{"slug": "enterprise-managed-settings-in-the-github-copilot-app-and-copilot-cloud-agent", "title": "Enterprise managed settings in the GitHub Copilot app and Copilot cloud agent", "summary": "GitHub announced that enterprise managed settings now govern the GitHub Copilot app and Copilot cloud agent, allowing enterprise owners to define a single set of guardrails—such as plugin approvals and bypass-prompt controls—via a managed-settings.json file that is automatically enforced across all Copilot clients. The Copilot app and cloud agent join Copilot CLI and VS Code as supported clients, ensuring consistent policy enforcement wherever developers work.", "body_md": "# Enterprise managed settings in the GitHub Copilot app and Copilot cloud agent\n\nYou can now govern the GitHub Copilot app and Copilot cloud agent with enterprise managed settings, the same centrally managed policies you use to control Copilot across your enterprise. With a `managed-settings.json`\n\nfile, enterprise owners define one set of guardrails, such as which plugins and marketplaces developers can use and whether they can bypass approval prompts. Copilot clients automatically enforce these settings for everyone on your enterprise’s Copilot plan.\n\nAs your developers adopt Copilot across more surfaces, you’re accountable for applying the same governance everywhere they work. Any client that sits outside your policy is a gap, a place where someone could install a plugin you haven’t vetted or run a command you’d normally gate. Your governance is only as strong as its least-covered surface.\n\nThe Copilot app and cloud agent now join Copilot CLI and VS Code as supported clients for enterprise managed settings, so your guardrails follow your developers into the app and cloud agent tasks. You define your policy once, and it’s enforced consistently wherever your teams build. That’s the cross-client consistency and high-trust teams need to adopt Copilot with confidence.\n\n[Bring every client under the same guardrails](#bring-every-client-under-the-same-guardrails)\n\nThe Copilot app reads the same `managed-settings.json`\n\nyou already use for your other clients. You can govern things like:\n\n- Which plugins are available.\n- Which plugin marketplaces developers can install from.\n- Whether developers can bypass approval prompts before Copilot runs commands, accesses files, or fetches URLs.\n- Setting auto model selection as the default for new conversations.\n\nThe Copilot cloud agent reads the applicable managed settings, including those for plugins and marketplace controls. It only uses the plugins and marketplaces you’ve approved. Bypass-prompt controls only apply to the interactive clients (i.e., the app, Copilot CLI, and VS Code).\n\nFor each supported key, your managed value takes precedence over anything a developer sets locally. See the full list of options in the [enterprise managed settings reference](https://docs.github.com/copilot/reference/enterprise-managed-settings-reference).\n\nIf you already deploy `managed-settings.json`\n\nfor Copilot CLI and VS Code, there’s nothing new to set up. The Copilot app automatically picks up your existing configuration the next time a developer signs in or restarts the app, and the cloud agent observes changes on the next task assignment.\n\n[Getting started](#getting-started)\n\nIf you’re setting up enterprise managed settings for the first time, the default approach is server-managed deployment:\n\n- Create and configure a\n`.github-private`\n\nrepository in your enterprise. For more information, see[our guide](https://docs.github.com/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-agents/create-github-private-repo). - In that repository, create or update\n`copilot/managed-settings.json`\n\n. - Add your enterprise policy keys and values in JSON, then commit and push to the default branch.\n\nSupported clients apply updated settings within about an hour, immediately after a developer restarts the client, or when a developer signs back in. You can also deploy through MDM or a distributed file.\n\nTo learn more, see [configuring enterprise managed settings](https://docs.github.com/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-agents/configure-enterprise-managed-settings).\n\nJoin the discussion within [GitHub Community](https://github.com/orgs/community/discussions/199139).", "url": "https://wpnews.pro/news/enterprise-managed-settings-in-the-github-copilot-app-and-copilot-cloud-agent", "canonical_source": "https://github.blog/changelog/2026-07-27-enterprise-managed-settings-now-apply-to-the-github-copilot-app", "published_at": "2026-07-27 17:00:35+00:00", "updated_at": "2026-07-27 21:53:07.181771+00:00", "lang": "en", "topics": ["ai-tools", "developer-tools", "ai-policy"], "entities": ["GitHub", "GitHub Copilot", "Copilot CLI", "VS Code"], "alternates": {"html": "https://wpnews.pro/news/enterprise-managed-settings-in-the-github-copilot-app-and-copilot-cloud-agent", "markdown": "https://wpnews.pro/news/enterprise-managed-settings-in-the-github-copilot-app-and-copilot-cloud-agent.md", "text": "https://wpnews.pro/news/enterprise-managed-settings-in-the-github-copilot-app-and-copilot-cloud-agent.txt", "jsonld": "https://wpnews.pro/news/enterprise-managed-settings-in-the-github-copilot-app-and-copilot-cloud-agent.jsonld"}}