GitHub says local sandboxing for Copilot is now generally available in Copilot CLI, the Copilot app and VS Code sessions using Agent Host. It lets developers set limits on what commands run by Copilot can access on their machines.
Sandbox policies can restrict which files and directories those commands read or change. They can also control access to the internet, local networks, Git credentials and GitHub CLI credentials, according to GitHub.
The company says the controls can extend to local tools and services, including local MCP and language servers where supported. Organizations can use enterprise-managed settings to require sandboxing and enforce policies that developers cannot weaken.
Read nextMicrosoft Gives Copilot Access to Local Files and Deeper Windows ControlLocal sandboxing uses Microsoft eXecution Container
Local sandboxing uses Microsoft eXecution Container, or MXC. GitHub says it translates a common policy into operating-system controls on Windows, macOS and Linux. The restrictions apply to tool execution regardless of which model Copilot uses.
GitHub says local sandboxing is included with Copilot at no additional cost. It is available now in Copilot CLI, the Copilot app and VS Code sessions using Agent Host.



