GitHub Copilot Makes Local Sandboxing Generally Available Across 3 Surfaces
Updated
Updated · github.blog · Oct 7
GitHub Copilot Makes Local Sandboxing Generally Available Across 3 Surfaces
3 articles · Updated · github.blog · Oct 7
Summary
GitHub Copilot’s local sandboxing is now generally available in the CLI, Copilot app, and VS Code sessions using Agent Host, giving agent workflows a secure execution boundary on developers’ own machines.
MXC powers the feature by translating one sandbox policy into native controls on Windows, macOS, and Linux, restricting filesystem, network, credential, and other system access for Copilot-initiated tools and commands.
Developers and organizations can limit which files agents read or modify, control internet and local-network access, and apply the same isolation to local tools and services, including supported MCP and language servers.
Enterprise-managed settings can require sandboxing and enforce policies developers cannot weaken, separating tool-execution controls from model choice as Copilot expands local and more autonomous workflows.