Commercial transition
Who is affected
GitHub Copilot enterprises governing MCP server use in supported Copilot clients.
Action required
Define and test enterprise MCP server policy matchers before broad enforcement, and verify client coverage instead of assuming the policy applies to every Copilot surface.
Evidence boundary
The GitHub source proves general availability of allowedMcpServers and deniedMcpServers, fail-closed policy behavior, and current enforcement on the Copilot app, Copilot CLI and VS Code. It does not claim enforcement on every current or future Copilot client.
Timeline
- MCP allowlists reach general availability
GitHub announced enterprise managed-setting keys for centrally controlling allowed and denied MCP servers.
Official sources
- MCP allowlists in enterprise managed settingsGitHub · 2026-08-06 · Official GitHub changelog