Microsoft's latest push to manage Copilot agent extensibility leads today's edition of The Tenant Desk, accompanied by critical security guidance on passkey vishing campaigns and non-human identity risks. We are also following opening arguments at the Supreme Court in a landmark climate preemption case and new power recovery quirks on recent iPhones.
Technical analysis published on Sunday details how AI agents using application-only tokens or OAuth 2.0 On-Behalf-Of (OBO) delegation can inadvertently fetch unauthorized data when manipulated by prompt injection. When middle-tier APIs rely solely on model-supplied identifiers or application authority rather than validating user-level entitlements at the resource layer, an attacker can trick the agent into requesting data belonging to another user. Recommended mitigations mandate enforcing strict object-level access control directly at backend resource endpoints.
Why it matters
Relying on downstream agent tokens for authorization creates severe data exposure risks in multi-tenant environments when prompt injection alters model intent. This analysis demonstrates why identity boundaries must be validated explicitly by the target API rather than trusted through the agent's context. Architects designing custom agentic harnesses must implement rigid zero-trust token inspection on every backend tool call.
As the October 25 default enablement deadline we've been tracking for custom agent uploads approaches, Microsoft's October 2026 update for Microsoft 365 Copilot introduces centralized chat interfaces across Teams and Outlook, general availability for Copilot in SharePoint and OneDrive, and new asynchronous background tasks for PowerPoint skills. Additionally, new FinOps features allow administrators to enforce model-choice governance and granular spending caps across enterprise tenants.
Why it matters
The October 25 default configuration shift requires immediate review in regulated tenants to prevent unvetted custom agent packages from bypassing internal review gates. For technical consultants, setting up model-choice governance allows organizations to balance high-cost frontier model queries against standard operational requirements. Failure to review agent upload permissions before the deadline could expose tenant boundaries to unmanaged third-party extensibility.
Microsoft announced Message Center notice MC1486284, extending Microsoft Entra Administrative Units (AUs) support to Data Loss Prevention (DLP) policies targeting Microsoft Copilot and Copilot Chat. Rolling out between late October and early November 2026, the update enables localized compliance teams to create, edit, and manage Copilot DLP rules scoped specifically to their assigned users. Scope evaluation depends directly on the initiating user's directory membership rather than file storage locations, while tenant-wide policies remain unaffected.
Why it matters
Decentralized compliance management allows regional business units and regulated subsidiaries to enforce localized AI safety policies without requiring Global Administrator access. Because policy scoping evaluates user identity during prompt execution, establishing clean Administrative Unit memberships in Entra ID is a mandatory prerequisite. Consultants advising multi-national tenants must verify directory scoping rules ahead of the late October rollout to prevent policy coverage gaps.
The U.S. Supreme Court opened its new term on Monday, October 5, hearing oral arguments in Suncor Energy v. Boulder. The case centers on whether federal law and the Clean Air Act preempt state-level tort claims brought by the City and County of Boulder seeking monetary damages from fossil fuel companies for local climate impacts. Suncor and Exxon Mobil, supported by an amicus brief from the Trump administration, contend that allowing municipal state-court suits disrupts federal energy regulation, while Boulder argues the lawsuit addresses deceptive trade practices and local infrastructure costs.
Why it matters
The outcome of this high-court battle will determine whether local governments can use state courts to hold energy producers financially accountable for climate adaptation expenditures. A ruling favoring the energy companies would effectively dismiss over 30 similar municipal lawsuits nationwide, leaving climate resilience costs entirely on local taxpayers. Conversely, a victory for Boulder would establish state tort law as a viable mechanism for municipal cost recovery.
Five Democratic governors—from California, Oregon, Maine, New Mexico, and Virginia—sent a joint letter to HHS Secretary Robert F. Kennedy Jr. requesting a postponement of the January 1, 2027, compliance deadline for Medicaid expansion work rules. The regulations mandate that non-pregnant adults ages 19 to 64 document 80 monthly hours of work or community engagement, or prove earnings of $580 per month. The governors cite early pilot data from Nebraska showing that the vast majority of coverage terminations resulted from unreturned administrative paperwork rather than employment ineligibility.
Why it matters
The impending work-reporting requirements expose lower-income workers to administrative coverage gaps caused by state IT processing delays and rigid documentation channels. For working families relying on Medicaid expansion, managing monthly paperwork requirements poses a direct risk of losing healthcare access despite meeting employment thresholds. State agencies and advocacy groups face a narrow window to establish simplified reporting interfaces before disenrollments begin.
Guardz security research team launched EntraReaper on Sunday, an open-source autonomous red-teaming platform that operates as a Model Context Protocol (MCP) server connecting Claude Code to 238 AADInternals PowerShell cmdlets. The tool wraps these cmdlets into 65 specialized functions across 87 attack scenarios to simulate complex threat vectors against Microsoft Entra ID and Microsoft 365. In baseline testing, an unauthenticated AI reconnaissance run mapped tenant attack surfaces in 25 minutes by identifying compound risks such as implicit OAuth grants and exposed device authorization endpoints.
Why it matters
The combination of LLM reasoning engines with administrative PowerShell toolkits dramatically lowers the execution barrier for automated identity attacks. For enterprise administrators, EntraReaper provides a mechanism to test tenant defenses against autonomous privilege escalation pathways before adversaries exploit them. Security teams should use these automated recon tools to identify and close legacy implicit grants and unmonitored device code endpoints.
Expanding on the passkey-themed vishing attacks we've tracked from the threat group 'Pink', Okta researchers disclosed new details Monday on the campaign's enrollment mechanics. Attackers contact employees directly and manipulate them into interacting with panel-controlled phishing sites that mirror Microsoft Entra ID passkey registration interfaces. By persuading targets to register an attacker-controlled authenticator during the live phone call, the group successfully plants rogue passkeys directly into victim accounts across the healthcare, technology, and automotive sectors.
Why it matters
This campaign illustrates how threat actors bypass passwordless protections by compromising the initial identity enrollment workflow rather than attempting token theft. Standard multi-factor authentication controls are ineffective if users are tricked into authorizing attacker devices during provisioning. Organizations deploying passkeys must implement out-of-band verification steps for enrollment and update help-desk verification protocols.
Security analysts at Guardz published technical details on Monday regarding Mir0Auth, a specialized phishing kit that abuses Microsoft Entra ID device authorization flows. The toolkit uses XOR-encoded C2 traffic to bypass perimeter security filters and tricks users into authenticating secondary devices. Telemetry shows attackers establishing rogue device persistence within 93 seconds of user approval, generating long-lived refresh tokens that bypass standard login prompts. Guardz recommends implementing Conditional Access policies that explicitly restrict device code flows to authorized hardware.
Why it matters
Device code phishing exploits legitimate OAuth mechanisms intended for smart TVs and headless hardware, allowing attackers to initiate sessions on genuine Microsoft sign-in pages without raising initial domain alerts. Because token issuance occurs without triggering typical IP anomaly thresholds, traditional perimeter monitoring misses the session hijacking. Tenant administrators should disable device code flow for general users via Entra Conditional Access unless strictly required by specialized hardware.
Tesla introduced a software update (2026.38.3) on Monday featuring an 'Emergency Drive Away' function for vehicles in the United States. The feature enables drivers stopped at Supercharger stalls to shift directly into Drive, prompting an on-screen confirmation that automatically unlatches and drops the fast-charging cable. Tesla Charging Director Max de Zegher noted the capability is designed for urgent safety departures, though improper activation while actively pulling high current risks connector damage and financial penalties.
Why it matters
Providing a software override to physically release locked DC fast-charging cables addresses driver safety concerns regarding potential perimeter threats at public charging stations. Managing emergency physical disengagements via software highlights how software control layers interact with high-voltage physical charging infrastructure. Network operators and automakers must balance immediate user security against equipment damage risks during automated unlatching.
The MBTA and the City of Boston activated an automated bus lane and stop camera enforcement program on Monday, using optical sensors to issue warnings to drivers blocking dedicated bus corridors ahead of formal fines starting in January. Concurrently, Mayor Michelle Wu submitted a proposal to the City Council offering $31.5 million in property tax abatements over 10 years to unlock four stalled residential construction projects across Charlestown, Allston, and Brighton, aiming to deliver 1,400 new housing units.
Why it matters
Combining transit corridor enforcement with targeted tax incentives directly targets two of Boston's primary economic bottlenecks: commute reliability and housing supply. Optical enforcement on bus routes increases public transit speed and throughput for working commuters. Meanwhile, offering municipal tax abatements provides the capital margin necessary for developers to resume construction on stalled middle-income housing projects.
Owners of iPhone 17 models and the iPhone Air are encountering a power-management bug where devices fail to boot or accept wired charging after the battery fully drains to zero percent. Affected units display a black screen and remain unresponsive to standard power adapters. A community-sourced workaround confirms that placing the unresponsive device on an inductive MagSafe or Qi wireless charger for 10 to 15 minutes restores basic voltage thresholds, enabling the phone to resume standard wired charging.
Why it matters
Firmware oversights that prevent power management ICs from initiating wired charging recovery from a fully depleted state turn standard battery drains into temporary device failures. For technical family members or IT help desks troubleshooting unbootable devices, utilizing wireless charging pads provides an immediate hardware-free recovery method. Apple is expected to address the bootstrap heuristic oversight in an upcoming iOS point release.
Agent Token Delegation Creates Complex Authorization Boundaries As autonomous AI agents execute middle-tier API calls using OAuth On-Behalf-Of flows, identity verification shifts from user authentication to object-level access validation at the resource layer.
Passkey Rollouts Face Target Phishing and Vishing Disruptions Threat actors are actively adapting social engineering and vishing tactics to manipulate human users during passkey enrollment, attempting to subvert passwordless adoption milestones.
Federal Preemption Battles Target Municipal Civil Litigation High-court challenges surrounding local authority over environmental damages and noncitizen voting rules test the constitutional boundaries between state-level torts and federal jurisdiction.
Administrative Reporting Mandates Risk Service Disruptions for Low-Income Enrollees Upcoming work-verification requirements across Medicaid expansion populations highlight how rigid paperwork channels can disconnect eligible households from social safety nets.
Automated Software Recovery Addresses Physical Hardware Edge Cases Automakers and hardware vendors are deploying software overrides and inductive power routines to mitigate physical disconnects and unbootable power states.