As organizations increasingly adopt AI agents, those agents are connecting to external systems, tools, and data through the Model Context Protocol (MCP).
That creates an important security question:
What should an AI agent actually be allowed to access and execute?
Microsoft is addressing this with the new MCP Firewall (Preview) in Microsoft Entra Global Secure Access.
🛡️ What can MCP Firewall control?
Organizations can:
🔹 Allow or block specific MCP servers
🔹 Control access to individual Tools, Resources, and Prompts
🔹 Restrict unsupported or unwanted MCP protocol methods and versions
🔹 Inspect and audit MCP interactions
🔹 Discover MCP servers and tool activity through Generative AI Insights
🔹 Apply identity-aware controls through Global Secure Access security policies
One of the most interesting capabilities is tool-level enforcement.
You could allow access to an MCP server while blocking a particular tool exposed by that server—providing much more granular control than simply allowing or denying the entire MCP connection.
🤖 Why does this matter?
MCP servers can give AI agents access to powerful capabilities—from retrieving enterprise data to performing actions against business systems.
As agentic AI adoption grows, security needs to evolve from:
“Can this agent connect?”
to:
“What can this agent access, which tools can it execute, and under what conditions?”
MCP Firewall brings those controls closer to the Zero Trust model:
🔐 Verify explicitly
🔐 Use least privilege
🔐 Assume breach
⚠️ MCP Firewall is currently in Preview and requires Microsoft Entra Internet Access with TLS inspection for MCP traffic inspection and enforcement.
💡 Bottom line: AI agents need security boundaries just like users and applications. MCP Firewall gives organizations more granular control over how agents interact with MCP servers, tools, resources, and prompts—an important step toward securing the growing world of agentic AI.
