Last week the super app started rolling out and Agent Plugins 1.0 shipped as a cross-platform standard. This week the focus shifts to the surfaces and infrastructure around that standard — the CLI becoming a genuine agent runtime, Copilot Studio maturing into a multi-harness enterprise agent platform, a critical consumer-side vulnerability patched server-side, and a model deprecation deadline hitting September 1 with no grace period.
For IT leaders, this week is about operationalizing what was announced: governing plugins across surfaces, securing the expanded attack surface, preparing for model churn, and understanding that the CLI is now an agent runtime deserving the same governance as any development tool.
1. GitHub Copilot CLI: A Real Agent Runtime
The CLI has moved from a coding assistant to a legitimate agent surface. The August releases added session management, safety nets, and orchestration primitives that make it viable for both interactive development and CI/CD automation.
Concurrent sessions with a sidebar for parallel agent workstreams. Session forks for branching without losing the original. /worktree for isolated speculative changes. /rewind without Git restores state and files Copilot changed while preserving your edits. /tasks for subagent management. Queued prompts for stacking instructions during active turns. Headless plan-then-implement combines --plan with --mode autopilot for one-pass CI/CD automation. Air-gapped GHES support and live tool-call durations round out the enterprise additions.
What this means for IT leaders: The CLI is an agent runtime now. Apply managed settings, MCP allowlists, credit caps via --max-ai-credits, and audit logging. The headless mode is pipeline-ready but needs cost governance.
2. Copilot Studio: Three Harnesses GA, Multi-Tenant Preview
Copilot Studio is maturing from a chatbot builder into an enterprise agent platform. Three harnesses are now generally available: Copilot Chat for customized chat experiences, Standard for conversational agents, and GitHub Copilot harness for complex agentic business processes requiring advanced reasoning and multi-step execution. The GitHub Copilot harness reaching GA is the significant one — it brings Copilot’s agentic execution loop into Studio agents.
Entra Agent ID is now mandatory — every new agent automatically receives one, with no environment-level opt-out. Multi-tenant agent management is in public preview in the M365 Admin Center, letting administrators manage agents across multiple tenants from one experience. Coming in September: Evaluations improvements with reasoning traces and run comparison, plus Copilot Apps in Canvas (preview) for interactive React-based app experiences.
What this means for IT leaders: The harness model means execution architecture is now a design decision. The GitHub Copilot harness opens Studio to genuinely complex workflows — but agents can take actions, not just generate text. Entra Agent ID being mandatory means every agent is an identity. Govern accordingly.
3. CoSnitch Vulnerability: Patched, but Lessons Remain
A critical vulnerability in Copilot Personal (consumer) was disclosed and patched August 18. Varonis Threat Labs demonstrated that a single crafted link could invoke a hidden URL parameter to make Copilot exfiltrate data from connected accounts — Gmail, Google Drive — without user confirmation. A poisoned-memory variant persisted even through password resets and device re-enrollment.
CVE-2026-24301 — CVSS 8.8. Scope: consumer Copilot only, not enterprise M365 Copilot. Microsoft deployed a server-side patch with no client update required. No evidence of pre-patch exploitation.
This is the third disclosed Copilot vulnerability in eight months. The pattern is clear: Copilot’s expanding attack surface demands active security management. SharePoint permissions remain the number one enterprise exposure vector — Copilot inherits permissions from over-shared sites. Restricted SharePoint Search is dead (blocked July 31); its replacement is Restricted Content Discovery, applied per site.
Purview DLP for external web search is now GA — preventing sensitive information from reaching search engines via Copilot prompts. Configure it immediately if you have not already.
Action items: Confirm the CoSnitch patch for Copilot Personal users. Review OAuth connections. Set up monthly Copilot security reviews. Audit SharePoint permissions. Deploy sensitivity labels and Purview Audit (Premium) into your SIEM.
4. Copilot Connectors: Unified Management and Self-Serve Arrivals
Connector management is now consolidated in the M365 Admin Center under Copilot → Connectors, covering both connectors and plugins from one page.
Self-serve sync connectors for Jira Cloud and Confluence Cloud enter preview this week. Users connect their own accounts with their own credentials — enabled by default, scoping to Entra groups available. Federated connectors (MCP-based) for Canva, HubSpot, Intercom, Linear, Notion, and others fetch data in real time without indexing into Graph. New industry connectors added for financial services (FactSet, Morningstar, PitchBook, S&P Global), healthcare (Article Galaxy, Nyquist AI), and cross-industry (CB Insights). Dataverse is now native grounding in Copilot Studio.
What this means for IT leaders: Self-serve connectors are on by default — decide your policy before preview lands. If you are building custom connectors, build them as MCP servers. The federated model eliminates indexing latency but shifts query load to source systems.
5. Model Churn: September 1 Deadline
Six models retire September 1 across GitHub Copilot: Gemini 3.1 Pro, Claude Opus 4.5/4.6, Claude Sonnet 4.5/4.6, and Raptor Mini. MAI-Code-1-Flash deprecates September 10. Pinned configurations and CI workflows referencing these models will break. Claude Sonnet 5 introductory pricing also ends September 1 — standard pricing ($3/$15 per million tokens) replaces $2/$10.
New August arrivals: Grok 4.6 (xAI), Gemini 3.7 Flash, MAI-Code-1.1-Flash, and Kimi K3 (1M token context). In M365 Copilot, GPT-5.6 (Sol/Terra/Luna) and Claude Sonnet 5 / Opus 5 / Fable 5 all entered the platform with a true model selector.
Promotional credit allowances drop sharply September 1: Business from 3,000 to 1,900 credits/seat (37% reduction), Enterprise from 7,000 to 3,900 credits (44% reduction). A 100-seat Business org loses 110,000 pooled credits monthly.
What this means for IT leaders: Audit pinned model configurations today. Enable replacement models before the deadline. Re-evaluate credit budgets — the reduction is permanent. The default-on model policy means new GA models auto-enable for Business and Enterprise orgs; if you wanted individual approval workflows, the August 26 opt-out deadline has already passed.
6. Copilot Cowork and App Updates
Copilot Cowork gains event-based scheduling, upload-your-own plugins, skill sharing, and new partners (Adobe, Canva, Miro, monday.com, Moody’s, S&P Global). The Copilot app shows which model handled each request with credit details. VS Code 1.132–1.133 adds element-level browser feedback and Claude BYOK switching within a session. PowerPoint skills as SKILL.md in OneDrive introduces a file-backed skill pattern — author, save, share. Copilot in Outlook now reasons over the entire inbox and calendar instead of a single thread.
7. Licensing and Partner Notes
FY27 CSP promotions: M365 Copilot at 15% off on 300+ licenses, 30% off on 1,000+. Copilot in 30 — partner-led 30-day trial with industry prompts, through December 31 (Product ID: CFQ7TTC0MM8R). Copilot Studio P3 pre-purchase plan offers tiered discounts. A 5% CSP uplift on monthly-billed annual subscriptions takes effect October 1. Microsoft Ignite 2026: November 17–20, registration open.
8. Cancelled and Walked-Back Items
Interactive Agents for Teams Meetings — cancelled August 17. Domain exclusion for M365 Copilot — rolled back. =COPILOT Excel function — cancelled. Copilot spending alerts — wiped by a Cost Management update; recreate them.
Strategic Next Steps
- Audit model selections — replacements must be enabled before September 1.
- Re-evaluate credit budgets — promotional allowances drop 37–44% on September 1.
- Configure CLI governance — managed settings, MCP allowlists,
--max-ai-creditsfor CI/CD. - Run a Copilot security review — monthly recurring. Audit SharePoint, verify Purview DLP, review OAuth.
- Decide on self-serve connector policy — Jira and Confluence are enabled by default.
- Choose harnesses per agent — execution architecture is now a design decision.
- Plan for Ignite — November 17–20 will reshape the roadmap again.
The story this week is about the infrastructure between the headlines. Agent Plugins 1.0 and the super app were the announcements; the CLI becoming an agent runtime, Copilot Studio getting real harnesses, connectors unifying, and security demanding ongoing attention — that is the operational reality. For IT leaders, the work is not in adopting the announcements but in governing the surfaces they create.
Follow along at https://x.com/kkaminsk for daily Copilot and Microsoft AI analysis.