Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

MCP tunnels and enterprise access control: what changes now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20377
Topic starter  

TL;DR: Anthropic MCP Tunnels invert the traditional network exposure model by letting internal systems reach out to Claude, while Stacklok adds the policy, segmentation, and orchestration layer needed to make MCP usable in production. The real issue is not connectivity but governance: tool scope, identity controls, and observability must move with the tunnel, or AI access simply recreates old risk in a new path.

NHIMG editorial — based on content published by Stacklok: Stacklok and Anthropic MCP Tunnels securely connect Claude to everything behind your firewall

By the numbers:

Questions worth separating out

Q: How should security teams govern managed MCP access for AI clients?

A: Security teams should treat managed MCP as a federated resource server and issue identity-bound tokens for each delegated task.

Q: Why do MCP tunnels still require IAM and NHI controls?

A: MCP tunnels solve the connectivity problem, but they do not decide who can reach which tools or how long that access should remain valid.

Q: What breaks when AI platform access is managed like ordinary user access?

A: What breaks is the assumption that access is stable, human-owned, and easy to review in a later cycle.

Practitioner guidance

  • Define MCP server ownership and approval boundaries Assign every MCP server to a named system owner, then require approval for any new tool exposure, group membership change, or external AI surface connection.
  • Segment tool access by role and purpose Use group-based segmentation to ensure engineering, marketing, and shared AI users see only the MCP tools required for their function.
  • Review tunnel access as a privileged pathway Treat the tunnel endpoint as a privileged access route and apply the same scrutiny you would use for service accounts, delegated admin paths, and other NHI entry points.

What's in the full article

Stacklok's full blog post covers the operational detail this post intentionally leaves for the source:

  • Exact deployment flow for the tunnel endpoint, including Docker Compose and Helm-based setup
  • How Stacklok's virtual MCP server model segments tools by group and maps to identity policy
  • Details on how Anthropic's Toolbox client handles MCP calls across Claude surfaces
  • Production considerations for moving from local experiments to monitored Kubernetes deployments

👉 Read Stacklok's blog post on Anthropic MCP Tunnels and enterprise tool access →

MCP tunnels and enterprise access control: what changes now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19968
 

Identity boundary control is now the real MCP governance problem. The tunnel changes where the connection starts, but it does not change the enterprise obligation to decide which identities can invoke which tools and under what purpose. That means MCP governance sits squarely inside IAM, PAM, and NHI lifecycle discipline, not just network engineering. Practitioners should treat every MCP endpoint as an identity-controlled interface, not a convenience layer.

A few things that frame the scale:

  • 53% of MCP servers expose credentials through hard-coded values in configuration files, according to the State of MCP Server Security 2025.
  • Only 18% of MCP server deployments implement any form of access scoping for tool permissions, which means tool governance is still the exception rather than the norm.

A question worth separating out:

Q: Who should own lifecycle reviews for MCP-connected AI tools?

A: The business or platform owner responsible for the underlying tool should own lifecycle reviews, with identity and security teams enforcing the process. That review should confirm the connector still serves a valid purpose, still needs the same scope, and still maps to a current group membership. If not, access should be removed or reduced.

👉 Read our full editorial: MCP tunnels shift AI access control behind the firewall



   
ReplyQuote
Share: