What happened
Microsoft's September 2026 Entra update introduced the Global Secure Access MCP Firewall (public preview), which inspects MCP traffic between AI agents and remote MCP servers, discovers shadow MCP servers/tools, and lets admins allow/block specific servers, tools, resources, or prompts and enforce protocol/transport requirements without modifying MCP clients or servers.
Why it matters
Brings enterprise-grade, centrally-managed zero-trust policy enforcement to the MCP layer at a moment when MCP auth-bypass and RCE vulnerabilities (e.g., CVE-2026-59822, CVE-2026-42271) are under active exploitation, giving a major identity vendor's customer base a native mitigation path.
Applicability
Microsoft Entra customers deploying AI agents/MCP integrations should pilot the MCP Firewall preview now to gain shadow-MCP visibility ahead of GA.