cd /news/ai-agents/microsoft-entra-agent-id-expands-wit… · home topics ai-agents article
[ARTICLE · art-132879] src=forkast.news ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Microsoft Entra Agent ID Expands with MCP Firewall, Adding Network-Level Control to Agent Governance

Microsoft expanded its Entra Agent ID governance framework with the MCP Firewall, a new Global Secure Access component now in Public Preview that enforces Zero Trust policies on Model Context Protocol traffic between AI agents and their tools and servers. The firewall adds network-level, default-deny control on top of Entra Agent ID, which reached general availability in April 2026, and joins Okta Agent SSO, IBM AgentOps, and Broadcom AgentMinder in an emerging four-layer agent governance stack. Microsoft says the tool targets shadow AI by blocking unauthorized MCP servers, though security teams must manage granular per-method policies that could break complex agent workflows if misconfigured.

by read2 min views1 publishedSep 17, 2026
Microsoft Entra Agent ID Expands with MCP Firewall, Adding Network-Level Control to Agent Governance
Image: Forkast (auto-discovered)

As AI agents move from experimental sandboxes into enterprise production, the challenge of keeping them on a short leash has become a primary focus for security teams. Microsoft is now expanding its governance framework with the introduction of the MCP Firewall, a new component of its Global Secure Access suite. While the industry is still finding its footing, this move signals a shift toward treating AI agent traffic with the same rigor as traditional network requests.

The MCP Firewall, which is currently in Public Preview, acts as a policy boundary between an AI agent and its broader ecosystem of tools and servers. It is important to note that this is not yet a generally available product; it is a testing-phase tool designed to provide centralized visibility and runtime protection for Model Context Protocol (MCP) traffic. By sitting directly in the path of communication, it allows organizations to enforce Zero Trust policies on the specific methods and resources an agent attempts to access.

This development arrives as the fourth layer in an emerging governance stack, joining existing solutions like Okta Agent SSO, IBM AgentOps, and Broadcom AgentMinder. The goal is to move beyond simple identity management. While Microsoft Entra Agent ID – which reached general availability in April 2026 – handles the registration, lifecycle, and conditional access for the agents themselves, the firewall addresses the ‘what’ of the interaction. It controls which specific tools, prompt templates, or protocol versions an agent is permitted to use.

The practical utility here lies in discovery. Many organizations are currently grappling with the shadow AI problem, where unauthorized or unmonitored MCP servers are integrated into workflows without IT oversight. The firewall provides a default-deny option, effectively forcing a ‘known-good’ environment where shadow servers and tools can be identified and blocked before they interact with sensitive data.

However, the transition from identity to network-level control introduces new operational friction. Security teams must now manage granular policies for individual MCP methods, which could potentially break complex agent workflows if not configured correctly. The Public Preview status suggests that Microsoft is still refining how these policies scale across large, distributed agent deployments.

The broader context is a race to standardize how agents interact with the enterprise. By linking Agent ID’s identity-based controls with the firewall’s network-level enforcement, Microsoft is attempting to close the loop on agent security. This dual-layer approach is a direct response to the reality that an agent’s identity is only as secure as the tools it is allowed to call.

As these governance layers continue to mature, the focus will likely shift toward interoperability. With four distinct governance layers now competing for space in the enterprise stack, the challenge for IT leaders will be integrating these tools without creating a fragmented security posture. For now, the MCP Firewall offers a necessary, if early-stage, mechanism to bring order to the chaotic growth of agentic tool usage.

── more in #ai-agents 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/microsoft-entra-agen…] indexed:0 read:2min 2026-09-17 ·