{"slug": "jumpcloud-agentic-iam-adds-mcp-discovery-govern-ai-agents-now", "title": "JumpCloud Agentic IAM Adds MCP Discovery: Govern AI Agents Now", "summary": "JumpCloud released a September 10 update to its Agentic IAM platform that auto-discovers hidden Model Context Protocol server configurations and routes them through a governed AI Gateway, giving each AI agent a tracked identity that can be audited, restricted, or revoked. The release follows a September 7 UK NCSC warning that organizations \"may struggle to identify and manage\" hidden AI agent risks, and cites figures including 30 CVEs filed against MCP infrastructure in 60 days between January and February 2026, 82% of MCP deployments vulnerable to path traversal, 8.5% using OAuth, and 88% of organizations reporting a suspected or actual AI agent-related security incident in the past 12 months. JumpCloud said a PAM MCP Server will arrive before the end of Q4 2026, positioning auto-discovery against Okta's Agent SSO, which went GA on August 24, and Microsoft Entra Agent ID.", "body_md": "Only 21% of IT teams have any governance controls over AI agents. JumpCloud wants to change that — and its [September 10 update to Agentic IAM](https://www.prnewswire.com/news-releases/jumpcloud-extends-iam-to-protect-the-new-agentic-workforce-302875486.html) makes MCP servers the first target. The platform can now auto-discover hidden Model Context Protocol server configurations across your organization and route them through a governed AI Gateway, treating each one as a real identity that can be audited, restricted, or revoked without touching a single human account.\n\n## The Shadow MCP Problem Nobody Wants to Talk About\n\nShadow IT was a solved problem until AI agents arrived. Now it’s back, worse, and executing code. MCP servers sit on individual laptops, inside AI tool configuration directories, invisible to the security team. The UK NCSC [flagged this on September 7](https://www.ncsc.gov.uk/news/shadow-ai-risk-warning-september-2026) — three days before JumpCloud’s release — warning that organizations “may struggle to identify and manage” hidden AI agent risks.\n\nThe numbers make the concern concrete: 30 CVEs were filed against MCP infrastructure in just 60 days between January and February 2026. Eighty-two percent of MCP deployments are vulnerable to path traversal. Only 8.5% use OAuth. And 88% of organizations have already experienced or suspected an AI agent-related security incident in the past 12 months.\n\nThe real danger isn’t theoretical. An AI agent connected to an unregistered MCP server can invoke database queries, trigger Kubernetes jobs, or open SSH sessions using the same credentials the developer configured at setup. If no one knows the server exists, no one is watching what it does.\n\n## What JumpCloud Shipped\n\nThe September 10 release adds four capabilities to Agentic IAM:\n\n- **Auto-discovery of hidden MCP setups** — JumpCloud scans for MCP server configurations across the organization and routes them through the AI Gateway rather than letting them run unmonitored.\n- **Unique agent identities with instant revocation** — every AI agent gets its own tracked identity. You can cut an agent’s access without locking out the human who deployed it.\n- **Uniform policy enforcement** — the same device trust and access policies that apply to human SaaS access now apply to AI tools, including requiring managed hardware before an agent can run.\n- **AI Gateway** — a central registration point authenticating all agent traffic via OpenID Connect, with full audit logs covering Agent-to-Agent and API flows.\n\nThe PAM MCP Server, arriving before end of Q4 2026, is the one to watch. It replaces shared API keys — still the dominant credential type for agent administrative access — with a zero-setup, per-tenant PAM agent scoped to isolated agent identities. No credential rotation ceremony required.\n\n## How This Stacks Up Against Okta and Microsoft\n\n[Okta went GA with Agent SSO on August 24](https://www.okta.com/newsroom/press-releases/okta-brings-first-class-identity-to-ai-agents-with-agent-sso/), built on the XAA open standard co-authored with Ping Identity. The XAA approach is sound and vendor-neutral, but it requires manual agent registration. JumpCloud’s auto-discovery is the operational advantage: most organizations won’t know they have a shadow MCP problem until something goes wrong, and a platform that finds the agents you didn’t register is more useful than one that only governs the ones you knew about.\n\nMicrosoft Entra Agent ID remains the default for Azure-first organizations, with deep integration into Intune and existing MDM infrastructure. JumpCloud’s cross-platform device trust is the counter — it works across macOS, Linux, and Windows without tying the identity layer to a cloud vendor’s broader ecosystem.\n\nThe competitive split is becoming clearer: Okta and Entra own large enterprise, JumpCloud owns the mid-market and cross-platform shops where AI agent proliferation is moving fastest and governance tooling is thinnest.\n\n## What to Do Before Your IT Team Asks First\n\nThe governance window is closing. Audit your MCP server configurations now — check `~/.config/claude/`, `.cursor/`, and any AI assistant tool config directory. Inventory what tools those servers expose and what credentials they use. Stop using shared API keys for agent access; start issuing scoped, short-lived tokens even if you’re not ready for a full IAM platform.\n\nIf your organization already runs JumpCloud, the [AI Gateway configuration is documented and available today](https://jumpcloud.com/support/configure-the-jumpcloud-mcp-server-for-the-ai-gateway). If you’re evaluating options, the XAA standard is the interoperability play — any platform that implements it (Okta, Ping, and others coming) gives you portability.\n\nThe broader reality: machine identities now outnumber humans 109:1 in the average enterprise, with AI agents accounting for 79 of every 100 machine identities. Only 14.4% of those agents reach production with full security approval. The rest are operating on assumption and trust. That’s not a future problem — it’s already in production.", "url": "https://wpnews.pro/news/jumpcloud-agentic-iam-adds-mcp-discovery-govern-ai-agents-now", "canonical_source": "https://byteiota.com/jumpcloud-agentic-iam-adds-mcp-discovery-govern-ai-agents-now/", "published_at": "2026-09-15 15:07:07+00:00", "updated_at": "2026-09-15 15:19:55.608396+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy", "ai-products", "ai-infrastructure"], "entities": ["JumpCloud", "Agentic IAM", "Model Context Protocol", "UK NCSC", "Okta", "Agent SSO", "Microsoft Entra Agent ID", "PAM MCP Server"], "alternates": {"html": "https://wpnews.pro/news/jumpcloud-agentic-iam-adds-mcp-discovery-govern-ai-agents-now", "markdown": "https://wpnews.pro/news/jumpcloud-agentic-iam-adds-mcp-discovery-govern-ai-agents-now.md", "text": "https://wpnews.pro/news/jumpcloud-agentic-iam-adds-mcp-discovery-govern-ai-agents-now.txt", "jsonld": "https://wpnews.pro/news/jumpcloud-agentic-iam-adds-mcp-discovery-govern-ai-agents-now.jsonld"}}