GitHub extends central management of Copilot settings to the Copilot app and the cloud agent
GitHub has extended central settings management (managed-settings.json) for Copilot to the Copilot app and the cloud agent - previously, it applied only to Copilot CLI and VS Code. Administrators can thus manage plugins, marketplaces and the bypassing of approval prompts consistently across clients.
GitHub has extended the enterprise managed settings feature for GitHub Copilot to the Copilot app and the Copilot cloud agent. Previously, central settings management worked only for Copilot CLI and VS Code; according to the company, it now covers all major clients through which developers use Copilot at work.
Central rules are defined in the managed-settings.json file, which enterprise account owners use to specify, among other things, which plugins and marketplaces developers may use and whether they can bypass approval prompts (bypass-prompt). According to GitHub, the Copilot app loads the same managed-settings.json file as the other clients, and the cloud agent respects the settings for plugins and marketplaces - it uses only those approved by the administrator. However, according to the article, control over bypassing approval prompts applies only to interactive clients, namely the app, Copilot CLI and VS Code.
According to the company, companies that have already deployed managed-settings.json for Copilot CLI and VS Code do not need to configure anything else - the Copilot app will automatically adopt the existing settings at the next sign-in or restart, and the cloud agent will take them into account when assigned its next task. For new deployments, GitHub recommends server-managed deployment through a file in a private .github-private repository within the enterprise account as the default option, or alternatively deployment through MDM or a distributed file. According to the article, updated settings take effect in supported clients within roughly an hour, or immediately after a developer restarts or signs in again.
Why it matters
Until now, enterprise administrators had to handle governance separately for Copilot CLI and VS Code, while the Copilot app and the cloud agent remained outside the reach of central rules - this created a gap where a developer could install an unapproved plugin or run an unauthorized command. Unifying rules in a single managed-settings.json file across clients reduces the risk of such unmanaged areas and makes it easier to meet company security and compliance requirements when deploying Copilot more broadly across teams.
Two audiences, two different impacts
What this means
For individuals
Developers who use the Copilot app or the cloud agent at work may find that centrally configured company rules now restrict their choice of plugins and marketplaces, and that it may no longer be possible to bypass approval prompts as before.
For a business
Companies using GitHub Copilot can now centrally enforce the same rules (approved plugins, marketplaces, a ban on bypassing approval prompts) in the Copilot app and for the cloud agent as well, closing the previous governance gap where these rules applied only to Copilot CLI and VS Code.
Risks and complianceCheck the original
Event sources
clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.