Changes confirmed medium confidence

GitHub Extends Copilot Default Policy to Eligible Features and Clients

Business and Enterprise administrators can set one default for unconfigured generally available capabilities before the policy begins applying on October 22.

Edited by Tyronne Panaino

GitHub introduced a broader global default policy for generally available Copilot features and supported client capabilities on September 24, 2026. Enterprise and organization administrators can configure the setting now, while GitHub says it will not affect users until October 22.

The change matters to Copilot Business and Copilot Enterprise customers because it creates one decision point for eligible capabilities that have not received an explicit administrator choice. The announced scope includes features on the enterprise Features and clients page, Copilot Code Review policy on the Agents page, and the MCP servers in Copilot policy.

One default can cover several Copilot surfaces

Administrators can choose among three global outcomes. `Enabled` makes current and future eligible features available by default. `Disabled` keeps current eligible features unavailable and requires administrator approval for future ones. `Let organizations decide` delegates the enable-or-disable choice to organization administrators.

The policy therefore changes the treatment of an unconfigured capability, not every capability indiscriminately. GitHub says the setting applies to eligible generally available features and supported clients. The announcement does not identify every feature that will qualify, so administrators still need the linked eligibility documentation and their own account view to determine the exact scope.

For managed environments, the practical effect is a clearer governance default. A company that accepts automatic access can avoid a separate decision for every eligible general-availability change. A company that requires review before access can choose the disabled position, while a multi-organization enterprise can leave the decision with organization administrators.

October 22 is the operating checkpoint

The setting is configurable during a 28-day preparation period. GitHub says the selected default begins applying on October 22 to eligible generally available features and capabilities that remain unconfigured. Administrators therefore have time to choose a policy before it changes user access.

The release preserves decisions already made. A feature that an administrator explicitly enabled or disabled will keep that choice rather than being overwritten by the new global setting. That distinction lets teams combine a broad default with exceptions for capabilities they have already reviewed.

Preview features remain outside the automatic path. GitHub says previews continue to require opt-in, and a preview that later becomes generally available keeps the existing choice. The policy is therefore not a blanket switch that silently activates every experimental Copilot capability.

What administrators should review

The immediate task is to inspect the AI Controls area, choose the intended global default, and compare that choice with explicit feature settings already on the account. Teams should also review who owns the decision when `Let organizations decide` is selected, because the authority moves from the enterprise default to organization administrators.

MCP-server and code-review controls deserve separate attention because they affect how Copilot can interact with development workflows, not just which interface a user sees. The announcement confirms that those policy surfaces fall within the new default structure, but it does not provide independent evidence about rollout behavior in every enterprise configuration.

The next verifiable checkpoint is October 22, when eligible unconfigured capabilities are due to begin following the selected default. Until then, the setting is a preparation control rather than proof that user access has already changed.

Status

Confirmed. Internal confidence: Medium. GitHub's official changelog supports the policy, its scope and the October 22 effective date, but this run did not independently test an enterprise account or verify which capabilities GitHub will classify as eligible at activation.

Sources

Update note: Last reviewed 2026-09-25. We will revise this post if GitHub changes the effective date, eligibility rules or administrator choices.

Sources

Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.

More Changes coverage