Maintained with ☕️ by
IcePanel logo

Control of MCP use with organization policies is deprecated. After March 17,

Share

Services

## Deprecate Deprecated Control of MCP use with organization policies is deprecated. After March 17, 2026, organization policies that use the `gcp.managed.allowedMCPServices`constraint won't work, and you can control MCP use with IAM deny policies. For more information about controlling MCP use, see[Control MCP use with IAM](https://docs.cloud.google.com/mcp/control-mcp-use-iam). ## Change Change After March 17, 2026, when you enable Firestore, the Firestore MCP server is automatically enabled. ## Announcement Announcement New best practices are available for securing generative AI agents using Model Context Protocol (MCP) with Google Cloud databases. This guide covers key security measures like least privilege, native database controls, and secure agent design to help you build safer AI applications. For more information, see [Best practices for securing agent interactions with Model Context Protocol](https://docs.cloud.google.com/firestore/native/docs/secure-agent-interactions-mcp).