Skip to main content

Restrict MCP server access to a custom registry

You can configure an MCP registry URL and access control policy to determine which MCP servers developers can discover and use in supported IDEs and Copilot CLI.

Wer kann dieses Feature verwenden?

Enterprise owners and organization owners

Copilot Enterprise or Copilot Business

Wichtig

This feature is in Öffentliche Vorschau and is not the recommended method for restricting access to MCP servers. The more secure, generally available method is to define settings in your enterprise's managed-settings.json file. See Configuring an MCP server allowlist for your enterprise.

Prerequisites

Before you can fully configure MCP server access for your company, you need to create an MCP registry. See Konfigurieren einer MCP-Registrierung für Ihre Organisation oder Ihr Unternehmen.

Configuring the MCP allowlist policy for an enterprise

To ensure uniform access, you can set and maintain your MCP registry URL and allowlist policy at the enterprise level. Otherwise, if your teams have different needs, you should configure separate policies for each organization.

  1. Navigieren Sie zu Ihrem Unternehmen. Beispielsweise auf der Seite Unternehmen in GitHub.com.

  2. Klicken Sie oben auf der Seite auf AI-Steuerelemente.

  3. Klicken Sie in der Randleiste auf MCP.

  4. Ensure MCP servers in Copilot is set to Enabled everywhere.

  5. In the MCP Registry URL section, enter the URL of your registry, then click Save.

    Hinweis

    Wenn Sie Ihre MCP-Registrierung mit Azure API Center einrichten, geben Sie die Basis-URL für Ihr API Center ein, einschließlich des Arbeitsbereichspfads, im Format:

    https://SERVICE-NAME.data.REGION.azure-apicenter.ms/workspaces/WORKSPACE-NAME
    

    Beispiel:

    https://contoso-apic.data.eastus.azure-apicenter.ms/workspaces/default
    

    Das Einschließen zusätzlicher Routensuffixe wie /v0.1/servers führt zu einem Fehler in der Registrierung, da GitHub Copilot den MCP-v0.1-Pfad automatisch anhängt.

  6. In the Restrict MCP access to registry servers section, select the dropdown menu, then click one of the following options:

    • Allow all: No restrictions. All MCP servers can be used.
    • Registry only: Only servers from the registry may run.

    Your chosen policy will immediately apply to developers in your enterprise.

Configuring the MCP allowlist policy for an organization

  1. Klicke in der rechten oberen Ecke von GitHub auf dein Profilbild und dann auf Your organizations.

  2. Wählen Sie eine Organisation aus, indem Sie darauf klicken.

  3. Klicke unter dem Organisationsnamen auf Settings. Wenn die Registerkarte „Einstellungen“ nicht angezeigt wird, wähle im Dropdownmenü die Option Einstellungen aus.

    Screenshot der Registerkarten im Profil einer Organisation. Die Registerkarte „Einstellungen“ ist dunkelorange umrandet.

  4. In der Randleiste unter "Code, Planung und Automatisierung" click Copilot, then click Policies.

  5. In the "Features" section, ensure MCP servers in Copilot is set to Enabled.

  6. In the MCP Registry URL (optional) field, enter the URL of your registry, then click Save.

    Hinweis

    Wenn Sie Ihre MCP-Registrierung mit Azure API Center einrichten, geben Sie die Basis-URL für Ihr API Center ein, einschließlich des Arbeitsbereichspfads, im Format:

    https://SERVICE-NAME.data.REGION.azure-apicenter.ms/workspaces/WORKSPACE-NAME
    

    Beispiel:

    https://contoso-apic.data.eastus.azure-apicenter.ms/workspaces/default
    

    Das Einschließen zusätzlicher Routensuffixe wie /v0.1/servers führt zu einem Fehler in der Registrierung, da GitHub Copilot den MCP-v0.1-Pfad automatisch anhängt.

  7. In the Restrict MCP access to registry servers section, select the dropdown menu, then click one of the following options:

    • Allow all: No restrictions. All MCP servers can be used.
    • Registry only: Only servers from the registry may run.

    Your chosen policy will immediately apply to developers in your organization.

Next steps

For detailed information on MCP allowlist enforcement and limitations, see MCP private registry enforcement.

Further reading