Enterprise-managed sandbox in Copilot for JetBrains
Administrators can now lock filesystem, network, and proxy settings for Copilot's sandbox in JetBrains IDEs, overriding user choices.
GitHub Copilot for JetBrains IDEs now supports enterprise-managed sandbox policies, in public preview. Administrators can centrally configure how the local sandbox restricts a developer's filesystem access, network connectivity, and other system capabilities, instead of leaving those settings to each user.
Managed policies can control sandbox enablement, filesystem and network access, proxy settings, developer-tool access, and macOS Keychain access, among other settings. Where a managed policy sets a value, it takes precedence over the user's own choice: Copilot locks the affected control in the IDE and marks it as managed by the organization.
The sandbox settings appear under GitHub Copilot > Sandbox only when an organization enables the Editor Preview feature flag or configures a managed setting to turn the sandbox on or off; otherwise they stay hidden.
