← back
Building Protected MCP Servers — Den Delimarsky and Julia Kasper, MCP Steering Committee & Microsoft
Takeaway
Remote MCP servers should sit behind a proper identity provider with OAuth/PKCE and per-tool scopes — treat them like any other protected enterprise API.
Summary
- MCP Steering Committee members Den Delimarsky and Julia Kasper (Microsoft Azure API Management) cover authorization for remote MCP servers.
- Remote MCP servers must propagate user identity to downstream APIs because permissions vary by user (admin vs contributor exposes different tools).
- Recommend OAuth 2.0 flows with PKCE, identity provider integration, and scoping per-tool access — local binary servers don't need this layer.
- Demo using Azure API Management as a policy layer in front of MCP servers for auth, throttling, and routing.
mcpsecurityazure
Original description
Join us to see how VS Code and GitHub Copilot's expanding suite of AI features can match or even surpasses the benefits of other popular AI developer tools. We'll focus on practical scenarios to ensure immediate applicability and work through live demos of Copilot features such as: Code generation using Edits, Planning/problem solving using Chat, Inline terminal command generation, Boilerplate code generation using Agent mode, Improving boilerplate with custom instructions and then refactoring using Agent mode and Edits, Improving test generation and code reviews with custom instructions, as well as an Introduction to MCP. About Den Delimarsky I am a Principal Product Engineer, currently working at Microsoft, where I help build developer tools and AI-powered experiences that make engineers more productive. You can learn more @ den.dev/about. About Julia Kasper Julia Kasper is a member of the Microsoft Developer Division focusing on the developer experience for the Microsoft Power Platform. She is passionate about scenarios where you extend the Power Platform with Azure services and have the best possible end-to-end experience. Recorded at the AI Engineer World's Fair in San Francisco. Stay up to date on our upcoming events and content by joining our newsletter here: https://www.ai.engineer/newsletter