Skip to main content

Enterprise managed settings

Understand the enterprise managed settings schema used by Copilot clients.

Use this reference to understand the currently supported keys in managed-settings.json.

For deployment methods and supported clients, see Настройка параметров, управляемых предприятием.

Precedence rules

When multiple settings sources are present, settings earlier in this list take precedence over settings later in the list:

  1. MDM-managed settings
  2. Server-managed settings
  3. File-based settings
  4. User-level settings

Supported keys

KeyPurposeВторой пилот CLIVS Codeприложение GitHub CopilotCopilot облачный агент
permissions.disableBypassPermissionsModeDisables bypass or YOLO-style allow-all behavior
permissions.modelSets auto model selection as the default for new conversations
enabledPluginsEnables or disables specific plugins by key
extraKnownMarketplacesAdds plugin marketplaces that users can access
strictKnownMarketplacesRestricts plugin installation to explicitly listed marketplaces
telemetryConfigures OpenTelemetry export, routing Copilot usage data to a collector of your choice
remoteControlRestricts whether sessions hosted on this device can be remotely controlled, based on the controlling client's SSO authorization status for the listed organizations. Doesn't affect the user's ability to remotely control sessions hosted on other devices

Applying different settings to enterprise teams

For server-managed deployments, the enterprise can apply different governance to groups of users based on their enterprise team membership. The enterprise defines all settings—team membership only determines which users receive a given set of values.

To make a key eligible for team-specific values, mark it as overridable in managed-settings.json using the { "overridable": <VALUE> } syntax. An overridable key uses the team's value when set, or falls back to your enterprise default when the team leaves it unset. The { "overridable": <VALUE> } syntax applies to the governance keys permissions.model and permissions.disableBypassPermissionsMode. Keys not marked overridable remain an enterprise-level decision that teams can't modify. enabledPlugins and extraKnownMarketplaces work additively. The enterprise managed-settings.json sets a baseline, and an enterprise team file can add more plugins and marketplaces on top of it. For the full setup steps, see Настройка параметров, управляемых предприятием.

Example configuration

The following example shows these keys in one managed settings file.

{
  "permissions": {
    "disableBypassPermissionsMode": "disable",
    "model": "auto"
  },
  "enabledPlugins": {
    "my-plugin@agent-skills": true
  },
  "extraKnownMarketplaces": {
    "agent-skills": {
      "source": {
        "source": "github",
        "repo": "OWNER/REPO"
      }
    }
  },
  "strictKnownMarketplaces": [
    {
      "source": "github",
      "repo": "OWNER/REPO"
    }
  ],
  "telemetry": {
    "enabled": true,
    "endpoint": "https://otel-collector.example.com",
    "protocol": "http/protobuf",
    "captureContent": false,
    "lockCaptureContent": true,
    "serviceName": "copilot",
    "resourceAttributes": {
      "deployment.environment": "production"
    },
    "headers": {
      "Authorization": "Bearer TOKEN"
    }
  },
  "remoteControl": {
    "mode": "requireSSO",
    "githubDotComOrganizations": ["ORG-NAME"]
  }
}

enabledPlugins

Defines plugins that are automatically installed or blocked for all enterprise users. Each entry uses the format PLUGIN-NAME@MARKETPLACE-NAME as the key, with a boolean value: true to require the plugin to be enabled, or false to require it to be disabled. See О стандартах плагинов, управляемых корпоративным предприятием.

extraKnownMarketplaces

Defines additional plugin marketplaces available to users. Each entry is a named marketplace object containing a source property. The following source types are supported:

  • "github" — requires repo in OWNER/REPO format; optional ref (branch, tag, or SHA) and path (subdirectory)
  • "git" — requires url; optional ref and path
  • "directory" — requires path

See О стандартах плагинов, управляемых корпоративным предприятием.

strictKnownMarketplaces

Restricts plugin installation to only the marketplaces explicitly defined by the enterprise. An empty array means complete lockdown. Each entry is a marketplace object with a source property indicating the source type. The following source types are supported:

  • "github" — requires repo in OWNER/REPO format; optional ref and path
  • "git" — requires url; optional ref and path
  • "url" — requires url; optional headers object
  • "npm" — requires package
  • "file" — requires path
  • "directory" — requires path
  • "hostPattern" — requires hostPattern (regex matching marketplace hosts)
  • "pathPattern" — requires pathPattern (regex matching marketplace paths)

permissions

disableBypassPermissionsMode

Prevents users from enabling bypass mode (also known as "YOLO mode"). Bypass mode lets an agent run commands, access files, and fetch URLs without asking for approval.

When you set disableBypassPermissionsMode to "disable", users cannot turn on bypass mode:

  • In Второй пилот CLI, all of the command line options for allowing all permissions (--yolo, --allow-all, and the individual --allow-all-tools, --allow-all-paths, and --allow-all-urls options) are suppressed at startup and cannot grant elevated permissions. The /yolo and /allow-all slash commands are also blocked.
  • In VS Code, the global auto-approve setting (chat.tools.global.autoApprove) is turned off and cannot be re-enabled.
  • In the приложение GitHub Copilot, the "Allow all" setting for "Tool Permissions" is blocked in the sessions settings.
  • This key is overridable by enterprise team mapping. In your managed-settings.json, use the { "overridable": "disable" } syntax to specialize the key's configuration on a per-team basis. You can then set "disableBypassPermissionsMode": "unmanaged" in a team settings file, providing a specialization that takes precedence over managed-settings.json for members of the subject team.

model

Sets auto model selection as the default for new conversations. See О компании Copilotвыбор автоматической модели.

  • When you set permissions.model to "auto", new sessions use Auto model unless the user specifies a different model on a per-conversation basis.
  • This key is overridable by enterprise team mapping. In your managed-settings.json, use the { "overridable": "auto" } syntax to specialize the key's configuration on a per-team basis. You can then set "model": "unmanaged" in a team settings file, providing a specialization that takes precedence over managed-settings.json for members of the subject team.

telemetry

Configures OpenTelemetry export, routing Copilot usage data to a collector of your choice.

This property is supported for Второй пилот CLI and VS Code.

When you set the telemetry property, Copilot telemetry is sent to the endpoint you specify. The following sub-properties are supported:

  • enabled: Set to true to turn on telemetry export, or false to turn it off.
  • endpoint: The URL of your OTLP collector (for example, https://otel-collector.example.com).
  • protocol: The transport protocol for telemetry export. Accepted values are "http/json" and "http/protobuf".
  • captureContent: Set to true to include prompt and response content in the telemetry payload, or false to exclude it.
  • lockCaptureContent: Set to true to prevent users from changing the captureContent setting.
  • serviceName: A label for the telemetry service name (for example, "copilot").
  • resourceAttributes: An object of OpenTelemetry resource attributes to attach to all exported telemetry (for example, {"deployment.environment": "production"}).
  • headers: An object of HTTP headers to include with each telemetry request (for example, an Authorization header for your collector).

remoteControl

Restricts whether Copilot sessions hosted on a device can be remotely controlled. This doesn't affect a user's ability to remotely control their sessions hosted on other devices.

  • mode: Set to "disabled" to prevent remote control of sessions on the device, "requireSSO" to only allow remote control from a client that is SSO-authorized for the organizations listed in githubDotComOrganizations, or "enabled" to allow it unrestricted.
  • githubDotComOrganizations: An array of organization logins. Required when mode is "requireSSO".