CIA Brief 20260912

image

Here’s a quick roundup of the latest Microsoft, security and AI news I’ve been tracking this week. As always, I’ve skipped the noise and focused on what actually matters for MSPs and SMBs.

Security
Microsoft 365 & Windows
Cloud & AI

As always, the challenge isn’t finding information — it’s focusing on what actually matters.

After hours

HOT OR COLD? BRAD PITT, 16 DOGS & PERFETTO COFFEE https://www.youtube.com/watch?v=7K13bjG_kJ4

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

Curiosity Is a Professional Strength

image

I have sat in plenty of meetings where everyone seemed to understand a term except me. A new acronym appeared on a slide, heads nodded around the room, and the conversation moved on. For years, the temptation was to stay quiet and work it out later. I did not want to be the person who slowed things down.

Now I see that moment differently. If I do not understand something, there is a fair chance somebody else is equally lost. The difference is that nobody wants to say so.

Questions expose the real work

I have learned that a simple question can be more useful than an impressive answer. “What does that mean in practice?” can uncover assumptions, vague thinking and risks that polished language has hidden.

This matters even more with AI. The vocabulary is arriving faster than most people can absorb it. Agents, grounding, orchestration and retrieval are discussed as if they have always been part of ordinary business conversation. They have not. Pretending otherwise does not make anyone more capable. It only makes the room less honest.

When I am working with Microsoft 365 Copilot, I treat uncertainty as a starting point. If I receive a long technical email in Outlook, I can ask Copilot to explain the unfamiliar concepts in plain language, identify what decisions are being requested and suggest questions I should take back to the sender. That does not replace my judgement. It gives my curiosity somewhere productive to go.

The same approach works in Teams. After a meeting, I might ask Copilot what terms were used without explanation, where the discussion relied on assumptions, or which points need clarification. The value is not in looking clever. The value is in leaving the meeting with fewer gaps hidden behind polite nodding.

Expertise is not knowing everything

The longer I work in technology, the less impressed I am by people who always need to appear certain. Technology is too broad, and it changes too quickly, for anyone to know everything. Real expertise is often visible in the quality of the questions someone asks and in how quickly they can turn an unknown into something useful.

I would rather work with a person who says, “I have not come across that before. Show me how it works,” than someone who fills the silence with confident guesses. The first response creates progress. The second creates risk.

For MSPs, this is especially important. Clients do not need us to perform certainty. They need us to investigate carefully, explain clearly and be honest about what we know. A technician who raises a hand early can prevent hours of rework. A business owner who asks what a Copilot proposal will actually change in the client’s day can stop a shiny but pointless project before it starts.

Curiosity needs practice

I do not think curiosity is a personality trait reserved for naturally inquisitive people. I think it is a professional habit. I can practise it by keeping a short list of things I did not understand during the week, then using Copilot in Word or Loop to explore them, organise my notes and identify what deserves deeper learning.

The goal is not to remove every gap. That is impossible. The goal is to become comfortable enough with the gap to examine it openly.

I no longer see “I don’t know” as an admission of weakness. I see it as the first accurate statement in a useful conversation. What matters is what I do next: ask, test, read, listen and come back with a clearer view.

Knowledge has limits. Curiosity keeps moving.

Is the Next Franchise a Fleet of Humanoid Robots or Robotaxis?

image

I have been thinking about what a franchise might look like ten years from now.

For the past century, the formula has been familiar. You buy the right to operate under an established brand. You lease premises, employ people, follow documented processes and pay the franchisor a fee. The local owner supplies capital and management. The franchise supplies the system.

But what happens when the system no longer needs a shopfront or a large human workforce?

The next franchise may not sell hamburgers, clean offices or deliver parcels. It may involve owning and operating a fleet of humanoid robots or Robotaxis.

From employing people to deploying capacity

Consider the basic economics of a Robotaxi fleet. The owner provides capital, maintains the vehicles, arranges charging, manages insurance and keeps the service operating. The platform provides the software, customer demand, navigation, payments and brand.

That already sounds remarkably like a franchise.

Humanoid robots potentially extend the idea beyond transport. A local operator might own a fleet performing cleaning, warehousing, simple maintenance, stock movement or after-hours inspection. The robots could work across multiple customer sites while the owner manages utilisation, maintenance and service quality.

The valuable asset is no longer necessarily the location. It is the available productive capacity.

I can imagine a future business owner asking, “How many robots should I add this quarter?” in much the same way a transport operator currently considers another vehicle or a traditional franchisee considers opening another location.

Ownership will not mean independence

There is an important catch.

Owning the physical machine does not mean owning the business. The platform controlling bookings, software, identity, updates, safety rules and customer access may hold considerably more power than the fleet owner.

This is where the comparison with today’s digital platforms becomes uncomfortable. You may own the asset, but someone else can change the commercial rules through a software update.

That makes governance critical.

A robot fleet will require more than mechanical maintenance. Every machine will need an identity, permissions, operating boundaries, audit history and a clearly accountable human owner. Organisations will need to know what each machine is authorised to do, what information it can access and when it must stop and ask for approval.

The same questions already apply to AI agents.

The control room will be in Microsoft 365

I suspect much of the day-to-day management will look more familiar than people expect.

A fleet operator might begin the morning by asking Copilot to summarise overnight incidents from Outlook, maintenance reports stored in SharePoint and exceptions discussed in Teams. Planner could surface required inspections. Power Automate could route failures to the appropriate supplier, while Power BI shows utilisation, revenue and downtime across the fleet.

The physical work may be performed by machines, but the management layer will still revolve around information, identity, risk and decisions.

For MSPs, this points to a new type of managed service. Clients may not only need their users, devices and Microsoft 365 environment managed. They may need someone to govern fleets of agents, robots and autonomous vehicles as one connected operational system.

The franchise is becoming a platform relationship

I do not know whether humanoid robots or Robotaxis will become the dominant version first. The technology, regulation and economics still have plenty to prove.

However, I believe the direction is worth watching.

The future small-business owner may employ fewer people directly while controlling far more productive capacity. Their competitive advantage will come from choosing the right platform, managing risk, maintaining utilisation and protecting customer trust.

The franchise of the future may not have a counter, a uniform or even a front door.

It may have a charging depot, a Microsoft 365 tenant and a dashboard full of machines waiting for their next job.

The transition from labour-priced services towards automated capacity, governance and outcome-based offerings also aligns with the strategic direction examined in 20260902-Cowork-Fable-51.

Wealth Starts as a Way of Thinking

image

I have met plenty of people who earn good money and still feel poor. Every decision is made from fear. Every new idea is dismissed because it might fail. Every purchase is supposed to prove something to somebody else. The bank balance may look healthy, but the thinking behind it remains fragile.

I have also met people with modest means who are already building something valuable. They are curious. They learn. They delay easy rewards. They see a problem and ask what it can teach them. Their financial position may not have caught up yet, but their direction is clear.

The first asset is how I think

Long before income grows, I believe a person has to become comfortable with creating value. That means looking beyond the next invoice or pay cheque and asking better questions.

What do I know that solves a real problem? What can I learn that makes my work more useful? Where am I wasting time because I have never challenged the process? Which relationships deserve more attention?

I see this in technology all the time. Two businesses can buy the same Microsoft 365 licences and get completely different results. One treats the subscription as another monthly cost. The other uses it to improve how knowledge is captured, decisions are made and customers are served.

The technology is identical. The thinking is not.

Better tools should produce better judgement

Copilot is a good example. I can use Copilot in Outlook to make an email sound polished, then move straight to the next message. That saves a few minutes. Useful, but limited.

Or I can ask Copilot to summarise a long client thread, identify the unresolved concerns, and help me see where my communication created confusion. Now I am not merely processing email faster. I am improving how I communicate and how I make decisions.

The same applies in Teams. After a meeting, I can use Copilot to revisit the discussion and examine where assumptions replaced evidence. I can take those lessons into the next client conversation. Over time, that compounds.

I do not become more valuable because I possess an AI licence. I become more valuable when I use that tool to sharpen my judgement.

Mental wealth compounds quietly

A stronger financial position is usually visible. Better thinking often is not.

No one sees the Saturday morning spent learning a new capability. No one applauds the decision to document a repeatable process in SharePoint rather than keeping it in my head. There is no instant reward for asking Copilot to challenge a business plan in Word before I commit money to it.

But those small choices alter what happens next. I make fewer avoidable mistakes. I spot opportunities earlier. I become more useful to clients. I create systems that keep working when I am tired, distracted or away from the office.

That is where the real compounding begins.

Money can increase my options, but it cannot create discipline, curiosity or judgement for me. Those have to be built first. If they are missing, more money often makes the weakness larger. If they are present, even limited resources can be used intelligently.

I have come to believe that financial progress is often a delayed reflection of internal progress. The visible result arrives later.

So I am less interested in looking successful and more interested in becoming capable. I want better questions, sounder habits, stronger systems and clearer decisions. The bank account is important, but it is a lagging indicator.

The real work starts much earlier, in the way I choose to think.

CIAOPS Need to Know Microsoft 365 Webinar – September

laptop-eyes-technology-computer_thumb

Now in our tenth year!

Join me for the free monthly CIAOPS Need to Know webinar. Along with all the Microsoft Cloud news we’ll be taking a look at implementing Local AI

Shortly after registering you should receive an automated email from Microsoft Teams confirming your registration, including all the event details as well as a calendar invite.

You can register for the regular monthly webinar here:

September Registrations

(If you are having issues with the above link copy and paste – https://bit.ly/n2k2609)

The details are:

CIAOPS Need to Know Webinar – September 2026
Friday 2nd of October 2026
11.00am – 12.00am Sydney Time

All sessions are recorded and posted to the CIAOPS Youtube channel.

Also feel free at any stage to email me directly via director@ciaops.com with your webinar topic suggestions.

I’d also appreciate you sharing information about this webinar with anyone you feel may benefit from the session and I look forward to seeing you there.

There’s No Such Thing as "Ready"

image

I’ve lost count of how many times a business owner has told me they’ll bring Copilot in “once we’re ready”. They mean it kindly. They want their data tidy, their policies signed off, their people trained, their SharePoint folders renamed from Final_v3_actual_final. And then they wait. Months pass. The readiness never quite arrives, because readiness isn’t a destination. It’s a story we tell ourselves to justify not starting.

Nobody learns to swim by reading about water. You learn by getting in, going under a little, and coming up knowing something you didn’t know before you got wet.

Confidence Is a Result, Not a Prerequisite

The people I see getting real value from Copilot didn’t feel ready either. They just opened Outlook one busy Tuesday, hit the Copilot button, and asked it to draft a reply to a client email they’d been avoiding. The draft wasn’t perfect. They fixed it. Next time it was faster. That small, slightly awkward first attempt taught them more than any rollout plan ever could.

Waiting to feel confident before you start gets the order backwards. Confidence is what you earn after you’ve fumbled through the first few goes. Ask Copilot in Teams to summarise a meeting you half-missed, and yes, the first summary might skate over the thing that actually mattered. So you learn to prompt it better. That’s not failure. That’s the lesson doing its job.

Small Goes Under, Not a Deep End

Drowning a little every day doesn’t mean throwing your team off the boat. It means deliberate, survivable exposure. Pick one repetitive task this week and hand it to Copilot. Draft the weekly client update in Word. Ask Copilot in Excel to explain what’s driving the number in a spreadsheet you inherited and never fully understood. Have it pull the three key points out of a forty-message channel in Teams before your Monday catch-up.

None of these are bet-the-business moments. Each one is a small go under the surface. Some will work beautifully and some will come back wrong — and the wrong ones are where the real learning lives, because they teach you where the tool’s edges are and where your own judgement still has to sit on top.

The businesses that stall are the ones treating adoption like a single, perfect dive that has to be flawless. The ones that get somewhere treat it like laps. A bit every day. Slightly uncomfortable. Steadily better.

The Water Was Never Going to Be Warm

Here’s the part nobody wants to hear: it never feels comfortable at the start, and that discomfort is not a signal to wait. It’s the signal you’ve finally begun. The team that’s “not ready” but using Copilot daily is six months ahead of the team that’s still perfecting its readiness checklist — because they’ve been quietly getting better the whole time the other one was preparing.

You don’t need clean data to draft an email. You don’t need a governance framework to summarise a document. You need a task, a first attempt, and the willingness to be a bit rubbish at it for a week.

What I’m watching now is how quickly the gap widens between the businesses that started imperfectly and the ones still waiting to feel ready. My honest read? The water’s fine. Get in.

You’ll Likely Fail… and That’s Okay

image

A few weeks ago I sat with a business owner who’d been quietly avoiding Copilot for months. Not because he doubted it — because he was worried he’d look foolish in front of his own team. He’d typed one clumsy prompt, got a mediocre answer, and decided the whole thing wasn’t for him. I told him the honest truth: your first attempt was always going to be a bit rubbish. Mine were too. That’s not the exception. That’s the process.

We’ve built up this strange expectation that new tools should work perfectly the moment we touch them. AI has made it worse, because the demos look so slick. So when reality delivers a bland summary or a reply that misses the mark, people don’t think I need to adjust — they think this doesn’t work. And then they stop.

Getting It Wrong Is the Point

Here’s what I’ve noticed working with people on Copilot. The ones who get value fastest aren’t the smartest or the most technical. They’re the ones willing to look a little silly while they learn. They’ll ask Copilot in Outlook to draft a reply, read it, wince, and then say “no, make it shorter and less formal.” That second and third pass is where the magic actually happens. The first prompt is just you clearing your throat.

I watched someone ask Copilot in Word to pull together a proposal from three older documents. The first version was a mess — it grabbed the wrong figures and buried the point. Instead of giving up, she told it exactly what was wrong. Ninety seconds later she had something genuinely usable. If she’d walked away after attempt one, she’d have told everyone Copilot “couldn’t do proposals.” Instead she’d learned how to steer it.

Small, Low-Stakes Failures

The trick is choosing where you’re allowed to get it wrong. Don’t stake your reputation on a board paper for your first go. Start somewhere forgiving. Ask Copilot in Teams to catch you up on a meeting you missed and see how close it lands. Have it summarise a long email thread in Outlook before you reply. If it’s off, you’ve lost nothing and learned how it thinks. These little experiments cost you a minute and quietly build the instinct you’ll lean on later.

What surprised me most is how quickly that instinct transfers. Once you’ve learned to nudge Copilot in Excel toward the right analysis, you already know how to nudge it in PowerPoint, or in a Loop page, or anywhere else. The skill isn’t the tool. The skill is being comfortable with the first answer not being the final one.

Give Yourself Permission

So I’d offer the same thing I offered that business owner. Give yourself permission to be a beginner again. Expect the early attempts to disappoint you. Treat each poor result as a clue, not a verdict. The people falling behind right now aren’t the ones failing — they’re the ones so afraid of failing that they never start.

I’m watching this play out across dozens of businesses, and the pattern is consistent. Comfort with imperfection is becoming its own competitive advantage. The willingness to fumble, adjust, and try again is quietly separating the people who’ll thrive with these tools from the people who’ll keep waiting for them to be “ready.” They already are. The question is whether you are.

Why GitHub Copilot Doesn’t Belong Inside Microsoft 365 Copilot

image

The other day I was asked a question that sounds sensible on the surface.

“If GitHub Copilot is so good, why not just build it directly into Microsoft 365 Copilot for everyone?”

At first glance it feels like the logical next step. One Copilot. One interface. One AI assistant for everything.

The more I think about it though, the more I believe that would be a mistake.

The reason comes down to something that AI vendors often overlook. Different people work in very different ways.

A software developer spends their day creating, testing and refining code. A finance manager lives in spreadsheets. A salesperson works across emails, meetings and CRM records. An executive spends much of their time making decisions based on information coming from multiple sources.

Those aren’t variations of the same job. They’re fundamentally different disciplines.

The Context Is More Important Than The AI

What makes GitHub Copilot valuable isn’t simply that it can generate code.

It’s that it understands the environment a developer works within.

It sits inside development tools. It understands repositories. It helps navigate large codebases. It assists with testing, debugging and software creation workflows. The value comes from the context surrounding the AI.

Microsoft 365 Copilot has a completely different context.

When I ask Copilot in Outlook to draft a response, or use Copilot in Teams to summarise a meeting, the AI is working with conversations, documents, calendars and organisational knowledge. It is focused on helping people communicate, collaborate and make decisions.

Trying to merge these two worlds into a single experience risks making both less useful.

A productivity worker doesn’t need a sophisticated coding assistant appearing in every interaction. In the same way, a developer probably doesn’t want meeting summaries and document drafting cluttering up their coding environment.

Specialisation Usually Wins

We’ve seen this pattern before.

Nobody expects Excel to become Visual Studio.

Nobody asks Word to become a network troubleshooting platform.

Microsoft succeeds because its tools are specialised while still working together.

I think AI will follow the same path.

GitHub Copilot should continue evolving as the specialist assistant for software creation. Microsoft 365 Copilot should remain focused on helping knowledge workers get through meetings, emails, documents and decision-making processes faster.

The mistake many organisations make is assuming every AI capability needs to be available to every employee.

In reality, most people only need the capabilities that relate directly to their role.

Adding more functionality doesn’t automatically create more value. Sometimes it just creates more complexity.

The Real Opportunity Is Connection

Where I do see value is in integration.

Imagine a project manager using Microsoft 365 Copilot to prepare for a software review meeting. The assistant could pull summaries of development activity from GitHub.

A developer could use GitHub Copilot to understand changes in a repository while still accessing relevant business context from Microsoft 365.

That’s very different from forcing both experiences into a single product.

The future isn’t one giant AI assistant trying to do everything.

It’s a collection of specialised agents and copilots that share information when necessary while remaining focused on their primary role.

We’re already starting to see this approach emerge across Microsoft’s ecosystem.

Keep The Tool Sharp

One lesson I’ve learned over many years working with Microsoft technologies is that the best tools are usually the ones with a clear purpose.

A hammer becomes less useful once you start turning it into a screwdriver, a saw and a wrench at the same time.

The same principle applies to AI.

GitHub Copilot should remain the coding expert. Microsoft 365 Copilot should remain the productivity expert.

The goal shouldn’t be to squeeze every AI capability into a single interface. The goal should be to put the right assistant in front of the right person at the right time.

That’s where the real productivity gains will come from.