Microsoft Tackles Shadow AI with MCP Firewall
Microsoft has introduced its MCP Firewall as part of its Global Secure Access suite. The firewall is currently in Public Preview and sits directly in the path of communication between an AI agent and its broader ecosystem of tools and servers.
This marks the fourth layer in Microsoft's emerging governance stack, joining Okta Agent SSO, IBM AgentOps, and Broadcom AgentMinder. While Entra Agent ID handles registration, lifecycle, and conditional access for agents themselves, the firewall controls which specific tools, prompt templates, or protocol versions an agent is permitted to use.
The practical utility of this development lies in discovery, where many organizations are grappling with the shadow AI problem, unauthorized or unmonitored MCP servers integrated into workflows without IT oversight. The firewall provides a default-deny option to force a 'known-good' environment where shadow servers and tools can be identified and blocked before interacting with sensitive data.