This week: Microsoft Copilot Studio: Persistent identity for Copilot Studio Agen… + 6 more E8 changes (Mon 5 Oct)
5 October 2026 · 10 changes that matter, 320 reviewed.
- Microsoft Copilot Studio: Persistent identity for Copilot Studio Agents — Copilot Studio agents can now have their own Entra ID accounts, complete with mailboxes and Teams presence. This creates new managed identities requiring governance and security controls, impacting identity and access management. [Restrict Administrative Privileges, Multi-Factor Authentication]
- Dynamics 365 Finance and Operations cross-app: Role-based access controls for ERP agents — Dynamics 365 now allows granular, role-based access controls for ERP agents, enabling administrators to define narrower permissions for agent-initiated requests than for direct user access. This reduces the attack surface when agents interact with sensitive ERP data. [Restrict Administrative Privileges]
- Dynamics 365 Customer Service: Service tools, skills and plugins are now available for Cowork, Code and Scout — Dynamics 365 Customer Service tools are now integrated into Copilot experiences. This allows Copilot agents to access and act on customer service data, potentially increasing data exposure and the attack surface for agentic AI. [Restrict Administrative Privileges]
- Dynamics 365 Contact Center: Out of the box real time translation on digital channels — Dynamics 365 Contact Center now includes out-of-the-box real-time translation for digital channels. This introduces a new third-party translation service, potentially exposing sensitive customer data to an external provider.
- Dynamics 365 Business Central: E-Documents - Exchange EDI documents — Dynamics 365 Business Central now supports Electronic Data Interchange (EDI) for exchanging business documents like orders and invoices. This centralises electronic document management, potentially increasing data flow and integration points with external entities.
- Dynamics 365 Business Central: Copilot and agents - Run data queries with MCP Server — New tools in Dynamics 365 Business Central allow Copilot and agents to run custom data queries against data without existing APIs. This expands data access for AI agents, increasing potential data exposure risks. [Restrict Administrative Privileges]
- Dynamics 365 Business Central: Development - Use AL language intelligence from AI agents and other editors — Dynamics 365 Business Central AL language server can now run independently, enabling AI coding agents and other development environments to use full AL language intelligence without Visual Studio Code. This expands AL development to agentic workflows. [Application Control, Restrict Administrative Privileges]
- Dynamics 365 Business Central: Ecommerce - Keep Shopify connections current — Dynamics 365 Business Central's Shopify connector now supports expiring offline access tokens and uses a newer Shopify API. This enhances security by automatically refreshing tokens and maintaining integration compatibility. [Patch Applications, User Application Hardening]
- Dynamics 365 Business Central: Development - Configure AL MCP workspaces dynamically — Dynamics 365 Business Central AL MCP server can now dynamically load projects at runtime without authentication prompts. This enables headless automation and flexible AI agent sessions, potentially increasing the attack surface for agent identities. [Restrict Administrative Privileges]
- Dynamics 365 Business Central: Development - Debug recorded Business Central failures with an AI agent — Dynamics 365 Business Central now uses an AI agent to debug application failures by recording sessions and collecting snapshots. This automates error capture for developers, potentially exposing sensitive data during debugging.
What we ignored
- Microsoft Outlook: Right-click to customize the classic ribbon — This is a UI customization, not a security-relevant change.
- Power Apps: Modern, refreshed look for embedded model-driven apps — Purely cosmetic UI change, no security relevance.
- Dynamics 365 Commerce: Add items to a transaction from the numpad — Operational feature with no security relevance for Australian government entities.