Your AI Agents Can Now Talk to the Internet on Their Own — Microsoft Just Added a Firewall for That

Microsoft Entra Global Secure Access MCP Firewall — control over AI agent traffic
Back to Blog

If your business has started experimenting with AI agents — Copilot Studio bots, custom assistants, anything that can "go fetch" data or trigger actions on its own — there's a new kind of traffic quietly moving through your network that your existing security tools were never built to see. Microsoft has just shipped a fix for exactly that gap: the Global Secure Access MCP Firewall.

It sounds technical. The problem it solves is actually pretty simple to understand.

What's an "MCP," and why does it need a firewall?

MCP stands for Model Context Protocol — think of it as the connector standard that lets AI agents plug into outside tools and data sources. When your AI assistant looks something up, pulls a file, or triggers an action in another system, there's a good chance it's talking to something over MCP behind the scenes.

The problem is that this traffic is new, it's growing fast, and until now, most organisations had almost no visibility into it. An employee could connect a Copilot agent to some random third-party MCP server they found online, and IT would have no idea it happened — no log, no approval, no way to say no.

Security teams have started calling this "Shadow MCP." It's the AI-era version of the old Shadow IT problem, except this time the thing quietly connecting to unapproved services can also take actions on your data.

What Microsoft's new MCP Firewall actually does

The MCP Firewall sits inside Microsoft Entra's Global Secure Access platform and gives security teams a proper layer of control over this traffic, without needing to touch every AI agent or tool individually:

  • Discover shadow MCP activity — see which MCP servers and tools are actually being used across your organisation, including ones nobody approved.
  • Allow or block specific servers and tools — instead of an all-or-nothing approach, you can permit the AI tools your business actually needs and block the rest.
  • Enforce protocol and transport rules — make sure MCP traffic is happening the way it's supposed to, closing off sloppy or outdated implementations that are easier to abuse.

The genuinely useful part is that all of this works without modifying the AI agents, tools, or servers themselves — it's enforced at the network layer, so you're not depending on every app vendor to build in the right security controls.

Why this should matter to you, even if you're not "deep" into AI yet

You don't need a company full of AI engineers for this to be relevant. If even one team is using Copilot Studio, testing an AI assistant, or connecting ChatGPT-style tools to internal data, that traffic already exists — whether IT signed off on it or not.

And unlike a rogue browser extension or an unapproved SaaS app, an AI agent with the wrong permissions doesn't just leak data by accident. It can be tricked into doing it, through techniques like prompt injection, where a malicious instruction hidden in a document or webpage manipulates the agent into taking an action it shouldn't.

Having visibility and control over this traffic isn't a "nice to have" anymore — it's quickly becoming as basic as knowing which apps are allowed to touch your company email.

What to do about it

  1. Find out if anyone in your organisation is already using AI agents or Copilot Studio — you may be further along than you think.
  2. Turn on visibility first. Before blocking anything, understand what MCP traffic already exists in your environment.
  3. Set an approval process for which MCP servers and tools are sanctioned, the same way you'd approve any other third-party integration.
  4. Treat this as part of your existing security posture, not a separate AI project — it plugs into the same Zero Trust and Conditional Access setup most businesses already have some pieces of.

The takeaway

AI adoption is moving faster than most companies' security policies. This is one of the first tools that actually closes that gap instead of just warning you about it.

Not sure what AI tools are already connecting to your network? AW InfraSec can assess your environment, set up Global Secure Access, and help you get ahead of Shadow AI before it becomes a real problem.

Source: Microsoft — "What's new in Microsoft Entra: September 2026," Microsoft Entra Tech Community Blog.

Ready to Get Free Consultations?

Partner with AW InfraSec for adaptive Microsoft Cloud and Security strategies that fuel your business growth.

Or reach us directly at sales.support@awinfracloud.com
+91-742-866-9270