Chapter 3 of 6 · Before you start

MCP and tool security

Runtime assurance 3.5 hours in a non-production POC

Chapter 3 of 6

Confirm:

  • An approved nonproduction MCP foundation is in place. It includes a pinned Foundry policy assistant, an APIM-managed GET operation over synthetic policy records with no side effects, the private network paths required by the approved topology, and an API Center metadata update process. The gateway owner checks that GET returns approved fields without changing state; the platform, network, and inventory owners confirm the remaining resources and configurations. (The private-networking, governed-agent, APIM, and API Center inventory controls establish these prerequisites.)
  • The Foundry policy assistant is pinned to a known version.
  • The approved APIM service has a system-assigned identity, an Application Insights logger, a supported tier, and no workspace.
  • The deployment operator has time-bound Contributor on the exact APIM resource group.
  • The agent operator has Foundry User on the exact Foundry project.
  • The existing APIM operation uses GET, validates policyId, returns approved fields, and does not change state.
  • Approved-read and adversarial records exist in the synthetic data set.
  • The Foundry agent identity has the approved MCP app role.
  • The APIM identity has the approved backend role definition at the exact backend scope. That role contains only the Actions or DataActions needed by get_policy.
  • Global and MCP diagnostics set request and response body logging to zero bytes.
  • Release, data, security, tool, identity, APIM, and API program owners are named.
  • The customer permits 2025-09-01-preview for this nonproduction APIM deployment.

Implementation files#

TypeFileConsumer
Deploymentartifacts/apim/main.bicepThe Session 08 APIM deployment scripts
Deploymentartifacts/apim/policies/mcp-policy.xmlThe API Management MCP runtime
Deploymentartifacts/environments/sandbox.jsonThe Session 08 preflight and deployment scripts
Deploymentartifacts/governance/agent-mcp-binding.jsonThe Foundry agent release owner
Recordartifacts/governance/security-evaluation.mdThe security owner running the Foundry candidate-version checks
Recordartifacts/governance/threat-model.mdThe security and identity owners
Runtimeartifacts/operations/mcp-traffic.kqlThe APIM operations owner

Session 08

MCP and tool security slide deck