Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Convene: Boston | Cybersecurity & Human Risk Conference Aug 13 - 14, 2026

How to Secure AI Agents and MCP Servers

Solution Category IAM
Type Webinar
Organization Oasis Security
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Focuses on identity and access management challenges specific to AI agents and MCP servers
  • Addresses the security gap between traffic routing and identity verification in agentic systems
  • Covers least-privilege and just-in-time access strategies for autonomous AI workloads
  • Designed for IAM, InfoSec, and security professionals deploying AI agents in production

Introduction

As organisations accelerate their adoption of AI agents and Model Context Protocol servers, security teams face a growing challenge: these autonomous systems often operate with persistent credentials that fall outside traditional identity governance frameworks. This session examines how to apply established identity and access management principles to agentic AI workloads, addressing a gap that many enterprises are only beginning to recognise.

About This Event

This one-hour virtual session takes place on 29 July 2026 and is structured around the practical realities of securing AI agents in enterprise environments. Rather than theoretical frameworks, the discussion centres on operational scenarios where AI agents and MCP servers have been deployed—often without formal security review—and now require proper governance.

The Identity Gap in Agentic AI Systems

AI agents present a fundamentally different security challenge compared to traditional service accounts or human users. These systems act autonomously, making decisions and accessing resources on behalf of users or processes. The session explores a critical distinction that many organisations overlook: while an MCP gateway can route and secure traffic between agents and backend systems, it cannot inherently verify the identity of the agent itself or determine whether that agent should possess its current credentials.

This creates a visibility problem. Security teams accustomed to asking basic questions about any identity—who authorised this access, what systems can it reach, when does this permission expire—often find these questions unanswerable when applied to AI agents. Standing credentials assigned during initial deployment may persist indefinitely, owned by no individual and subject to no rotation policy.

Applying Least-Privilege Principles to Autonomous Systems

The session addresses how organisations can extend least-privilege and just-in-time access models to AI agents. Traditional approaches assume a human or well-defined service requesting access, but agents operate continuously and may require dynamic permissions based on their current task. Eliminating standing credentials—access that remains available whether or not it is actively needed—reduces the attack surface significantly.

Participants will examine strategies for ensuring that AI agents request and receive only the permissions necessary for their immediate function, with access that expires automatically rather than persisting until manually revoked.

Who Should Attend

This session is designed for identity and access management professionals, information security teams, and security architects responsible for AI agent deployments. It assumes familiarity with core IAM concepts and addresses practitioners who are actively working to bring agentic systems under proper security governance. Those grappling with specific access control challenges in their own AI implementations are encouraged to bring detailed questions for discussion.