An MCP registry isn't enough. You need a review gate too
I wrote about setting up an MCP Registry with Azure API Center last year. That post covers the mechanics: register your MCP servers, expose an endpoint, point Copilot at it, restrict access to registry-only. It works, and it’s a real control. But a registry alone answers one question: is this server on the approved list? It doesn’t answer the harder one: should it be. That second question is what an agentic security review is for. ...