Home icon

Understanding IAM for Managed AWS MCP Servers

Security Blog



This article explains how to use IAM to govern AI agent access through AWS-managed Model Context Protocol (MCP) servers with standardized security controls.

  • Two new IAM context keys enable differentiation between AI and human-driven actions
  • aws:ViaAWSMCPService (boolean) allows denying all MCP-initiated actions organization-wide
  • aws:CalledViaAWSMCP (string) restricts actions to specific MCP servers like EKS or ECS
  • Simplified authorization model eliminates need for separate MCP-specific IAM actions
  • VPC endpoint support coming soon for private network communication in regulated industries
  • Defense-in-depth approach combines network perimeter and service-level IAM controls
  • Start with restrictive policies and monitor CloudTrail logs to refine access over time

AWS-managed MCP servers now integrate with existing IAM policies, allowing organizations to secure AI workflows while maintaining flexibility for governance and compliance requirements.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 5
2026
The AWS MCP Server now supports cross-account and cross-role access
Aug 22
2025
Announcing the AWS Billing and Cost Management MCP server
Aug 22
2025
AWS Announces Billing and Cost Management MCP Server
Jul 16
2025
AWS API MCP Server now available

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.