Session
Trust No Agent: Security and Governance for SQL Server 2025's MCP Server
SQL Server 2025 ships with a native MCP server: a purpose-built interface that lets AI agents and LLM-powered tools query your databases directly. Transformative for AI-driven workflows. Also a new attack surface that most security teams haven't started thinking about yet.
This session examines what the MCP interface actually exposes, how authentication and authorisation work at the MCP layer, and what the default configuration assumes that you should not accept in production. The threat model includes prompt injection through MCP, over-privileged agent connections, unaudited query generation, and data exfiltration paths that bypass conventional monitoring.
From there we build the controls: least-privilege agent identities, row-level security for AI sessions, MCP-aware audit configuration, and detection patterns that flag unusual agent behaviour. A practical security framework for enabling SQL Server 2025's AI capabilities without handing an attacker a direct line to your data.
Danny de Haan
Database Security & Infrastructure Advocate || Solutions Engineer @ Redgate
Roermond, The Netherlands
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top