cd /news/ai-agents/jumpcloud-agentic-iam-adds-mcp-disco… · home topics ai-agents article
[ARTICLE · art-130355] src=byteiota.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

JumpCloud Agentic IAM Adds MCP Discovery: Govern AI Agents Now

JumpCloud released a September 10 update to its Agentic IAM platform that auto-discovers hidden Model Context Protocol server configurations and routes them through a governed AI Gateway, giving each AI agent a tracked identity that can be audited, restricted, or revoked. The release follows a September 7 UK NCSC warning that organizations "may struggle to identify and manage" hidden AI agent risks, and cites figures including 30 CVEs filed against MCP infrastructure in 60 days between January and February 2026, 82% of MCP deployments vulnerable to path traversal, 8.5% using OAuth, and 88% of organizations reporting a suspected or actual AI agent-related security incident in the past 12 months. JumpCloud said a PAM MCP Server will arrive before the end of Q4 2026, positioning auto-discovery against Okta's Agent SSO, which went GA on August 24, and Microsoft Entra Agent ID.

read4 min views3 publishedSep 15, 2026
JumpCloud Agentic IAM Adds MCP Discovery: Govern AI Agents Now
Image: Byteiota (auto-discovered)

Only 21% of IT teams have any governance controls over AI agents. JumpCloud wants to change that — and its September 10 update to Agentic IAM makes MCP servers the first target. The platform can now auto-discover hidden Model Context Protocol server configurations across your organization and route them through a governed AI Gateway, treating each one as a real identity that can be audited, restricted, or revoked without touching a single human account.

The Shadow MCP Problem Nobody Wants to Talk About #

Shadow IT was a solved problem until AI agents arrived. Now it’s back, worse, and executing code. MCP servers sit on individual laptops, inside AI tool configuration directories, invisible to the security team. The UK NCSC flagged this on September 7 — three days before JumpCloud’s release — warning that organizations “may struggle to identify and manage” hidden AI agent risks.

The numbers make the concern concrete: 30 CVEs were filed against MCP infrastructure in just 60 days between January and February 2026. Eighty-two percent of MCP deployments are vulnerable to path traversal. Only 8.5% use OAuth. And 88% of organizations have already experienced or suspected an AI agent-related security incident in the past 12 months.

The real danger isn’t theoretical. An AI agent connected to an unregistered MCP server can invoke database queries, trigger Kubernetes jobs, or open SSH sessions using the same credentials the developer configured at setup. If no one knows the server exists, no one is watching what it does.

What JumpCloud Shipped #

The September 10 release adds four capabilities to Agentic IAM:

  • Auto-discovery of hidden MCP setups — JumpCloud scans for MCP server configurations across the organization and routes them through the AI Gateway rather than letting them run unmonitored.
  • Unique agent identities with instant revocation — every AI agent gets its own tracked identity. You can cut an agent’s access without locking out the human who deployed it.
  • Uniform policy enforcement — the same device trust and access policies that apply to human SaaS access now apply to AI tools, including requiring managed hardware before an agent can run.
  • AI Gateway — a central registration point authenticating all agent traffic via OpenID Connect, with full audit logs covering Agent-to-Agent and API flows.

The PAM MCP Server, arriving before end of Q4 2026, is the one to watch. It replaces shared API keys — still the dominant credential type for agent administrative access — with a zero-setup, per-tenant PAM agent scoped to isolated agent identities. No credential rotation ceremony required.

How This Stacks Up Against Okta and Microsoft #

Okta went GA with Agent SSO on August 24, built on the XAA open standard co-authored with Ping Identity. The XAA approach is sound and vendor-neutral, but it requires manual agent registration. JumpCloud’s auto-discovery is the operational advantage: most organizations won’t know they have a shadow MCP problem until something goes wrong, and a platform that finds the agents you didn’t register is more useful than one that only governs the ones you knew about.

Microsoft Entra Agent ID remains the default for Azure-first organizations, with deep integration into Intune and existing MDM infrastructure. JumpCloud’s cross-platform device trust is the counter — it works across macOS, Linux, and Windows without tying the identity layer to a cloud vendor’s broader ecosystem.

The competitive split is becoming clearer: Okta and Entra own large enterprise, JumpCloud owns the mid-market and cross-platform shops where AI agent proliferation is moving fastest and governance tooling is thinnest.

What to Do Before Your IT Team Asks First #

The governance window is closing. Audit your MCP server configurations now — check ~/.config/claude/, .cursor/, and any AI assistant tool config directory. Inventory what tools those servers expose and what credentials they use. Stop using shared API keys for agent access; start issuing scoped, short-lived tokens even if you’re not ready for a full IAM platform.

If your organization already runs JumpCloud, the AI Gateway configuration is documented and available today. If you’re evaluating options, the XAA standard is the interoperability play — any platform that implements it (Okta, Ping, and others coming) gives you portability. The broader reality: machine identities now outnumber humans 109:1 in the average enterprise, with AI agents accounting for 79 of every 100 machine identities. Only 14.4% of those agents reach production with full security approval. The rest are operating on assumption and trust. That’s not a future problem — it’s already in production.

── more in #ai-agents 4 stories · sorted by recency
── more on @jumpcloud 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/jumpcloud-agentic-ia…] indexed:0 read:4min 2026-09-15 ·