Every time an AI agent connects to an MCP server, something has to decide a very basic question: Is this connection allowed? Aembit has always answered that question with identity — verifying the agent, checking the policy, issuing a short-lived credential, and logging the result – to give security teams a “yes” they can trust.
But a “yes” to the connection isn’t the same as a “yes” to everything that happens after it. An approved agent can still be handed a manipulated tool listing designed to hijack its next move. It can still send sensitive data to a tool it shouldn’t, or receive a malicious instruction disguised as a normal response. Identity answers who and what can connect. It doesn’t, on its own, answer whether what’s flowing through that connection is safe.
What’s Launching at Fal.Con?
Today at CrowdStrike Fal.Con, we announced a new integration with CrowdStrike AI Detection and Response (AIDR) and Aembit’s own IAM for Agentic AI. Administrators can now attach a CrowdStrike AIDR content security configuration to the access policies that already govern MCP access, so the same policy that decides whether an agent can connect also decides whether the content crossing that connection is safe.
This is Aembit’s third CrowdStrike integration, following integrations with CrowdStrike Endpoint Security and CrowdStrike Next-Gen SIEM, and the first built to inspect MCP content specifically. It’s available now to Aembit customers with CrowdStrike AIDR for Agents subscriptions.
How Does the Aembit-CrowdStrike Integration Work?
The integration builds on Aembit’s existing IAM for Agentic AI solution that manages connections between AI agents and MCP servers and adds inspection at three points in the MCP flow, matching CrowdStrike’s documented MCP event types:
Tool listings. Before an agent ever sees what tools are available, AIDR checks the listing for manipulated descriptions or hidden instructions designed to change the agent’s behavior.
Tool inputs. When an agent calls a tool, AIDR evaluates what it’s sending, catching sensitive data or unintended actions before they reach the tool.
Tool outputs. When a tool responds, AIDR evaluates what’s coming back, so regulated data or malicious instructions don’t make it into the agent’s next step.
Based on CrowdStrike’s decision, Aembit allows the content, blocks it, or forwards a transformed version, such as one with sensitive data redacted or defanged. Every decision is captured in a workload event alongside the identity, agent, target MCP server, and access policy context that produced it, so a CrowdStrike finding and an Aembit access event are never two separate stories.
Inspection is opt-in per access policy, not applied everywhere by default. Customers choose which connections need it, typically the MCP servers handling the most sensitive systems or data, and can configure fail-open or fail-closed behavior for AIDR outages depending on how much risk they’re willing to accept versus how much availability they need. Access policies without content security continue to work exactly as they do today.
Why Does This Matter for Agentic AI Security?
While there are plenty of tools that impose controls on AI agent activity, many don’t establish a strong identity for the agent that is distinct from the user behind the action. Security teams are left configuring individual controls or managing overpermissioned agents.
With this integration, Aembit and CrowdStrike are taking a different approach: building content inspection into the same control plane that already handles identity, access policy, credential issuance, and audit logging for every AI agent. There’s no separate proxy to deploy in front of every MCP client and no gap between what your identity platform allowed and what your security tooling actually caught.
For security architects, that means applying CrowdStrike AIDR policy without stepping outside the access model already in place. For platform teams, it means configuring inspection once, at the policy level, instead of touching every agent and client individually. For SOC analysts, it means starting from an AIDR finding and immediately seeing the Aembit identity and policy decision behind it, or starting from an access event and finding the AIDR decision tied to it, in either direction.
How Do I Get Started?
The integration is configurable through the Aembit UI, API, or Terraform, and requires a CrowdStrike AIDR for Agents subscription. For more information about the integration and how it’s configured, check out Aembit’s docs site.
Aembit and CrowdStrike are showcasing the integration together at Fal.Con 2026 in Las Vegas, Aug. 31-Sept. 3. If you’re attending, come find us at Booth 2006.
You can also talk to an engineer to learn more today.