Manage AI settings in enterprise environments

Organizations can govern AI features in VS Code through three management solutions: Copilot enterprise-managed settings, VS Code device policies, and GitHub organization or enterprise settings.

These solutions control different layers of the AI experience. An organization might use all three, but should configure an overlapping control in only one system.

Note

If you're a developer and an agent, model, or tool is unavailable, first check the AI troubleshooting guidance. For an organization-managed restriction, ask your administrator which capabilities are approved.

Understand the three management solutions

Before you choose a solution, understand where each one is configured and what it controls.

Copilot enterprise-managed settings

Use enterprise-managed settings for Copilot guardrails that should apply across supported clients, such as VS Code and Copilot CLI.

Administrators define these settings with the GitHub-supported server-managed, MDM-managed, or file-based delivery methods. Even when you use an MDM solution, enterprise-managed settings use the Copilot configuration format and delivery path, not the VS Code device-policy namespace.

For server-managed deployments, administrators can override supported settings for specific enterprise teams. GitHub applies the matching values based on each person's enterprise team membership. See Override enterprise-managed settings for teams.

Refer to the enterprise-managed settings setup guide and settings reference for supported keys, client coverage, configuration schemas, and precedence.

VS Code device policies

Use device policies for editor-specific controls on managed VS Code installations.

Administrators deploy these policies through platform management tools, such as Group Policy, Microsoft Intune, or macOS configuration profiles. The policies apply to the managed device and override the corresponding user settings in VS Code.

Refer to the VS Code enterprise policy reference for policy names, accepted values, supported platforms, and minimum versions.

GitHub organization and enterprise settings

Use GitHub organization and enterprise settings for account-level and service-side controls, such as Copilot access, model availability, content exclusions, and organization-provided customizations.

Administrators configure these controls on GitHub. They follow the signed-in GitHub account and its organization or enterprise membership rather than the VS Code device-policy channel.

Refer to Manage Copilot for your enterprise for configuration and reference information about these controls.

Choose a management solution

The solutions are not mutually exclusive. Choose the solution for each control based on the scope you need.

Requirement Management solution Configuration location Scope
Apply consistent Copilot guardrails across supported clients. Copilot enterprise-managed settings GitHub-supported server, MDM, or file delivery Supported Copilot clients and keys
Control a VS Code-specific editor feature on managed devices. VS Code device policies Operating system or device management Managed VS Code installations
Control Copilot access or GitHub-hosted organization and enterprise behavior. GitHub organization or enterprise settings GitHub organization or enterprise administration Signed-in accounts and GitHub-hosted services

Some controls are available through more than one solution. Review the order of precedence before you combine them.

Before a broad rollout, test the proposed configuration with a representative project, device, and account. Confirm that developers can complete approved tasks while the intended restrictions remain in place.

Understand precedence

Across managed-settings delivery methods

When the same managed setting is available from multiple sources, VS Code applies them in this order:

  1. MDM-managed settings.
  2. Server-managed settings.
  3. File-based settings.
  4. User settings.

For most keys, the value from the highest-precedence source wins. Some keys, including permissions.deny, permissions.ask, and permissions.allow, combine restrictions from multiple sources in the most restrictive direction. See Precedence of deployment methods for the complete and current rules.

With VS Code device policies

Some enterprise-managed settings map to a VS Code device policy. When an administrator configures both systems:

  • If the systems configure different controls, both controls apply.
  • If both systems configure the same control, the enterprise-managed setting takes precedence. The values are not merged.
  • If enterprise-managed settings do not provide that control, the VS Code device policy remains in effect.

Configure an overlapping control through one management solution when possible. Run Developer: Policy Diagnostics to inspect the effective value and its source.

Use Copilot enterprise-managed settings

Configure and administer enterprise-managed settings by following the GitHub documentation:

Not every enterprise-managed setting applies to every client. Before you configure a setting for VS Code, check the Supported clients column in the enterprise-managed settings reference.

Verify applied managed settings

Run Developer: Policy Diagnostics in VS Code to inspect effective policy values and their sources. For more information, see Verify policy enforcement.

If the diagnostics show a server-managed source with an unexpected value, check copilot/managed-settings.json, copilot/team-mappings.json, the mapped file under copilot/teams/, and the user's enterprise team memberships. GitHub resolves team overrides before it delivers the server-managed settings to VS Code.

For GitHub-side validation errors or delivery troubleshooting, follow Validate server-managed settings.

Meet minimum version requirements

The managed-settings service can require a minimum VS Code version before AI features are available. When the installed version does not meet the requirement:

  • Chat shows the required and installed versions and provides the appropriate update action.
  • The editor window shows a banner even when Chat is closed. Other editor features remain available.
  • The Agents window shows a blocking notice with an Open Editor Window action.

If built-in updates are disabled by policy, the notice directs the developer to contact an administrator. AI features become available after the installed version meets the requirement.

Apply managed telemetry in VS Code

Managed OpenTelemetry configuration applies to the Copilot Chat extension and Agent Host. The extension might offer Reload Window after a configuration change. VS Code restarts Agent Host automatically after it resolves a managed telemetry change.

Identity capture is off by default and independent of content capture. Review both controls before deployment, and remove conflicting OpenTelemetry environment variables from managed devices. For the configuration schema and supported clients, see telemetry in the enterprise-managed settings reference.

Use VS Code device policies

The following sections describe VS Code device policies. Deploy them by following Enterprise policies, and use the policy reference for accepted values and minimum versions.

Jump to:

Control access and feature availability

Restrict AI features to approved GitHub organizations

Set the ChatApprovedAccountOrganizations policy to require developers to sign in with a GitHub account that belongs to an approved organization before AI features are activated.

Provide a JSON array of GitHub organization logins, such as ["contoso", "contoso-research"]. Use ["*"] to allow any signed-in GitHub account.

The policy is fail-closed. AI features remain disabled until account policy data resolves and the signed-in account belongs to an approved organization. Run Developer: Policy Diagnostics to inspect the Account Policy Gate state.

Enable or disable the use of agents

Set the ChatAgentMode policy to false to disable agents. This policy controls chat.agent.enabled Open in VS Code Open in VS Code Insiders .

When the policy is disabled, the Agent option is not available in the agents dropdown. Developers can still use ask or edit for code explanations and file edits.

Enable or disable extension language tools

Use the following policies to control extension, browser, and plugin tools:

  • Set ChatAgentExtensionTools to false to disable tools contributed by extensions.
  • Set BrowserChatTools to false to disable browser tools.
  • Set ChatPluginsEnabled to false to disable agent plugin integration.

Configure Copilot code review

Use CopilotReviewSelection to control code review for selected code. Use CopilotReviewAgent to control access to the code review agent for pull requests and changed files.

Configure next edit suggestions

Set CopilotNextEditSuggestions to false to disable next edit suggestions.

Enable or disable Claude Agent

Set Claude3PIntegration to false to disable Claude Agent sessions in VS Code.

Configure models and data handling

Set a default chat model

Set the ChatDefaultModel policy to choose the default model for new conversations. This policy controls chat.defaultModel Open in VS Code Open in VS Code Insiders and accepts auto, a model family name, or a full model ID.

Developers can select another model for an individual conversation. Reopened conversations keep their saved model.

Control dictation data

Use the following policies to control whether dictation audio and transcripts leave the developer's device.

Policy Setting Behavior
DictationEnabled dictation.enabled Open in VS Code Open in VS Code Insiders Controls whether built-in dictation is available.
DictationModel dictation.model Open in VS Code Open in VS Code Insiders Selects an on-device model or the mai cloud transcription service.
DictationLLMCleanup dictation.experimental.llmCleanup Open in VS Code Open in VS Code Insiders Controls whether final transcripts are sent to a language model for cleanup.

To keep dictation audio on the device, set DictationModel to nemotron-3.5-asr-streaming-0.6b. In VS Code for the Web, where on-device transcription is not supported, this policy makes dictation unavailable.

To prevent transcript text from being sent to a language model, set DictationLLMCleanup to false. For more information, see Dictation privacy.

Govern agents and tools

Enable or disable hooks

Set the ChatHooks policy to false to disable hooks in the Local harness. This policy controls chat.useHooks Open in VS Code Open in VS Code Insiders and does not apply to Copilot sessions that use Agent Host.

Use the SDK harness for Policy Hooks

Copilot Policy Hooks apply to sessions on the SDK harness, not to sessions that remain on Local.

Set the ChatEditorPreferCopilotHarness policy to true to prefer the SDK harness for new editor chat sessions. This policy controls chat.editor.preferCopilotHarness Open in VS Code Open in VS Code Insiders (Experimental).

The preference does not migrate existing sessions or change explicit or remembered Claude and Codex selections. Check the session target during rollout.

Restrict hook sources

Set ChatAllowManagedHooksOnly to allow hooks only from enterprise-managed sources and plugins that policy force-enables. Set ChatStrictPluginOnlyCustomization when you also need to block standalone user and workspace skills, agents, instructions, and MCP servers.

Plugin distribution is a separate decision. To force-enable plugins or govern marketplaces across supported Copilot clients, use the plugin controls in the enterprise-managed settings reference.

Manage agent plugins and marketplaces

Use the following policies to govern agent plugins in VS Code:

  • ChatEnabledPlugins force-enables or force-disables named plugins.
  • ChatExtraMarketplaces adds plugin marketplaces.
  • ChatStrictMarketplaces restricts plugin installation to approved marketplace sources. An empty list blocks installation from all marketplaces.

Plugins blocked by policy remain visible in the Extensions view but appear disabled. Marketplaces managed by policy are identified in the marketplace picker.

For cross-client plugin governance instead of VS Code-only policy, use Copilot enterprise-managed settings.

Configure agent tool approvals

Use VS Code device policies to control approval behavior for agent tools.

Disable global auto-approval

Set ChatToolsAutoApprove to false to prevent developers from enabling global auto-approval.

Caution

Global auto-approval bypasses security prompts for tool invocations. Disable it unless your threat model explicitly supports this behavior.

Require manual approval for specific tools

Use ChatToolsEligibleForAutoApproval to require manual approval for specific tools.

Configure terminal auto-approval

Set ChatToolsTerminalEnableAutoApprove to false to require approval for terminal commands.

Learn more about tool approval.

Configure security and observability

Configure agent sandboxing

VS Code sandbox device policies are deprecated and apply to Local sessions. They do not enforce sandboxing for Copilot sessions that use Agent Host.

The current enterprise-managed settings reference does not list the shared sandbox key as supported for VS Code. For Agent Host sessions, use the session sandbox controls and verify the effective sandbox policy.

The following deprecated policies preserve Local-session behavior:

Policy Local-session behavior
ChatAgentSandboxEnabled Requires or disables sandboxing for supported terminal commands.
ChatAgentSandboxAllowNetwork Controls outbound network access for sandboxed terminal commands.
ChatAgentSandboxAllowUnsandboxedCommands Controls whether a command can run outside the sandbox after user confirmation.
ChatAgentSandboxAllowAutoApprove Controls automatic approval of sandboxed terminal commands.

Configure agent network filtering

Set ChatAgentNetworkFilter to true to restrict network access according to the allowed and denied domain policies.

Use ChatAgentAllowedNetworkDomains for permitted domain patterns and ChatAgentDeniedNetworkDomains for blocked patterns. Denied domains take precedence.

Network filtering applies to the fetch tool and Integrated Browser. Terminal coverage depends on the session target, platform, and sandbox configuration. See Configure sandbox network access.

Restart VS Code after you change network filtering settings so new Integrated Browser sessions use the updated policy.

Configure telemetry export with OpenTelemetry

Use the CopilotOtel* policies to control OpenTelemetry export for Copilot in VS Code. These policies cover export enablement, the collector endpoint and protocol, content and identity capture, the service name, resource attributes, and exporter headers.

For the complete list of policies and the settings they control, see the enterprise policy reference.

Use GitHub organization and enterprise settings

GitHub-hosted controls apply through the signed-in account and GitHub services. They are not VS Code device policies.

Use GitHub organization and enterprise settings to manage Copilot access, available models and features, content exclusions, and other service-side policies. See Manage Copilot for your enterprise.

Configure organization-level custom instructions

Organization administrators create custom instructions on GitHub. When github.copilot.chat.organizationInstructions.enabled Open in VS Code Open in VS Code Insiders is true, supported Copilot sessions in VS Code include organization instructions that the signed-in account can access.

Learn how to add custom instructions for your organization.

Configure organization-level custom agents

Organization administrators create custom agents on GitHub. When github.copilot.chat.organizationCustomAgents.enabled Open in VS Code Open in VS Code Insiders is true, organization and enterprise agents that the signed-in account can access appear in the agents dropdown.

Learn how to create custom agents for your organization.

Security considerations

AI-powered development features can perform actions with user-level permissions. Review AI security considerations before enabling agents or auto-approval.

For Copilot security, privacy, compliance, and transparency information, see the Copilot Trust Center FAQ.