Commercial software intelligenceEvidence checked · 8 September 2026
SkuTrace

Commercial product change, preserved as evidence.

SK-2026-162 · Enterprise AI governance

GitHub Copilot adds enterprise MCP server allowlists and denylists

GitHub Copilot enterprise managed settings now support generally available MCP server controls through allowedMcpServers and deniedMcpServers, with policies that fail closed and enforcement currently documented for the GitHub Copilot app, Copilot CLI and VS Code.

Generally available

Commercial transition

Previous stateEnterprise managed settings did not expose the announced central MCP allowlist and denylist keys.
New stateEnterprise owners can define allowedMcpServers and deniedMcpServers matchers for MCP servers in managed settings; malformed or unverifiable policy configuration fails closed, and enforcement is documented for the Copilot app, Copilot CLI and VS Code.

Who is affected

GitHub Copilot enterprises governing MCP server use in supported Copilot clients.

Action required

Define and test enterprise MCP server policy matchers before broad enforcement, and verify client coverage instead of assuming the policy applies to every Copilot surface.

Evidence boundary

The GitHub source proves general availability of allowedMcpServers and deniedMcpServers, fail-closed policy behavior, and current enforcement on the Copilot app, Copilot CLI and VS Code. It does not claim enforcement on every current or future Copilot client.

Timeline

  1. MCP allowlists reach general availability

    GitHub announced enterprise managed-setting keys for centrally controlling allowed and denied MCP servers.

Official sources