You can now govern the GitHub Copilot app and Copilot cloud agent with enterprise managed settings, the same centrally managed policies you use to control Copilot across your enterprise. With a managed-settings.json file, enterprise owners define one set of guardrails, such as which plugins and marketplaces developers can use and whether they can bypass approval prompts. Copilot clients automatically enforce these settings for everyone on your enterprise’s Copilot plan.

As your developers adopt Copilot across more surfaces, you’re accountable for applying the same governance everywhere they work. Any client that sits outside your policy is a gap, a place where someone could install a plugin you haven’t vetted or run a command you’d normally gate. Your governance is only as strong as its least-covered surface.

The Copilot app and cloud agent now join Copilot CLI and VS Code as supported clients for enterprise managed settings, so your guardrails follow your developers into the app and cloud agent tasks. You define your policy once, and it’s enforced consistently wherever your teams build. That’s the cross-client consistency and high-trust teams need to adopt Copilot with confidence.

Bring every client under the same guardrails