TrustSink is an attack technique that abuses Microsoft Entra ID’s federated trust model by using a rogue MFA provider to intercept user credentials during legitimate login attempts.
Microsoft has delayed its plan to enable usage-based billing by default for new Microsoft 365 Copilot Business subscriptions purchased through the Cloud Solution Provider (CSP) program.