Local sandboxing for GitHub Copilot now generally available
By Steven Van ·
Included at no extra cost, local sandboxing lets developers restrict file, network and credential access for Copilot tools.
Developers can now restrict what Copilot’s local commands and tools can access on their machines. Local sandboxing is generally available in GitHub Copilot CLI, the Copilot app, and VS Code sessions using Agent Host, at no additional cost.
Enable it for local sessions
Local sandboxing is off by default. In Copilot CLI, running /sandbox enable turns it on and saves the setting for future sessions. In the Copilot app, project settings define the default for new local repository and working tree sessions, and sandboxing can be changed for an active session. Settings are configured separately in the CLI and app.
Control files, networks and credentials
Policies can grant read-only or read/write access to specific paths, deny paths, control internet and local network access, and decide whether Git and GitHub CLI credentials are available. The CLI also offers controls for local MCP and language servers, macOS keychain access, and per-command exceptions. The app exposes a subset of these controls and can request approval to run an individual command outside the sandbox.
Enterprises can require sandboxing and enforce its configuration through managed settings. Sandbox policies apply to tool execution regardless of which model Copilot uses.
Operating-system isolation
Microsoft eXecution Container (MXC) translates policies into native controls on macOS, Linux and recent Windows 11 builds. This restricts process access without placing commands inside a separate virtual machine or container. CLI built-in file tools run outside the operating-system sandbox and check the policy themselves on a best-effort basis.
Platform requirements and network restrictions vary. GitHub recommends macOS 15 or later; Linux requires bubblewrap 0.5.0 or later, with additional dependencies for outbound traffic. Windows requires a supported Windows 11 update, and proxy rules rely on programs honoring proxy settings. The sandbox documentation details the requirements and policy controls.
