
Local sandboxing for GitHub Copilot now generally available
Quick Answer
Local sandboxing for GitHub Copilot is now available, providing a secure execution environment for workflows on developers' machines.
Quick Take
Powered by Microsoft eXecution Container (MXC), it restricts access to files, networks, and credentials, ensuring compliance with organizational policies without additional costs.
Key Points
- Local sandboxes restrict access to filesystem, network, and credentials based on developer-defined policies.
- MXC translates sandbox policies into native controls across Windows, macOS, and Linux.
- Developers can enforce enterprise-managed settings to require sandboxing.
- Local sandboxing supports isolation for local tools and services, enhancing security.
- Included with GitHub Copilot at no additional cost.
📖 Reader Mode
~1 min readLocal sandboxing for GitHub Copilot is now generally available in GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host.
Local sandboxes give developers a secure execution boundary for agentic workflows on their own machines. Tools and commands initiated by Copilot run with restricted access to the filesystem, network, credentials, and other system capabilities, based on policies defined by the developer or their organization.
Local sandboxing is powered by Microsoft eXecution Container (MXC), which translates a common sandbox policy into native operating-system controls across Windows, macOS, and Linux.
With local sandboxing, developers and organizations can:
- Limit the files and directories that agent-run commands can read or modify.
- Control access to the internet, local networks, Git credentials, and GitHub CLI credentials.
- Apply sandboxing to local tools and services, including local MCP and language servers where supported.
- Use enterprise-managed settings to require sandboxing and enforce policies that developers cannot weaken.
- Adopt more autonomous agent workflows while maintaining clear boundaries around what Copilot can access.
Model execution and tool isolation are separate concerns. Sandbox policies apply to tool execution regardless of which model Copilot uses.
Local sandboxing is included with GitHub Copilot at no additional cost. To get started, see About cloud and local sandboxes for GitHub Copilot.
— Originally published at github.blog
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from GitHub Copilot Changelog
See more →
GitHub Copilot for JetBrains adds improved OpenTelemetry configuration and model management
The latest GitHub Copilot for JetBrains update enhances workflow control with OpenTelemetry configuration, improved model management, and support for servers in Claude agent flows, facilitating better observability and cost control for enterprise users.
