![]()
Here’s a quick roundup of the latest Microsoft, security and AI news I’ve been tracking this week. As always, I’ve skipped the noise and focused on what actually matters for MSPs and SMBs.
Security
- Passkey-themed social engineering leads to identity and cloud compromise
Microsoft has identified attacks where threat actors use passkey-related lures to gain access to cloud environments and establish long-term persistence. Good reminder that stronger authentication alone is not enough. User awareness, conditional access policies and monitoring for suspicious identity activity still matter just as much.
https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ - Threat Matrix: Mapping threats across cloud web applications
Microsoft has released a new threat matrix designed to help organisations better understand attacks targeting cloud-hosted web applications and services. Worth a look if you’re responsible for application security because it provides a structured way to assess risks, identify gaps and prioritise protections across cloud workloads.
https://www.microsoft.com/en-us/security/blog/2026/09/09/threat-matrix-mapping-threats-across-cloud-web-applications/ - Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft examined a business email compromise campaign that used AI-generated content, executive impersonation and fake invoices to target finance teams. Good reminder that the biggest risk isn’t the technology itself, but how convincingly it can be used to exploit existing business processes and payment approval workflows.
https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/
Microsoft 365 & Windows
- 7 Features It’s Not Too Late to Try Out This Year
Microsoft has highlighted several recently released capabilities across Microsoft 365 applications that many users may have overlooked. Nothing groundbreaking, but it’s a useful reminder that customers often pay for features they never adopt. MSPs should be helping users discover and use the tools already included in their subscriptions.
https://techcommunity.microsoft.com/blog/microsoft365insiderblog/7-features-it%E2%80%99s-not-too-late-to-try-out-this-year/4553099 - Take Control of Your EWSAllowedAppIDs List Before EWS Access Changes
Microsoft has provided additional guidance around managing the EWSAllowedAppIDs allow list as Exchange Web Services continues its journey toward deprecation. This one matters. MSPs should identify applications still dependent on EWS now rather than discovering the dependency after access changes impact production workloads.
https://techcommunity.microsoft.com/blog/exchange/take-control-of-your-ewsallowedappids-list-before-ews-access-changes/4553534
Cloud & AI
- OpenAI GPT-6 Astra Now Available in Microsoft 365
OpenAI’s GPT-6 Astra model is now being made available within Microsoft Copilot and Copilot Studio experiences. The model itself will grab headlines, but the bigger question for SMBs remains whether their data, permissions and business processes are ready to take advantage of stronger AI capabilities.
https://techcommunity.microsoft.com/blog/Microsoft365CopilotBlog/available-today-openai-gpt-6-astra-in-microsoft-copilot/4552808 - Azure Copilot Announces General Availability of the Troubleshooting Agent
Microsoft has announced general availability of the Azure Copilot Troubleshooting Agent, designed to help administrators diagnose and resolve Azure issues more efficiently. Still early, but anything that helps reduce time spent tracking down cloud problems could deliver real value for MSPs managing multiple customer environments.
https://techcommunity.microsoft.com/blog/appsonazureblog/azure-copilot-announces-general-availability-of-the-troubleshooting-agent/4554549
As always, the challenge isn’t finding information — it’s focusing on what actually matters.
After hours
HOT OR COLD? BRAD PITT, 16 DOGS & PERFETTO COFFEE – https://www.youtube.com/watch?v=7K13bjG_kJ4
Editorial
If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.
If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.
Watch out for the next CIA Brief next week