microsoft / microsoft/mcp

[Initiative] 🛡️ Security, Identity & Governance

Open
#3,106 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
C#
Stars
3.7k
Forks
624
Avg merge
2d 20h
Merged PRs (30d)
220

Description

## Problem statement

Azure MCP Server connects agents to Azure resources across local and remote environments. Authentication, authorization, secret handling, dependency integrity, multi-user isolation, and enterprise governance must evolve continuously as the product adds tools, transports, and deployment models.

## Vision

Azure MCP Server is secure by default, preserves user identity and least-privilege access, exposes clear trust boundaries, and gives administrators consistent controls for governing how agents access Azure resources.

## Who this helps

- **Users and administrators** can deploy Azure MCP Server with clear, least-privilege security and governance controls.
- **Remote service operators** can safely support concurrent users and on-behalf-of authorization.
- **Toolset authors** can follow consistent authentication, validation, policy, and secret-handling patterns.
- **Maintainers** can identify and remediate security or compliance risks before release.

## Goals (in scope)

- Strengthen authentication and authorization across supported deployment modes
- Improve identity propagation, isolation, input validation, secret handling, and sensitive-data protections
- Establish consistent governance, policy, auditability, and compliance guidance
- Reduce software supply-chain and dependency risk
- Establish security testing, review, telemetry, and response practices

## Non-goals (out of scope)

- Replacing Azure RBAC, Azure Policy, or host-provided identity controls
- Granting broader permissions to simplify tool behavior
- Tracking confidential vulnerability details in a public issue

## Success criteria

- [ ] Security, identity, and governance workstreams are represented by linked child issues with owners
- [ ] Supported deployment modes have documented trust boundaries and least-privilege guidance
- [ ] Administrators have clear controls and audit signals for governing Azure access
- [ ] Security-sensitive changes have appropriate automated and manual validation
- [ ] Identified risks have explicit remediation or accepted-risk decisions

## Dependencies

- Microsoft identity platform, Azure RBAC, and Azure governance capabilities
- Security review, compliance, and incident-response processes
- Coordination with remote hosting, packaging, and service toolset owners

Contributor guide

Open the contributing guide

Research direction

Start with this issue's goals, non-goals, success criteria, and dependencies, then decompose the security, identity, and governance work into linked child issues with owners. Done means supported deployment modes have trust-boundary and least-privilege guidance, administrators have governance controls and audit signals, security-sensitive changes are validated, and risks have remediation or accepted-risk decisions.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, csharp
Domain
authentication, authorization, cloud, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.