GitHub Copilot app access managed by new policy
GitHub now offers a dedicated policy to manage access to the Copilot application independently of the Copilot CLI. This feature provides enterprises and organizations granular control over who can use the Copilot app, enhancing security and compliance by aligning app usage with existing review and audit processes. The new policy is enabled by default, allowing immediate use by developers, and can be configured through enterprise or organization AI Controls.
- →Dedicated policy for GitHub Copilot app access
- →Copilot app joins other clients for enterprise-managed settings
- →New policy available in AI Controls
- →Policy configuration options
Features (1) ›
- Dedicated policy for GitHub Copilot app access
GitHub Copilot app access can now be managed independently using a dedicated policy at the enterprise and organization levels, offering greater control than previous reliance on Copilot CLI policies. This allows administrators to enable or disable the app for their teams.
Enhancements (1) ›
- Copilot app joins other clients for enterprise-managed settings
The Copilot app is now a supported client for enterprise-managed settings, similar to Copilot CLI and VS Code. This ensures that centrally defined guardrails, such as allowed plugins, are consistently enforced across all supported Copilot clients.
Notes (2) ›
- New policy available in AI Controls
The new Copilot app policy is located within the AI Controls tab of enterprise or organization settings, under the 'Copilot Clients' section. It is set to 'Enabled everywhere' by default.
- Policy configuration options
Administrators have three options for the Copilot app policy: 'Enabled everywhere' grants developers access, 'Disabled everywhere' turns off the app, and 'Let organizations decide' delegates the choice to individual organization administrators.
https://github.blog/changelog/2026-07-27-manage-github-copilot-app-access-with-a-dedicated-policy
Related releases
- GitHub Copilot Enterprise Teams Model Policy Targeting in Public Preview GitHub Changelog ·
- npm restricts granular access token ability to bypass 2FA for sensitive actions GitHub Changelog ·
- GitHub Models officially retired GitHub Changelog ·
- GitHub Copilot VS Code Updates: Agents, Chat, UI, and Accessibility GitHub Changelog ·
- GitHub Actions: Reference same-repo workflows with self-repository syntax GitHub Changelog ·
- GitHub Stacked Pull Requests Enter Public Preview GitHub Changelog ·