Existential dread aside, what are you guys doing to throw a lasso around Claude accessing on-prem resources?

Posted by anpr_hunter@reddit | sysadmin | View on Reddit | 50 comments

Title says it all. We've been subjected to a Claude Enterprise rollout at warp speed over the past month, and only now is our leadership realizing that our warnings about carte-blanche UNC and ODBC access were valid, and we are now in a perilously undergoverned situation with our Claude Desktop clients.

We're looking at leveraging Docker at the client and server levels to start funneling all the MCP stuff through chokepoints where we can apply EDR/DLP policies.

This is super, super easy to achieve when you're dealing with Claude interacting with cloud-hosted services with API keys, as many software engineering firms do, but the documentation Github offerings for interactions with on-prem systems - MS SQL, SMB servers - are sparse and immature for enterprise use. We're trying a few things with Docker, MS DAB and other things and making some headway though.

What's your angle of attack?