AGENTRY.NEWSWhat AI Agents Do, Documented.October 8, 2026

Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.

Microsoft hardens Agent Framework with MCP security fixes

By
Agentry Newsroom
Published

Microsoft released Agent Framework Python 1.19.0 and .NET 1.22.0 on September 18, 2026, introducing security hardening for model context protocol (MCP) sessions and new vector-database connectors for production agent deployments.

MCP Security Tightening

The .NET release implemented per-invocation session scoping for provider-backed MCP sessions, according to official release records. This change, contributed by Microsoft engineer Jose Alvarez (@jpalvarezl), restricts MCP skill archives to ZIP files only and adds identity and ownership checks for MCP requests. The security tightening addresses isolation between agent invocations, preventing session data leakage across separate execution contexts.

Vector-Store Connectors Expand

The Python release added alpha vector-store connectors for MongoDB and Azure Cosmos DB for NoSQL, enabling developers to integrate real-world NoSQL databases with agent memory and retrieval systems. These connectors allow agents to persist and query embeddings in production environments without requiring separate vector database infrastructure.

The releases represent incremental hardening of the Agent Framework's core runtime, targeting the infrastructure layer where agent isolation and data persistence are critical. MCP, Microsoft's open protocol for connecting agents to external systems and skills, has become a central integration point for enterprise deployments—making session-scoping and access controls material to operational security.

Developer Adoption Context

The timing follows months of Agent Framework adoption among enterprise teams building autonomous workflows. The September releases maintain Microsoft's quarterly update cadence for the framework, which has grown to include integrations with Azure AI services, Azure SQL, and third-party LLM providers. The per-invocation session scoping eliminates a class of cross-request contamination risks that arise when agents handle sensitive customer data or financial transactions in multi-tenant environments.

Neither the Python nor .NET releases shipped breaking changes to existing SDK APIs, allowing current users to adopt the security improvements without refactoring production code. Developers building agents that require vector-backed retrieval can now choose between MongoDB for document-centric architectures and Cosmos DB for globally distributed deployments.

Del dette opslag: