Summary

On August 18, 2026, GitHub let enterprise admins enforce Copilot settings across JetBrains IDEs, including allowlists and denylists for which MCP servers developers can reach, the ability to disable the Copilot agent's Bypass Approvals and Autopilot modes, plugin governance, and centralized OpenTelemetry routing.

What changed

GitHub added enterprise-managed settings for Copilot in JetBrains IDEs that cascade organization-wide via configuration files and override local developer preferences. Admins can allowlist or denylist the Model Context Protocol servers Copilot may connect to, disable the agent's Bypass Approvals and Autopilot permission modes, require or block specific plugins and restrict installs to approved marketplaces, and centrally configure OpenTelemetry collection.

Why it matters

MCP allowlisting and agent-permission locks give security teams real governance over what an AI coding agent can connect to and how autonomously it can act, addressing the enterprise control gap that has trailed the rapid spread of MCP and autonomous coding agents.

Evidence excerpt

"Administrators can now apply consistent controls for everyone on your enterprise's Copilot plan" - including allowlists and denylists for MCP servers and disabling the agent's Bypass Approvals and Autopilot modes.

Sources