The AI plumbing standard powering Claude, Copilot and Cursor just got an enterprise login system — MCP is growing up
The Model Context Protocol team shipped a stable Enterprise-Managed Authorisation extension on 6 July, letting IT departments control which AI agents can connect to internal tools through their existing identity provider instead of per-employee consent prompts — adopted at launch by Anthropic, Microsoft and Okta, and a sign MCP is maturing from developer convenience into enterprise infrastructure worth asking vendors about.
15 July 2026
The Model Context Protocol (MCP) — the open standard, now under the Linux Foundation, that lets AI agents like Claude, Copilot and Cursor connect to external tools and data — reached a new maturity milestone on 6 July. Its Enterprise-Managed Authorisation extension moved to stable status, and it solves a problem that will be familiar to anyone who’s rolled out an AI coding agent to a real team: constant, repetitive consent prompts every time an agent tries to reach a connected server.
Instead of every employee individually approving every MCP server connection, the extension moves that decision into the organisation’s existing identity provider — the same system already governing who can access what elsewhere in the business. Anthropic, Microsoft and Okta backed it at launch, with client support already live in Claude, Claude Code, Cowork and VS Code, and server-side support from tools including Atlassian, Figma, Linear and Supabase. The scale behind this matters too: MCP’s SDK now sees roughly 97 million downloads a month, and by mid-2026 a majority of enterprise AI teams report MCP-backed agents in production somewhere in their stack.
The extension is deliberately scoped — it governs which servers an agent can connect to, not what that agent is allowed to do once it’s in a system. Runtime permissions inside each tool are still a separate control an organisation has to set up. But moving connection-level access into standard enterprise identity management is exactly the kind of unglamorous plumbing that decides whether AI agent adoption stays stuck in individual pilots or becomes something IT is willing to sanction org-wide.
So what
If your organisation is evaluating AI coding or AI product tooling beyond a few early adopters, “does it support enterprise-managed MCP authorisation” is now a fair procurement question — it’s the difference between an agent an IT team can govern properly and one that quietly accumulates access nobody tracked. We build integrations with this kind of enterprise control in mind as standard. See our platform & API work or get in touch to talk through what a properly governed AI-connected system looks like for your business.