Join our Newsletter — 33% off our NHI Course

MCP 2025-11-25: are your agent controls ready for year two?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: MCP 2025-11-25 adds first-class Tasks for async work, simplifies OAuth with CIMD, and introduces enterprise-managed access through Cross App Access, while also formalising extensions, M2M OAuth, URL-mode elicitation, and sampling with tools, according to WorkOS. The release turns MCP from a protocol for demos into a governable substrate for agents, tooling, and enterprise identity control.

Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “MCP 2025-11-25 is here: async Tasks, better OAuth, extensions, and a smoother agentic future”.

Key questions

Q: What breaks when MCP access is still handled through ad hoc app-to-app consent?

A: The main failure is governance visibility.

Q: When should organisations prioritise OAuth over simpler authentication for MCP?

A: Organisations should prioritise OAuth when an MCP server can touch user-specific data, production systems, or privileged actions.

Q: How do security teams tell whether MCP client metadata is still trustworthy?

A: Look for stable ownership, controlled hosting, accurate redirect URIs, current signing keys, and consistent fetch behaviour from the authorisation server.

Practitioner guidance

  • Define governance for task handles Classify task handles as governed execution objects and decide which identities can create, resume, observe, or cancel them across long-running workflows.
  • Inventory client metadata trust Review every MCP client metadata endpoint for ownership, hosting controls, redirect URIs, and key rotation so identity metadata cannot drift unnoticed.
  • Move downstream access into IdP policy Use enterprise-managed access paths for MCP where possible so downstream authorisation is enforced through central policy rather than isolated app consent.

Bottom line: MCP 2025-11-25 adds governance primitives that make long-running work, delegated OAuth, and enterprise policy easier to manage in production.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.