GitHub Copilot default feature policy hits October 22. Set it
GitHub Copilot Business and Enterprise get a default policy for new features on October 22. Unconfigured GA features, including MCP servers, follow it. Set it now.
GitHub Copilot is getting a default policy for new features, and it takes effect on October 22. GitHub announced the change on September 24 for Copilot Business and Enterprise. After the date, every generally available Copilot feature you have not configured follows one global setting. That includes the policy for MCP servers in Copilot. If you have not looked at your AI Controls page, you have three weeks to decide what your team's coding agent is allowed to turn on.
What actually happened
Per the GitHub changelog, admins now see a "Default policy for new features" option under AI Controls → Copilot at the enterprise and organization level. There are three choices:
- Enabled: current and future eligible features are on for users by default
- Disabled: current eligible features stay off, and future ones need admin approval
- Let organizations decide: each org admin makes the call
The policy covers generally available features and client capabilities, including the Copilot Code Review policy and the MCP servers in Copilot policy. Preview features stay opt-in. Features you have already set by hand keep your setting. Anything left "Unconfigured" follows the global default once the policy goes live on October 22.
Why the Copilot default policy matters for your business
This is a small settings change with a big blast radius. "Unconfigured" is the state most small teams are in, because nobody owns the Copilot admin page. After October 22, that default decides what ships to your developers without a ticket, a review or a Slack message.
MCP servers are the item to watch. An MCP server gives the coding agent tools: database access, cloud APIs, your issue tracker. Turning that on by default for a whole org is a permissions decision, not a productivity toggle.
Our recommendation for most small teams:
- Set the global default to Disabled. New GA features then need an admin to approve them. You lose nothing you use today if you configure those features explicitly first.
- Explicitly enable what you already rely on (completions, chat, code review) so it does not change under you.
- Keep an allowlist for MCP servers. Approve each one and note what credentials it holds.
- Put a quarterly reminder on the calendar to review new features. Deliberate adoption beats surprise adoption.
Key takeaways
- GitHub Copilot Business and Enterprise get a global "Default policy for new features" on October 22, 2026
- Options are Enabled, Disabled, or Let organizations decide
- Unconfigured GA features, including the MCP servers policy and Copilot Code Review, follow the default
- Preview features stay opt-in, and settings you already made are kept
- Set it to Disabled, explicitly enable what you use, and allowlist MCP servers
Your coding agent's permissions should be a decision, not a default. We set up AI dev tooling with scoped MCP servers, written policies and audit logs, so you know what every agent can touch. See how we build governed AI dev workflows, or ask us to review your Copilot and MCP settings before October 22.
Sources: GitHub Changelog.
- #github-copilot
- #ai-governance
- #mcp
- #developer-tools
- #ai-coding
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
iOS 26.7.1 fixes exploited CoreGraphics bug CVE-2026-86950
Apple patched CVE-2026-86950, a CoreGraphics flaw that may have been exploited, in iOS 26.7.1 and macOS Tahoe 26.7.1. Staying on iOS 26 is fine, unpatched is not.
Read itSign in with ChatGPT: the user's plan pays your bill
OpenAI's Sign in with ChatGPT lets Plus and Pro users spend their own plan allowance inside 16 partner tools, with per-app weekly caps. What it does to your margins.
Read it