{"type":"post","slug":"enterprise-managed-auth-narrows-agent-connector-permissions","title":"Enterprise-managed auth narrows agent connector permissions","description":"Claude Enterprise admins can now authorize MCP connectors once through an identity provider, so users inherit connector access from IdP groups instead of granting it themselves.","retrieval_nugget":"Claude Enterprise admins can now authorize MCP connectors once through an identity provider, so users inherit connector access from IdP groups instead of granting it themselves.","published_at":"2026-08-30","updated_at":"2026-09-12","record_date":"2026-06-18","date_kind":"published_at","topics":["agent-security","agents","ai","mcp","security"],"entities":["Claude"],"source_url":"https://claude.com/blog/enterprise-managed-auth","source_title":"Centrally manage authorization for MCP connectors","source_domain":"claude.com","source_terms":["Enterprise-managed","auth","narrows","connector","permissions"],"summary_word_count":191,"schema_version":"newruntime-agent-readable-v0.2","stable_id":"post:enterprise-managed-auth-narrows-agent-connector-permissions","status":"published","source_urls":["https://claude.com/blog/enterprise-managed-auth"],"visuals":[],"editorial_provenance":{"schema_version":"newruntime-editorial-copy-v1","content_status":"source_grounded_final","final_copy_sha256":"sha256:470fc3d7e2e76e71071af9fe53ff098accc317f78fb1cb39783beb9baf4d0138","reviewed_at":"2026-09-12T10:00:00Z","source_evidence_count":1,"verified_claim_count":2,"site_analysis_schema_version":"newruntime-site-analysis-v1","site_object_kind":"field_note","observed_fact_count":2,"implication_count":1,"watch_condition_count":1,"related_record_count":3},"analysis":{"schema_version":"newruntime-site-analysis-v1","object_kind":"field_note","thesis":"Anthropic made enterprise-managed authorization generally available for MCP connectors: an admin provisions a connector for the whole organization through the identity provider, starting with Okta, and users get access automatically on first login.","observed_facts":[{"text":"Admins can provision MCP connectors organization-wide through their identity provider, starting with Okta.","source_urls":["https://claude.com/blog/enterprise-managed-auth"]},{"text":"Enterprise-managed authorization is generally available and supports Datadog, Notion and Slack in addition to Asana, Atlassian, Canva, Figma, Granola, Linear and Supabase.","source_urls":["https://claude.com/blog/enterprise-managed-auth"]}],"mechanism":"Previously an admin enabled a connector for the organization and then every individual user authorized it themselves; now the admin authorizes once and users inherit access through the IdP groups and roles they already hold, which Anthropic describes as zero-touch setup for the end user.","why_now":"The August update lists Datadog, Notion and Slack as supported, with Exa, Miro and Zoom named as coming, alongside existing support for Asana, Atlassian, Canva, Figma, Granola, Linear and Supabase.","implications":["The authorization decision therefore moves from the person using the agent to the directory that already describes what that person may reach."],"evidence_boundary":"The announcement covers provisioning and supported applications, not what a connector may do once granted or how revocation propagates.","watch_conditions":["The condition to watch is whether inherited access publishes a per-connector scope and an audit trail, because inheriting a connector from a directory group is only safe if the group's reach is legible."],"related_records":[{"url":"https://newruntime.com/posts/agent-operations-are-converging-on-connectors-memory-observability-dashboard","relation":"Prior coverage of the control plane forming around agent operations."},{"url":"https://newruntime.com/posts/chaindrop-agent-identity-control-plane","relation":"Prior coverage of identity as the starting point for agent security."},{"url":"https://newruntime.com/topics/mcp","relation":"Topic hub for connector and protocol governance."}]},"routes":{"html":"https://newruntime.com/posts/enterprise-managed-auth-narrows-agent-connector-permissions/","markdown":"https://newruntime.com/posts/enterprise-managed-auth-narrows-agent-connector-permissions.md","json":"https://newruntime.com/posts/enterprise-managed-auth-narrows-agent-connector-permissions.json"}}
