Use this reference to understand the currently supported keys in managed-settings.json.
For deployment methods and supported clients, see Konfigurieren von unternehmensverwalteten Einstellungen.
Precedence rules
When multiple settings sources are present, settings earlier in this list take precedence over settings later in the list:
- MDM-managed settings
- Server-managed settings
- File-based settings
- User-level settings
Supported keys
| Key | Purpose | Copilot CLI | VS Code | GitHub Copilot App | Copilot-Cloud-Agent |
|---|---|---|---|---|---|
permissions.disable | Disables bypass or YOLO-style allow-all behavior | ||||
permissions.model | Sets auto model selection as the default for new conversations | ||||
enabledPlugins | Enables or disables specific plugins by key | ||||
extra | Adds plugin marketplaces that users can access | ||||
strict | Restricts plugin installation to explicitly listed marketplaces | ||||
telemetry | Configures OpenTelemetry export, routing Copilot usage data to a collector of your choice | ||||
remoteControl | Restricts whether sessions hosted on this device can be remotely controlled, based on the controlling client's SSO authorization status for the listed organizations. Doesn't affect the user's ability to remotely control sessions hosted on other devices |
Applying different settings to enterprise teams
For server-managed deployments, the enterprise can apply different governance to groups of users based on their enterprise team membership. The enterprise defines all settings—team membership only determines which users receive a given set of values.
To make a key eligible for team-specific values, mark it as overridable in managed-settings.json using the { "overridable": <VALUE> } syntax. An overridable key uses the team's value when set, or falls back to your enterprise default when the team leaves it unset. The { "overridable": <VALUE> } syntax applies to the governance keys permissions.model and permissions.disableBypassPermissionsMode. Keys not marked overridable remain an enterprise-level decision that teams can't modify. enabledPlugins and extraKnownMarketplaces work additively. The enterprise managed-settings.json sets a baseline, and an enterprise team file can add more plugins and marketplaces on top of it. For the full setup steps, see Konfigurieren von unternehmensverwalteten Einstellungen.
Example configuration
The following example shows these keys in one managed settings file.
{
"permissions": {
"disableBypassPermissionsMode": "disable",
"model": "auto"
},
"enabledPlugins": {
"my-plugin@agent-skills": true
},
"extraKnownMarketplaces": {
"agent-skills": {
"source": {
"source": "github",
"repo": "OWNER/REPO"
}
}
},
"strictKnownMarketplaces": [
{
"source": "github",
"repo": "OWNER/REPO"
}
],
"telemetry": {
"enabled": true,
"endpoint": "https://otel-collector.example.com",
"protocol": "http/protobuf",
"captureContent": false,
"lockCaptureContent": true,
"serviceName": "copilot",
"resourceAttributes": {
"deployment.environment": "production"
},
"headers": {
"Authorization": "Bearer TOKEN"
}
},
"remoteControl": {
"mode": "requireSSO",
"githubDotComOrganizations": ["ORG-NAME"]
}
}
enabledPlugins
Defines plugins that are automatically installed or blocked for all enterprise users. Each entry uses the format PLUGIN-NAME@MARKETPLACE-NAME as the key, with a boolean value: true to require the plugin to be enabled, or false to require it to be disabled. See Informationen zu unternehmensverwalteten Plug-In-Standards.
extraKnownMarketplaces
Defines additional plugin marketplaces available to users. Each entry is a named marketplace object containing a source property. The following source types are supported:
"github"— requiresrepoinOWNER/REPOformat; optionalref(branch, tag, or SHA) andpath(subdirectory)"git"— requiresurl; optionalrefandpath"directory"— requirespath
See Informationen zu unternehmensverwalteten Plug-In-Standards.
strictKnownMarketplaces
Restricts plugin installation to only the marketplaces explicitly defined by the enterprise. An empty array means complete lockdown. Each entry is a marketplace object with a source property indicating the source type. The following source types are supported:
"github"— requiresrepoinOWNER/REPOformat; optionalrefandpath"git"— requiresurl; optionalrefandpath"url"— requiresurl; optionalheadersobject"npm"— requirespackage"file"— requirespath"directory"— requirespath"hostPattern"— requireshostPattern(regex matching marketplace hosts)"pathPattern"— requirespathPattern(regex matching marketplace paths)
permissions
disableBypassPermissionsMode
Prevents users from enabling bypass mode (also known as "YOLO mode"). Bypass mode lets an agent run commands, access files, and fetch URLs without asking for approval.
When you set disableBypassPermissionsMode to "disable", users cannot turn on bypass mode:
- In Copilot CLI, all of the command line options for allowing all permissions (
--yolo,--allow-all, and the individual--allow-all-tools,--allow-all-paths, and--allow-all-urlsoptions) are suppressed at startup and cannot grant elevated permissions. The/yoloand/allow-allslash commands are also blocked. - In VS Code, the global auto-approve setting (
chat.tools.global.autoApprove) is turned off and cannot be re-enabled. - In the GitHub Copilot App, the "Allow all" setting for "Tool Permissions" is blocked in the sessions settings.
- This key is overridable by enterprise team mapping. In your
managed-settings.json, use the{ "overridable": "disable" }syntax to specialize the key's configuration on a per-team basis. You can then set"disableBypassPermissionsMode": "unmanaged"in a team settings file, providing a specialization that takes precedence overmanaged-settings.jsonfor members of the subject team.
model
Sets auto model selection as the default for new conversations. See Über CopilotAutomatische Modellauswahl.
- When you set
permissions.modelto"auto", new sessions use Auto model unless the user specifies a different model on a per-conversation basis. - This key is overridable by enterprise team mapping. In your
managed-settings.json, use the{ "overridable": "auto" }syntax to specialize the key's configuration on a per-team basis. You can then set"model": "unmanaged"in a team settings file, providing a specialization that takes precedence overmanaged-settings.jsonfor members of the subject team.
telemetry
Configures OpenTelemetry export, routing Copilot usage data to a collector of your choice.
This property is supported for Copilot CLI and VS Code.
When you set the telemetry property, Copilot telemetry is sent to the endpoint you specify. The following sub-properties are supported:
enabled: Set totrueto turn on telemetry export, orfalseto turn it off.endpoint: The URL of your OTLP collector (for example,https://otel-collector.example.com).protocol: The transport protocol for telemetry export. Accepted values are"http/json"and"http/protobuf".captureContent: Set totrueto include prompt and response content in the telemetry payload, orfalseto exclude it.lockCaptureContent: Set totrueto prevent users from changing thecaptureContentsetting.serviceName: A label for the telemetry service name (for example,"copilot").resourceAttributes: An object of OpenTelemetry resource attributes to attach to all exported telemetry (for example,{"deployment.environment": "production"}).headers: An object of HTTP headers to include with each telemetry request (for example, anAuthorizationheader for your collector).
remoteControl
Restricts whether Copilot sessions hosted on a device can be remotely controlled. This doesn't affect a user's ability to remotely control their sessions hosted on other devices.
mode: Set to"disabled"to prevent remote control of sessions on the device,"requireSSO"to only allow remote control from a client that is SSO-authorized for the organizations listed ingithubDotComOrganizations, or"enabled"to allow it unrestricted.githubDotComOrganizations: An array of organization logins. Required whenmodeis"requireSSO".