Users can be confused when GrpcSecurity is not available because they have a GrpcServlet (they should use the normal web MVC security in that case). The best thing to do is probably provide a failure analyzer that recognizes the scenario where user tries to inject GrpcSecurity but it isn't available despite being on the classpath.