Last reviewed
Correct answer: B. It approves that configuration for use, and each developer still installs and configures the server themselves.
Explanation
The principle — Approval and distribution are separate mechanisms in Cursor's enterprise controls. Allowlisting approves an MCP configuration; it does not distribute or install the server.
Why the key is correct — The MCP Allowlist defines which servers and tools a team may run: command entries approve local servers by command pattern, URL entries approve remote servers by URL pattern, and a tool allowlist can narrow which tools from an approved server run automatically. All of that is permission. Each developer still installs and configures the server on their own machine, from Customize or by adding it to mcp.json, which is why the team reported no new tools after the announcement.
Why the others are wrong — Nothing is pushed to anyone's editor by allowlisting, so the managed-extension analogy imports a delivery model Cursor deliberately keeps separate. Installing for everyone with tools held back is still distribution, just with an extra step, and no install takes place at all. And an allowlist restricts what may run rather than placing software on machines at launch.
Remember this — Decide permission with the allowlist, then handle delivery separately through shared team servers and the team marketplace, and tell people plainly that they still need to install.
Sources — Cursor's MCP documentation.
Sources
“Allowlisting approves an MCP configuration. It does not distribute or install the server.”
Practise 10 questions on this topic
Take Cursor Basics — Timed Test 1 (10 questions) — scored instantly, explanation for every question, no login.