Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Agentic Broker
    Real-time Protection Policies for MCP Security
    Configuring RTP Policies to Block Events
    Broad Access Control to Block all MCP Traffic with RTP

    Broad Access Control to Block all MCP Traffic with RTP

    Contact your Netskope account team to enable Agentic Broker in your account. Additional licensing is required for Agentic Broker and DLP. Note, to create a DLP policy, the DLP add-on license is required if you do not have DLP enabled in your account.

    An administrator can create an RTP Policy to block all MCP traffic by creating a policy for the category “MCP Server”. Create a new policy. In the source dropdown select Category and select “MCP Server”. Set the Profile & Action to Block. Give it a name and save. Apply the changes. 

    Policy Configuration Interface: The “Create Policy” screen. The Source dropdown is set to “Category” and the Category is set to “MCP Server”. Not selecting any activity applies the policy to all activities. “Profile & Action” field is set to Block.

    To block a specific activity of all MCP Servers, in the Destination section select the specific Activity. The supported list of activities for MCP Server category are:

    • CallToolRequest
    • CallToolResult
    • CreateMessageRequest
    • CreateMessageResult
    • ElicitResult
    • GetPromptRequest
    • GetPromptResult
    • InitializeRequest
    • InitializeResult
    • ListPromptsResult
    • ListResourcesResult
    • ListResourceTemplatesResult
    • ListToolsResult
    • ReadResourceRequest
    • ReadResourceResult
    Upload, Logout, Login Successful, Login Failed, Login Attempt, Browse and Download activities do not apply to MCP Communications. They apply to cloud applications. Do not select these when creating a DLP policy for MCP traffic.

    Refresh the Application Events page to view that all MCP server traffic is now blocked. 

    Application Events Page: Every MCP server event is blocked.

    In this Topic
    • Broad Access Control to Block all MCP Traffic with RTP