{"slug": "local-sandboxing-for-github-copilot-now-generally-available", "title": "Local sandboxing for GitHub Copilot now generally available", "summary": "GitHub made local sandboxing generally available for GitHub Copilot across Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, giving developers a secure execution boundary for agentic workflows on their own machines. The feature is powered by Microsoft eXecution Container (MXC), which translates a common sandbox policy into native operating-system controls on Windows, macOS, and Linux, restricting agent-run commands' access to the filesystem, network, credentials, and other system capabilities. Local sandboxing is included with GitHub Copilot at no additional cost, and enterprise-managed settings can require sandboxing and enforce policies developers cannot weaken.", "body_md": "# Local sandboxing for GitHub Copilot now generally available\n\nLocal sandboxing for GitHub Copilot is now generally available in GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host.\n\nLocal sandboxes give developers a secure execution boundary for agentic workflows on their own machines. Tools and commands initiated by Copilot run with restricted access to the filesystem, network, credentials, and other system capabilities, based on policies defined by the developer or their organization.\n\nLocal sandboxing is powered by [Microsoft eXecution Container (MXC)](https://github.com/microsoft/mxc), which translates a common sandbox policy into native operating-system controls across Windows, macOS, and Linux.\n\nWith local sandboxing, developers and organizations can:\n\n- Limit the files and directories that agent-run commands can read or modify.\n- Control access to the internet, local networks, Git credentials, and GitHub CLI credentials.\n- Apply sandboxing to local tools and services, including local MCP and language servers where supported.\n- Use enterprise-managed settings to require sandboxing and enforce policies that developers cannot weaken.\n- Adopt more autonomous agent workflows while maintaining clear boundaries around what Copilot can access.\n\nModel execution and tool isolation are separate concerns. Sandbox policies apply to tool execution regardless of which model Copilot uses.\n\nLocal sandboxing is included with GitHub Copilot at no additional cost. To get started, see [About cloud and local sandboxes for GitHub Copilot](https://docs.github.com/copilot/concepts/security-governance-and-network-settings/about-cloud-and-local-sandboxes?utm_source=changelog-cta-cloud-local-sandbox-documentation&utm_medium=changelog&utm_campaign=oct-7-event-oct-2026).", "url": "https://wpnews.pro/news/local-sandboxing-for-github-copilot-now-generally-available", "canonical_source": "https://github.blog/changelog/2026-10-07-local-sandboxing-for-github-copilot-now-generally-available", "published_at": "2026-10-07 15:46:17+00:00", "updated_at": "2026-10-07 18:50:32.554813+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "ai-safety", "ai-products"], "entities": ["GitHub", "GitHub Copilot", "GitHub Copilot CLI", "VS Code", "Agent Host", "Microsoft eXecution Container (MXC)", "Microsoft"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/local-sandboxing-for-github-copilot-now-generally-available", "markdown": "https://wpnews.pro/news/local-sandboxing-for-github-copilot-now-generally-available.md", "text": "https://wpnews.pro/news/local-sandboxing-for-github-copilot-now-generally-available.txt", "jsonld": "https://wpnews.pro/news/local-sandboxing-for-github-copilot-now-generally-available.jsonld"}}