The Model Context Protocol (MCP) is moving from prototype to production faster than the architectural patterns required to operate it safely. This paper is a practitioner's field guide for .NET architects who must deliver MCP-based agentic systems on the OAuth 2.1 / .NET / Azure stack. It covers: the architectural patterns that scale; the four authorization patterns and when to choose each; a security treatment of indirect prompt injection through trusted MCP tool output; the operational concerns of observability, FinOps, and governance; and a twenty-item threat catalogue suitable as an artefact for threat-modelling workshops. The paper is 113 pages, organised into nine chapters and four appendices. A separate reference implementation built on .NET 9 / .NET 10, ASP.NET Core, and Azure-native services accompanies the paper and is cited section-by-section. Reference protocol revision: Model Context Protocol Specification 2025-11-25. Target platform: .NET 9 / .NET 10, ASP.NET Core, Azure. Companion reference implementation: https://github.com/alenjoy333/mcp-enterprise-dotnet
Alen Joy (Tue,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: