Azure API Management at Build 2026: A2A, MCP safety and an agent catalogue
At Build 2026, Microsoft made A2A APIs generally available in Azure API Management, extended content safety to MCP and A2A, and let API Center register agents.
Most of the attention at Microsoft Build 2026 went to Logic Apps and agents. The changes to Azure API Management and Azure API Center got less notice, but for integration teams on Azure they may matter more. Microsoft is making its API gateway the place where traffic between agents is governed, with the same tools that are already used for APIs.
What Microsoft announced
The main changes in API Management are:
- A2A APIs are generally available. Traffic between agents using the A2A protocol can be managed like other APIs, with rate limiting, token budgets, authentication and transformation. A2A calls can use the same Microsoft Entra ID setup as the rest of the APIs.
- Content safety for MCP and A2A. The
llm-content-safetypolicy, which used to cover only calls to language models, now also checks the arguments and responses of MCP tool calls and the messages sent between agents. This is generally available. - Anthropic and Google Vertex AI as backends. The AI gateway features, such as token control, semantic caching, logging and tracing, now also cover models from Anthropic and Vertex AI, not only Azure OpenAI.
- Unified Model API (public preview). One endpoint, compatible with the OpenAI Chat Completions format, that can route to Azure OpenAI, Anthropic or Vertex AI. Model aliases mean that the client code does not need to change when the provider changes.
In Azure API Center, the catalogue of an organisation’s APIs, agents can now be registered and assessed, and the catalogue can be synchronised with Git.
Why it matters
These are small features one by one, but together they show a clear line. Microsoft does not build a separate product for agent governance. It adds agents to the API catalogue, agent traffic to the API gateway and AI safety checks to the same policy engine. For organisations that already run API Management, it means they can govern agents with skills and processes they already have.
The content safety extension is especially practical. Prompt injection often arrives through what a tool returns, not through what the user types. Checking MCP responses and messages between agents in the gateway catches more of it than checking only the prompt.
How it compares
The same pattern is showing up with other gateway vendors, and with iPaaS vendors that have their own gateways. What sets Azure apart is the tie to Entra ID and Azure Monitor, which many organisations already use. For companies that run agents on several platforms, the question is still whether all agent traffic will actually pass through API Management, or only the traffic that starts in Azure.
What to ask
- Which A2A traffic goes through the gateway? Map which agents talk to each other, and whether those calls pass through API Management or go directly.
- Is content safety turned on for MCP? Check that the policy covers tool responses, not only prompts, and decide what happens when something is blocked.
- Is API Center the agent catalogue? Decide whether agents should be registered in API Center, or in another registry that API Center feeds.
Sources
- What's new in Azure API Management at Microsoft Build 2026 (Microsoft Tech Community, 1 June 2026)
- Azure API Center now supports agent registration, agent assessment and Git-based synchronization (Microsoft Tech Community, 1 June 2026)
- Azure API Management's Unified Model API makes provider switching a policy, not a code change (ChatForest, 3 June 2026)
This post was written with AI assistance and reviewed by the editor before publishing.