Week of September 28–October 2, 2026 · Sources checked October 2
The announcements kept coming after last week’s roundup. I’m pulling the useful changes together, with the settings, costs and limits that are easy to miss in separate launch posts.
This week, Copilot Studio documents hooks before tool calls. Lovable adds a path for publishing internal apps to Microsoft’s runtime. SharePoint adds PDF edits, version comparisons and Teams notifications. Microsoft starts rolling out a plugin registry. GitHub Copilot can work through desktop apps and run a process you define in code.
My bar stays the same: show me the finished task, the permissions behind it, and the bill. That is how I’d judge the new models too.
This week in 60 seconds
- New models: Sonnet 5.5 and GPT-6.1 Sol reach GitHub Copilot. Wednesday’s Microsoft update starts their Cowork and Copilot Studio rollout.
- Copilot Studio hooks: Run a workflow at a lifecycle event. Check the failure behavior before relying on it to stop an action.
- Lovable: a Microsoft-tenant publishing path. Check the plan and admin setup before building.
- SharePoint: PDF work, file-version comparisons and Teams notifications. Some advanced features consume Copilot Credits.
- Plugins: Admins get a registry for managing capabilities. Copilot Studio support for that registry is still future.
- GitHub Copilot: Desktop computer use and reusable agent workflows enter public preview.
- Admin checks: Review Copilot retention coverage, inherited code-review settings and Purview’s classic DSPM retirement window.
Table of contents
- New models: separate the product, rollout and bill
- Copilot Studio hooks: check the call before it runs
- Lovable apps: who hosts them after the build?
- SharePoint: PDF edits and Teams notifications
- Plugin registry: who can use what?
- GitHub Copilot: desktop apps and repeatable workflows
- Work IQ: ask a business question, then check the records
- Admin dates and settings worth checking
- OpenAI in Teams: check the execution identity
- What I’d check first
New models: separate the product, rollout and bill
September 28–30 · Different products, different rollout stages. Claude Sonnet 5.5 and GPT-6.1 Sol are generally available in GitHub Copilot with gradual rollouts. Your plan determines which you can try.
| Model | Eligible GitHub Copilot plans |
|---|---|
| Claude Sonnet 5.5 | Pro, Pro+, Max, Business, Enterprise |
| GPT-6.1 Sol | Pro+, Max, Business, Enterprise |

The announcements cover the app, CLI, coding agent and supported IDEs, plus GitHub.com and mobile. Business and Enterprise admins should check their model policy: new models can become enabled under the global default.
Wednesday’s update brings them to Cowork and Copilot Studio
Microsoft’s September 30 announcement says both models begin rolling out in Copilot Cowork and Copilot Studio with usage-based billing. Word, Excel, PowerPoint and Chat begin a phased rollout in the coming week under the user subscription license, with limits. Access varies by license and region.
Sonnet 5.5 also became available in Microsoft Foundry on September 28. Check Foundry availability and pricing separately from the Copilot rollout.
GitHub reports fewer tokens and steps in its own tests. Compare the completed change. Give both models the same bug or PCF task, check the result, and compare elapsed time, retries and total credits. An answer that needs fixing still costs you time.
HydraFusion adds another way to compare the work
September 30 · Research preview. HydraFusion expands from CLI into VS Code and the Copilot app. It can select one model, escalate a draft, or have another model family critique it. GitHub lists Pro, Pro+, Business and Enterprise. Business and Enterprise admins must enable preview features. VS Code needs version 1.140 or later, or Insiders.
↑ Back to this week’s contents
Copilot Studio hooks: check the call before it runs
Preview documentation checked October 2 · Agents using the GitHub Copilot harness. Hooks trigger a workflow at a lifecycle event. The agent does not have to decide to call that workflow as a tool.

There are six events: session start, a submitted prompt, an agent error, before a tool runs, successful tool completion, and tool failure. Before a tool runs, a hook can inspect or change arguments and deny the call. Afterward, a hook can adjust the returned result or log it.
If the hook workflow fails, times out or returns an unreadable response, the agent continues. Keep rules that must block unauthorized updates enforced in the underlying service.

For a Dataverse pilot, log an update tool and reject a request that breaks a business rule. Then deliberately break the hook workflow and check the service’s authorization.
↑ Back to this week’s contents
Lovable apps: who hosts them after the build?
September 28 · Lovable integration; Managed Runtime is in public preview. Lovable’s announcement describes packaging an app with Microsoft’s runtime SDK and deploying it into the company’s Microsoft tenant. Microsoft introduced Copilot Managed Runtime on September 25. The runtime also powers apps built in Cowork, Code and Copilot Studio.
Microsoft provides hosting. Entra handles sign-in, and organizational policies govern connectors, data access and endpoints. The SDK and CLI support development, deployment and versioning.

Hosted apps appear in Microsoft 365 admin center → Apps, where admins can review access, usage, health and policy, and enable or disable apps. The host and SDK remain in public preview.
The Lovable setup has specific limits
Lovable’s current setup guide spells out who can build, publish and use these apps:

- Plan and rollout: Lovable Business or Enterprise, with gradual availability. A Microsoft work account and one-time IT tenant setup are required.
- Audience: internal organizational users with Microsoft work sign-in. Public or anonymous access is unavailable.
- Backend: these apps use Microsoft connectors. Lovable Cloud databases, secrets and backend functions are outside this deployment path.
- Identity: building and publishing use the Microsoft account that owns the project’s connection. Published app data access uses each end user’s sign-in.
- Cost: the Lovable plan covers building. Running the app uses your organization’s Microsoft licensing.
IT setup is required. The tenant admin consents to Lovable managed apps and enables Allow external artifact deployment in the target environment group. A Lovable workspace admin controls connector availability; Enterprise defaults to disabled. The setup guide distinguishes published runtime activity, which stays in Microsoft, from project source code and chat history, which stay in Lovable under its workspace settings.
Building the screen is only the start. I’d use a small status app with test data, check access as two different users, deploy a second version and inspect consumption before handing it to a team.
↑ Back to this week’s contents
SharePoint: PDF edits and Teams notifications
October 1 update · General availability rollout started September 30. Copilot in SharePoint’s latest update covers splitting, merging and reordering PDFs, comparing file versions, restoring an earlier version, and building Teams notifications from changes in a library.
Copilot shows the workflow plan before creation. Review the trigger, condition, card fields and Teams destination before selecting Create.

The result is a Teams card with contract fields and a file link. This is a notification workflow. The example does not demonstrate a completed business approval.

Teams workflows require a Microsoft 365 Copilot license and Power Automate access. Advanced Autofill, image generation/editing and site analytics also need Copilot Credits and are rolling out during October. Check that distinction before applying AI processing across a whole library.
My first check would be the generated trigger and condition, followed by the card produced after a file changes.
↑ Back to this week’s contents
Plugin registry: who can use what?
September 30 · Rollout underway. Microsoft’s plugin registry announcement brings skills, connections and agents into a managed catalog. Admins control access under Microsoft 365 admin center → Agents → Tools.

For builders, Work IQ Developer Tools can import supported skills and MCP configurations and package them for Microsoft Copilot. The wiqd plugin commands are in public preview. Each Copilot experience supports its own capabilities; one package does not guarantee identical behavior in every app.

Copilot Studio, GitHub Copilot and Microsoft Foundry support for this registry is still future in the announcement.
Before approving a package, I’d check its instructions, connected systems and allowed users.
↑ Back to this week’s contents
GitHub Copilot can now work through desktop apps
October 1 · Public preview on Windows and macOS. Computer use is available in GitHub Copilot CLI and the Copilot app. It can inspect app content, click, type, scroll and move through a task across applications.
The practical target is a business process stuck in software without an API, command-line interface or MCP tool. GitHub’s demonstration uses an expense-report workflow in Safari.

The feature starts disabled. Turn it on in the app’s Computer Use settings or with /computer on in CLI. App permissions and enterprise policies still apply. GitHub’s documentation describes the risks of fragile interfaces, including wrong or repeated actions.
Check the result in the destination app. The agent saying “done” is not the same as the right record being updated.
Put recurring release checks in a workflow
October 1 · Public preview. Dynamic workflows let you define stages in code and use agents where judgment is needed. They can run checks, work in parallel, pass structured results forward and pause for review.
For a Power Platform pilot, I’d run a PCF build and tests, ask an agent to investigate failures, then pause for a developer to inspect the findings. Save that process and rerun it on the next change.
The preview covers CLI, the app and SDK on all Copilot plans. CLI needs experimental features enabled. Agent, time and credit limits are documented, but the credit limit is approximate. Work already running can exceed it.
↑ Back to this week’s contents
Work IQ: ask a business question, then check the records
Preview follow-through from last Friday. Microsoft scheduled Business Applications in Work IQ to begin rolling out September 30 and continue through October. Last week’s edition covers the announcement; the current documentation explains the supported applications and agent entry points.
For a pilot, ask which customers have an upcoming renewal and an unresolved service issue. Check the answer against the records and the asking user’s permissions. Follow the admin quickstart and review consumption alongside answer quality. Confirm that the preview is available in your environment.
↑ Back to this week’s contents
Admin dates and settings worth checking
Copilot retention: check the policy coverage
Archived notice dated September 28 · Change scheduled for late October through mid-November. The independent reproduction of MC1481313 says some legacy Teams policies that also cover Copilot interactions will become Teams-only.
If you depend on that implicit coverage to retain or delete prompts and responses, inspect the policy and configure the Copilot workload explicitly where required.
Confirm the dates in your Message Center. Microsoft Learn explains policy separation; the independent archive supplies the new change schedule.
Two follow-ups for the admin list
- GitHub code review · Effective September 28. Inherited Default moves from Lite to Balanced for organizations and repositories. Explicit Lite stays. This was announced earlier; inspect the effective setting and consumption on a representative pull request.
- Purview DSPM classic · November 30–December 31. Archived MC1481315 gives the retirement window for DSPM classic and DSPM for AI classic. Confirm it in your Message Center, identify affected workflows and update internal guidance using Microsoft’s task mapping.
↑ Back to this week’s contents
OpenAI in Teams: check the execution identity
September 29 · Enterprise updates. OpenAI’s release notes cover shared recurring team tasks, participation in approved Teams conversations and reusable Codex Cloud environments.
Recurring work runs under a team service account and configured connections. The connected provider account determines access. Check that identity before attaching a task to business data.
Shared cloud environments give coding tasks a prepared workspace. The cloud-environment documentation says browser and computer use are currently unsupported there.
↑ Back to this week’s contents
What I’d check first
- Admin: inspect Copilot retention coverage and inherited GitHub review settings. Neither depends on trying a new model.
- Maker: pick one tool call for a hooks pilot. Test a denied call and a broken hook workflow.
- Builder: run one recurring release check with an explicit review point. Compare a complete task, not a promising transcript.
I want evidence that the work is right, the permissions are right, and the cost is understood. That is what I’ll check before putting any of these features into a business process.
