracking a hard end-of-year deadline for migrating off classic Purview security consoles, alongside the launch of a unified Microsoft 365 plugin registry. Elsewhere, the legal battles over state voter roll verification are escalating, and OpenClaw introduces a new open-source control plane for self-hosting AI agents.

Microsoft 365 & SharePoint

Microsoft Purview Schedules Unified DSPM Console Migration as Classic Portals Retire

Microsoft confirmed on Wednesday, September 30, that the redesigned, unified Purview Data Security Posture Management (DSPM) experience will deploy to GCC, GCC High, and DoD environments in October 2026. This follows Message Center notice MC1481315, which outlines the mandatory retirement of Purview DSPM classic and DSPM for AI classic consoles across all commercial and sovereign clouds between November 30 and December 31, 2026.

Administrators relying on legacy Purview security consoles face a firm end-of-year deadline to transition compliance monitoring, risk posture reports, and automated workflows to the unified portal. Sovereign cloud tenants in particular must validate their Entra app registrations and partner integrations quickly given shorter deployment windows. Failing to update internal administrative documentation and API calls before November 30 risks interrupting automated data governance reporting.

Verified across 3 sources: WindowsForum · Pupuweb · TrustList

Microsoft Retires SharePoint OTP Authentication, Mandating Entra B2B Guest Accounts

Following up on external access policy shifts, Microsoft announced that SharePoint One-Time Passcode (OTP) authentication for external file sharing will be retired between October 1 and October 31, 2026. Legacy specific-people sharing links using ad hoc OTP authentication will stop functioning for external recipients who do not have a formal Microsoft Entra B2B guest account provisioned in the tenant.

Ad hoc OTP links created a security bypass where external users accessed tenant documents without satisfying tenant-level Entra Conditional Access, MFA, or Purview controls. Migrating fully to Entra B2B guest accounts forces external identity governance into standard directory auditing workflows. Organizations must immediately run PowerShell audit scripts to identify active OTP shares and convert external collaborators into directory guests before October 31 to prevent widespread access failures.

Verified across 1 sources: Syskit

SharePoint Framework 1.24 Roadmap Confirms October GA for Copilot UX Components

Microsoft announced on Wednesday, September 30, that SharePoint Framework (SPFx) 1.24 and Copilot UX components are scheduled for worldwide General Availability in October 2026. The release officially incorporates React 18 support, build-time validation for declarative agent manifests, automatic hotfix versioning for Teams manifests, and upcoming support for Node.js 24 and 26 in the release candidate.

Standardizing Copilot UX components within SPFx 1.24 provides developers with a structured, supported path to embed custom interactive controls directly into the M365 Copilot canvas without managing custom web hosting. However, upgrading SPFx solutions to React 18 introduces stricter state-rendering rules that can break existing web parts. Developers and architects must audit current client codebases for React 18 compliance ahead of the October GA.

Verified across 1 sources: Microsoft Developer Blogs

Copilot & Power Platform

Microsoft Consolidates Extensions into Plugin Registry and Replaces UI Agent Buttons

Under Message Center notice MC1484008 issued Thursday, October 1, 2026, Microsoft announced the rollout of the Microsoft plugin registry to unify governance across agents, skills, connectors, and Model Context Protocol (MCP) servers in Word, Excel, PowerPoint, and SharePoint. Governed through the M365 admin center and Agent 365, the rollout will also update end-user interfaces between late October and late November 2026, replacing the 'Agents', 'Agents & Skills', and 'Customize' buttons with a single 'Plugins' button.

Managing custom agents and third-party connectors across disparate Microsoft 365 app surfaces previously created administrative blind spots and user friction. Unifying these discovery and control points into the central M365 admin center allows IT teams to enforce consistent publishing policies and restrict unvetted extensions. Architects must prepare client adoption materials for the upcoming UI shift and verify that custom Copilot Studio agents align with the new registry structure.

Verified across 1 sources: MWPro

Enterprise AI

OneTrust Launches CORIE Runtime AI Governance and Tool-Call Monitoring Engine

At TrustWeek 2026 on Wednesday, September 30, OneTrust introduced CORIE (Contextual Orchestration for Reasoning, Intelligence and Evidence), a platform providing real-time runtime governance for autonomous AI agents. The tool evaluates agent actions at the specific tool-call level—permitting, blocking, or escalating them based on contextual risk—and logs actions to an evidence ledger. It also features an MCP Gateway to extend governance context into external tools including ChatGPT, Claude, Copilot, and Glean.

Static pre-deployment prompts and standard access permissions fail to prevent non-deterministic multi-step agent actions once an agent starts invoking external APIs. Evaluating policy compliance dynamically at the tool-call level prevents runaway execution and data leakage across complex enterprise integrations. For Microsoft 365 consultants and enterprise architects, integrating third-party policy enforcement engines like CORIE alongside Entra Agent IDs is becoming a prerequisite before permitting autonomous agents in production.

Verified across 1 sources: Channel Insider

OpenClaw Foundation Releases OpenClaw Enterprise Platform for Self-Hosted AI Agents

The OpenClaw Foundation launched OpenClaw Enterprise (OCE) on Wednesday, September 30, in collaboration with OpenAI and Red Hat. The open-source platform provides a multi-tenant control plane, strict isolation boundaries, and standardized primitives for hosting persistent AI agents via Docker Compose or Kubernetes. OpenAI is currently testing the system internally with an agent named Androidclaw to manage build alerts, pull requests, and GitHub issue tracking.

Blanket enterprise bans on public autonomous agent platforms often leave developers reaching for shadow IT solutions. Providing a self-hosted, open-source control plane allows security teams to audit runtime code directly and enforce containerized sandboxing within on-premises or private cloud environments. This gives IT departments a governed architecture to pilot long-running developer agents without exposing internal source code to unvetted third-party runtimes.

Verified across 1 sources: Complete AI Training

Politics, Fact-Checked

American Oversight Sues DHS for Records Behind 250,000 Noncitizen Voter Claims

Following up on the Supreme Court's decision last week restoring state access to the SAVE database, watchdog group American Oversight filed a FOIA lawsuit against the Department of Homeland Security on Wednesday. The suit demands records backing DHS Secretary Markwayne Mullin's claim that 250,000 noncitizens are registered to vote across four states. Disclosed agency letters showed internal reviews flagged fewer than 120,000 potential matches, while county election directors noted that preliminary database comparisons routinely flag legally naturalized citizens.

The dispute highlights operational tensions between federal executive assertions and county-level election administration. Rushed automated list-maintenance checks using federal databases like SAVE frequently generate false positives by matching outdated immigration statuses against recently naturalized voters. Understanding the underlying statistical methodology and legal limitations of these database probes is essential for evaluating voter roll integrity claims ahead of the midterms.

Verified across 2 sources: The Hill · USA Today

Cybersecurity

Cyera and OffSeq Analyze Mir0Auth Phishing Kit Weaponizing Device Code Flows

Adding to the wave of device-code phishing toolkits like N0va and GhostCode we've tracked this month, security researchers from Cyera and OffSeq Radar detailed Mir0Auth on Wednesday. The toolkit targets Microsoft 365 accounts using DocuSign and business lures to trick users into completing legitimate Microsoft Device Code authentication flows. Once authenticated, attackers capture valid OAuth tokens while bypassing MFA and passwords, subsequently dropping second-stage payloads such as ConnectWise ScreenConnect via malicious MSI installers.

Device code phishing remains one of the most effective identity compromise tactics because the initial authentication prompt originates directly from Microsoft's trusted login infrastructure. Because traditional credential-harvesting defenses and basic MFA do not block authorized OAuth device flows, security teams must deploy strict Entra Conditional Access policies to block device code authentication on standard corporate endpoints. Continuous monitoring of high-privilege token grants is required to spot compromised sessions early.

Verified across 2 sources: Cyera · OffSeq Radar

EVs & Charging

Ionna Fast-Charging Network Expands Past 180 Live Stations with App-Free Payment

Yesterday we tracked the Ionna network reaching its 1,526-stall milestone; today, the automaker-backed joint venture provided the operational blueprint behind that expansion. CEO Seth Cutler outlined a strategy that prioritizes 400 kW Alpitronic hardware, app-free payments via Plug & Charge or credit card tap, a maximum base rate of 39 cents per kWh, and site deployments at over 40 Circle K locations.

Ionna's rapid expansion demonstrates that an OEM-backed charging network can scale reliable high-power infrastructure without forcing drivers into proprietary mobile applications. By anchoring sites around existing retail partnerships like Circle K and integrating directly with 19 third-party navigation and payment platforms, the network reduces common payment and reliability friction points for long-distance EV travel.

Verified across 6 sources: The Drive · CNET · Honda News · The Next Web · WardsAuto · Electrek

Science & Space

MED-EL Launches TICI Unico Fully Subcutaneous Cochlear Implant in Europe

Austrian medical manufacturer MED-EL announced on Tuesday, September 29, the European launch of the TICI Unico, the world's first commercially available fully internal cochlear implant. The 20-gram device places all hardware—including the microphone and power supply—under the scalp, providing up to 40 hours of continuous battery life per charge without external headpiece processors.

Housing the entire microphone and signal processing assembly beneath the skin represents a major engineering milestone in bio-integrated medical devices, eliminating external wear barriers during sleep or water exposure. Successful commercial deployment in Europe provides clinical data on subcutaneous acoustic sensing that will drive future regulatory approvals and hardware developments across the global hearing technology sector.

Verified across 2 sources: IEEE Spectrum · Life Science Focus

Consumer Tech Quirks

Google Pixel Owners Report Persistent Intermittent NFC Tap-to-Pay Failures

Reports confirmed on Wednesday, September 30, reveal a persistent software bug affecting Google Pixel devices from the Pixel 8 through the Pixel 11 Pro XL series. The issue causes NFC tap-to-pay transactions in Google Wallet to fail approximately 20% of the time at retail terminals and transit turnstiles, failing to register nearby readers entirely. Standard steps like clearing app cache or unlocking the device fail to resolve the intermittent drops.

Intermittent hardware-adjacent software bugs in mobile payment stacks severely disrupt daily convenience for tech-reliant users, forcing them to carry physical card backups. Because the failure spans multiple hardware generations, the issue likely points to a regression within low-level Play Services or Android NFC driver stacks rather than isolated component defects on newer models.

Verified across 3 sources: Android Police · Trusted Reviews · Android Pure


The Big Picture

Administrative Control Planes Shift Toward Centralized Registries Across Microsoft 365, Purview, and Power Platform, isolated extension mechanisms and classic portals are being replaced by single unified dashboards like the Microsoft Plugin Registry and the modernized Purview DSPM console.

Runtime Tool Inspection Outpaces Static Pre-Deployment AI Audits Enterprise security frameworks like OneTrust CORIE highlight a broader movement toward monitoring autonomous agent tool-calls live in production rather than relying strictly on initial prompt safety checks.

Delegated SaaS Authorization Becomes the Primary Cloud Phishing Vector Threat actors are continuously leveraging legitimate Microsoft device code flows and Graph API channels to execute command-and-control operations without triggering credential-harvesting alerts.

Regional Infrastructure Constraints Force Local Energy and Real Estate Mandates From Massachusetts executive orders governing 25MW+ data center power sourcing to Cambridge office-to-residential conversions, local authorities are stepping in to manage utility and housing pressure.

Public Sector Databases Face Operational Friction in Pre-Election Maintenance Legal actions and local election director feedback demonstrate that deploying federal immigration databases like SAVE right before deadlines carries high error rates and minimal practical impact.

What to Expect

2026-10-13 — Microsoft Office 2021 and Windows Server 2012 ESU main end-of-support deadline.
2026-10-19 — Emily Knight officially assumes office as Boston's next Economic Development Chief.
2026-10-31 — SharePoint One-Time Passcode (OTP) external sharing retirement completes.
2026-11-30 — Microsoft Purview DSPM classic console retirement phase begins.
2027-02-01 — Entra ID SMS and voice multi-factor authentication retirement deadline.

Every story, researched.

Every story verified across multiple sources before publication.

🔍

Scanned

Across multiple search engines and news databases

491
📖

Read in full

Every article opened, read, and evaluated

130
⭐

Published today

Ranked by importance and verified across sources

11

— The Tenant Desk

🎙 Listen as a podcast

Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.

Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste
Overcast
+ button → Add URL → paste
Pocket Casts
Search bar → paste URL
Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
Look for Add by URL or paste into search

Spotify isn’t supported yet — it only lists shows from its own directory. Let us know if you need it there.