MCP Endpoint Security Controls - blatant avenue for data loss!

Posted by cananyonehelpmoi@reddit | sysadmin | View on Reddit | 18 comments

So, we have recently started using Claude AI with a group of test users and have found a pretty glaring security hole with how the MCP connector works, allowing users unfettered access from personal devices to their company M365 data.

We have CA policies in place to grant access only from hybrid/compliant devices.

At the moment, our group of test users can sign in to their personal Claude account on their work laptops, then setup and authenticate their M365 connector.

They can then log in to their personal Claude account on a personal device and access the M365 connector/data from that device.

From what I can gather, the only way to prevent this happening is to block access to Claude personal accounts on the company devices.

Anyone got other ideas?