GitHub Copilot CLI and VS Code restrict plugin installs
Enterprises can now control which plugins users can install in GitHub Copilot CLI and VS Code via new enterprise-managed settings. This feature, currently in public preview, helps enforce client governance by allowing plugins only from explicitly defined marketplaces. This applies to users licensed through Copilot Business or Copilot Enterprise accounts.
- →Control plugin installations in VS Code and Copilot CLI
- →Enhances client governance and security
Features (1) ›
- Control plugin installations in VS Code and Copilot CLI
Enterprise-managed settings now support `strictKnownMarketplaces` for GitHub Copilot CLI and VS Code, allowing administrators to control which plugins users can install. This feature is available in public preview and automatically applies to users licensed through Copilot Business or Enterprise.
Notes (1) ›
- Enhances client governance and security
This update allows enterprises to enforce client governance strategies by preventing users from installing untrusted plugins before tool execution. It builds upon previous enterprise-managed plugin capabilities for Copilot CLI and VS Code.
https://github.blog/changelog/2026-06-25-enterprise-managed-settings-now-support-strictknownmarketplaces-in-vs-code-and-the-cli
Related releases
- GitHub Copilot Deprecates Gemini 2.5 Pro and 3 Flash Models GitHub Changelog ·
- GitHub Copilot Enterprise Teams Model Policy Targeting in Public Preview GitHub Changelog ·
- npm restricts granular access token ability to bypass 2FA for sensitive actions GitHub Changelog ·
- GitHub Models officially retired GitHub Changelog ·
- GitHub Copilot VS Code Updates: Agents, Chat, UI, and Accessibility GitHub Changelog ·
- GitHub Actions: Reference same-repo workflows with self-repository syntax GitHub Changelog ·