Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Introducing PathfinderAI and MCP Server: Simplifying Privilege-Centric Identity Security by Using AI on Your Terms current page
Link copied

Introducing PathfinderAI and MCP Server: Simplifying Privilege-Centric Identity Security by Using AI on Your Terms

Apr 27, 2026

Security teams are drowning in disconnected tools, manual reporting, and complex identity data. PathfinderAI, built into the BeyondTrust Pathfinder Platform, introduces natural language intelligence to simplify identity security operations. With MCP Server integration, organizations can securely extend these capabilities across AI ecosystems like Microsoft Copilot and ServiceNow—transforming how teams analyze, prioritize, and remediate privilege risks.

Author:
Josh Headshot 2024 1
Josh Fu
VP, Product Marketing
Pathfinder AI and MCP
Introducing PathfinderAI and MCP Server: Simplifying Privilege-Centric Identity Security by Using AI on Your Terms
Josh Headshot 2024 1
Josh Fu
VP, Product Marketing

How BeyondTrust is redefining identity security operations with natural language intelligence built directly into our Pathfinder Platform

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Ask any security team leader about their biggest operational challenge and you'll hear a familiar answer: their analysts are drowning. Modern security operations centers (SOCs) are often cluttered with disconnected point tools. While these tools attempt to provide a cohesive picture, they often fail to make organizations safer because they don’t integrate well. This fragmentation forces analysts to spend excessive time extracting data from each tool, which delays reporting, visibility, prioritization, and, ultimately, remediation.

Identity has become the modern perimeter. However, for identity security teams, the problem is even more pronounced. Every misconfigured privilege, stale account, or shadow admin is a potential attack path. While the data to find these risks exists, it requires navigating complex product interfaces, knowing exactly where to look, and manually piecing together the True Privilege (total effective privileges) of a single identity. Now, multiply that task by hundreds of human, non-human, and agentic AI identities. It’s a time sink that most teams simply can’t afford.

Furthermore, security leaders need to communicate risk to the board, executives, and compliance teams, while analysts need to communicate findings to their leadership. Generating these reports—which involves pulling data, summarizing trends, building narratives, and highlighting the risks of inaction—is currently manual, labor-intensive work. It eats hours that should be spent on analysis and remediation, and the resulting reports are often stale by the time they're distributed.

Bridging the Identity Visibility Gap

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Modern security platforms generate enormous volumes of data, yet analysts frequently report that they don't have enough visibility. Even though it’s a cliche at this point, the saying is still as true as ever: You can’t protect what you can’t see.

Organizations now manage an average of 45 security tools, each capturing overlapping yet often conflicting data streams. But, correlating this data to connect a suspicious login to an escalated privilege and a lateral movement attempt requires either deep product expertise or time-intensive effort. Not all risks are equal priority. Without clear prioritization, analysts may spend as much time on a low-risk alert as they do on a critical privilege escalation path, simply because of the order of alerting.

Even when an analyst correctly identifies and prioritizes a risk, the remediation path is rarely obvious. What are the correct steps for a shadow admin in a hybrid environment? What is the downstream impact of removing a specific privilege? To solve these challenges, security teams are turning to AI agents and large language models (LLMs) to process mass data and come accelerate better decision-making.

BeyondTrust is leading this important shift with PathfinderAI and MCP Server, asymmetrically changing how fast and easily security analysts can level up and proactively stop identity risks before they become breaches.

How PathfinderAI and MCP Server Transform Operations

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

The Pathfinder Platform: One Place to Secure Everything

The BeyondTrust Pathfinder Platform dynamically maps and manages privilege relationships for every human, machine, and agentic identity. It continuously updates access paths and exposes hidden attack vectors in a single, unified control plane that spans Privileged Access Management (PAM), Identity Threat Detection and Response (ITDR), Cloud Identity Management, and Cloud Infrastructure Entitlement Management (CIEM).

Because Pathfinder aggregates identity, access, and privilege data from across the entire BeyondTrust portfolio, it creates a foundation for AI that analyzes your full security suite rather than operating in a vacuum.

PathfinderAI is the natural language, interactive layer built on this foundation. Simultaneously, the MCP Server enables security teams to centralize usage within their own LLM stacks and AI-driven workflows.

What's in This Release

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

PathfinderAI and MCP Server launched in Early Access on April 15th, 2026.

  • PathfinderAI: Initially available to all Identity Security Insights customers on Pathfinder in the US region.
  • MCP Server: Initially available to Remote Support, Privileged Remote Access, Endpoint Privilege Management, Password Safe, and Entitle customers on Pathfinder in the US region.

PathfinderAI provides a natural language interface to your identity security data. Analysts and operators can ask questions in plain English and receive direct, contextually relevant answers drawn from the Pathfinder data platform. Built on cutting-edge frontier models, the architecture design is security-first, protecting against prompt injection and context poisoning attacks, to ensure the AI layer itself doesn't become an attack surface.

Key Capabilities of PathfinderAI

Here’s what security teams can do with PathfinderAI at Early Access:

  • Query Identity Security Insights Data in Natural Language: Ask questions like “Which Azure accounts have elevated privileges but no MFA?”, “Which AI agents with high privilege are exposed to the internet?”, or “Which human accounts can access secrets in production cloud environments?”—and receive immediate, actionable answers in plain English.
  • Receive Tactical Guidance: Get step-by-step instructions, configurations, or Python code on how to reduce privileges, remediate risky access, and enforce least privilege via Identity Security Insights.
  • Streamline Reporting: Produce reports on key human, machine, and agentic identity risks by True Privilege priority to quickly surface trends, anomalies, and high-impact exposures.
  • Automate Remediation Workflows: Generate personalized, context-aware communications—such as emails to resource owners or stakeholders—infused with specific findings to accelerate response and accountability.
  • Boost Efficiency: Reduce time and costs spent navigating and searching for data.

What is Model Context Protocol (MCP)?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Let’s look at what a Model Context Protocol (MCP) server is. An MCP server is a standardized way to connect AI models to external tools, data sources, and services.

MCP is an open protocol that defines a common interface for AI models to interact with third-party vendor applications. Instead of every AI application needing custom integrations for every tool via an API, MCP provides a single, consistent way for AI to communicate with these that is constantly up to date.

MCP is becoming an industry-wide standard, with many organizations adopting it to make their services accessible to AI models in a consistent way.

How It Works

An MCP server sits between an AI model and an external service like BeyondTrust. It exposes a set of capabilities and defined functions that AI agents can call. The AI then decides when and how to use them based on the prompts. Where you once had to build a complex middleware application, MCP streamlines your ability to integrate data and take actions across multiple tools simultaneously.

What security teams can do with Pathfinder MCP server at Early Access:

  • Expand AI-Native Workflows: Gain interoperable, plug-and-play access to all supported BeyondTrust products within the Pathfinder Platform.
  • “Bring Your Own AI”: Connect existing frontier models—such as those from OpenAI, Anthropic, and Microsoft—directly to the BeyondTrust Pathfinder Platform.
  • Accelerate Time-to-Value: Quickly realize the benefits of your BeyondTrust portfolio within the Pathfinder Platform and ability to broaden the use of AI in your existing security workflows.
  • Direct Data Access: Access and leverage BeyondTrust Pathfinder data immediately, without the friction of coding against API wrappers or SDKs.

The roadmap significantly expands these capabilities as we move toward General Availability in Q3 2026 and subsequent releases:

  • MCP Server Integration: The MCP Server integration will enable the Pathfinder AI Agent to invoke tools across BeyondTrust solutions, while allowing external AI agents from ecosystems like Microsoft Copilot, ServiceNow, and OpenAI to interact with BeyondTrust capabilities through a standardized, authenticated interface.
  • Persistent Investigation Context: Conversation history will preserve chat context across sessions, enabling analysts to build on prior investigations without losing momentum.
  • Seamless Cross-Platform Continuity: Persistent chat across all Pathfinder applications will ensure context remains intact when navigating between products.
  • Global Availability: Expanded availability beyond the U.S. will support customers worldwide with consistent access and performance.
  • AI-Assisted Remediation: Write-capable actions will extend PathfinderAI from read-only intelligence to guided, AI-assisted remediation.

When your analysts can ask a question in natural language and receive an accurate answer in seconds, you're compressing what used to be a 30-minute data-gathering effort into a 10-second streamlined upleveling of Tier 1 skill.

Why This Matters to Customers, Security Teams, and Security Analysts

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

At BeyondTrust, we've always believed that securing privileged access shouldn't slow your business down; it should power it forward. That's why we’re providing organizations with the flexibility of using the integrated PathfinderAI to accelerate privilege-centric identity security workflows or “bring their own AI” using the MCP server.

We don’t just manage identities, we control their privileges—which is where the business risk lies. Securing privilege is arguably the fastest, most measurable path to provable risk reduction.

The most immediate business value of these new BeyondTrust capabilities is faster time-to-respond. When your analysts can ask a question in natural language and receive an accurate answer in seconds, you're compressing what used to be a 30-minute data-gathering effort into a 10-second streamlined upleveling of Tier 1 skill. Multiplied across an entire analyst team and hundreds of investigations per month, that compression translates directly into massive operational efficiency improvements and cost reduction.

For security leaders responsible for reporting upward, PathfinderAI and the MCP Server also eliminates the “manual reporting tax” described earlier. Instead of spending hours aggregating data for executive briefings, analysts can use these to surface key metrics, trends, and risk summaries that form the backbone of security reporting.

The governance model built into the platform ensures these capabilities are deployed responsibly. LLM features are disabled by default and require explicit opt-in at the site level, giving customers control over whether PathfinderAI is enabled in their environment. Access to PathfinderAI is governed by Pathfinder's RBAC controls, meaning the same access policies that govern product access also govern AI access. No analyst can query data they aren't already authorized to see, and customers have the control to turn it on or off. For security teams in regulated industries, this control model is not a nice-to-have—it's a prerequisite.

Early Access Program

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

As stated earlier, PathfinderAI and the MCP Server launched in Early Access on April 15th, 2026.

  • PathfinderAI: Initially available to all Identity Security Insights customers on Pathfinder in the US region.
  • Pathfinder MCP Server: Initially available to all Remote Support, Privileged Remote Access, Endpoint Privilege Management, Password Safe, and Entitle customers on Pathfinder in the US region.

During the EA phase, BeyondTrust is actively collecting feedback. This feedback directly informs model tuning and feature prioritization before General Availability. We encourage every eligible team to opt in, put the PathfinderAI and MCP Server to work on real investigations, and tell us what it gets right and where it needs to improve.

To learn more about enabling these features for your organization, contact your sales representative, or reach out to one of our highly trained advisors.

About the Author

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Josh Headshot 2024 1
Josh Fu
VP, Product Marketing

Josh brings a diverse range of experience in the endpoint, cloud, IT, and security to BeyondTrust, having been mentored by some of the most well-respected leaders in this space. His career encompasses channel, consulting, sales engineering, strategic alliances, competitive intelligence, and of course, product marketing. These have led to him speaking about threat intelligence and machine learning at multiple conferences worldwide. He has lived in eight cities across the US and traveled to over thirty countries (several recent trips were planned entirely around the dinner reservation). He currently lives in Minneapolis, MN with his wife, their 4-year-old, and two labs. Now that he’s getting a little more sleep, he’s discovering new hobbies in snowboarding and tinkering with cars.

Learn More

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Blog
How to Detect Shadow AI and Enforce Governance for NHIs
Blog
Preventing Shadow AI Agent and NHI Takeover with Privilege-Centric Security
Blog
Securing Agentic AI Workloads with Visibility and Privileged Control
Blog
Agentic AI Security: How Autonomous AI Redefines Identity Compared to Generative AI
Blog
Operationalizing AI Security: How To Govern AI Agent Identities Before Attackers Exploit Them
Blog
Generative AI’s Role in Insider Threat Evolution
Latest Posts
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
Related
  • How to Exploit Remote Desktop Protocol Vulnerabilities
    Jul 21, 2020 How to Exploit Remote Desktop Protocol Vulnerabilities
    Blog
    1m
  • What it’s like to be a CTO/CISO at this Year’s Gartner Security & Risk Management (SRM) Summit
    Jun 18, 2019 What it’s like to be a CTO/CISO at this Year’s Gartner Security & Risk Management (SRM) Summit
    Blog
    1m
Share this Article
  • Link
Tags
  • AI Agent Security
  • Pathfinder MCP
  • PathfinderAI
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.