megachangelog
Feature

Deploy managed Copilot settings via MDM in VS Code and CLI

Enterprise administrators can now deploy managed GitHub Copilot settings directly to devices through native mobile device management and file-based configuration, in addition to existing server-managed options.

Enterprise administrators can now deliver managed GitHub Copilot settings directly to devices through native mobile device management (MDM) and file-based configuration, in addition to the existing server-managed channel. This is generally available for GitHub Copilot CLI and VS Code.

Device-level deployment lets you enforce Copilot governance using the same tools you already use to manage endpoints. You can push settings through Microsoft Intune, Jamf, or Group Policy, or deploy a configuration file with Chef, Puppet, or Ansible. Because settings are read from the device, they apply consistently across VS Code and Copilot CLI, regardless of how a developer signs in.

Delivery channels

You can deliver managed settings through any of three channels, all of which use the same keys and values.

  • Native MDM reads OS-level managed preferences. On Windows, settings come from the HKEY_LOCAL_MACHINE\SOFTWARE\Policies\GitHubCopilot registry key. On macOS, they come from managed preferences for the com.github.copilot domain.
  • File-based reads a managed-settings.json file from a well-known path (i.e, /Library/Application Support/GitHubCopilot/managed-settings.json on macOS, %ProgramFiles%\GitHubCopilot\managed-settings.json on Windows, and /etc/github-copilot/managed-settings.json on Linux). File-based settings must be owned by root and cannot be world-writable or symlinked.
  • Server-managed resolves settings from the developer’s signed-in GitHub account via managed-settings.json in your organization’s .github-private repository.

When more than one channel provides settings, the highest-precedence channel wins outright, in this order:

  1. Native MDM
  2. Server-managed
  3. File-based

Supported settings

The device-level channels support the same managed setting keys as the server-managed channel, including:

  • permissions.disableBypassPermissionsMode
  • model
  • enabledPlugins
  • extraKnownMarketplaces
  • strictKnownMarketplaces
  • telemetry.* for OpenTelemetry export configuration

Scalar settings use their dot-separated key directly, while structured settings such as enabledPlugins are supplied as a JSON string value. Additional keys will be added over time.

Getting started

To learn how to deploy managed settings to your devices, see Deploy Copilot managed settings. For the full list of keys and the settings they control, see Configure enterprise managed settings.

Join the discussion within GitHub Community.

The post Deploy managed Copilot settings via MDM in VS Code and CLI appeared first on The GitHub Blog.

copilotmdmenterpriseconfigurationvscode

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →