Copilot Local Sandboxing Is Now Generally Available

GitHub CopilotView original changelog

GitHub made local sandboxing for GitHub Copilot generally available in Copilot CLI, the GitHub Copilot app and VS Code sessions that use Agent Host. Commands and tools started by Copilot now run with limited access to files, network and credentials under rules set by the developer or organization. The feature is built on Microsoft eXecution Container (MXC) and is included with Copilot at no extra charge.

Key Takeaways

  • Local sandboxing is now generally available, moving out of the public preview that began earlier in 2026.
  • It covers Copilot CLI, the GitHub Copilot app and VS Code Agent Host sessions.
  • Sandbox rules limit file, network and credential access for commands Copilot runs.
  • A single policy maps to native controls on Windows, macOS and Linux through Microsoft eXecution Container.
  • Policies apply to tool execution regardless of the model in use and can extend to local MCP and language servers.
  • It is included at no additional charge, and enterprises can require it through managed settings.

A Secure Boundary on the Developer's Own Machine

GitHub announced that local sandboxing for GitHub Copilot is now generally available in Copilot CLI, the GitHub Copilot app, and VS Code sessions that use Agent Host. It gives developers a security boundary on their own machines: commands and tools that Copilot launches run with limited access to files, network, credentials and other system features, based on rules set by the developer or their organization.

Built on Microsoft eXecution Container

Local sandboxing is built on Microsoft eXecution Container (MXC), which maps a single shared sandbox policy to the native controls on Windows, macOS and Linux. Because the policy applies to tool execution, it works the same regardless of which model Copilot is using.

What Can Be Controlled

Developers can restrict which files and directories agent-run commands may read or change, and control access to the internet, local networks, and Git and GitHub CLI credentials. Sandboxing can also be applied to local tools and services, including local MCP servers and language servers where supported. Organizations can use enterprise-managed settings to require sandboxing and prevent developers from weakening the policy.

Cost

Local sandboxing is included with GitHub Copilot at no additional charge. The feature was previously in public preview, and GitHub documents it under "About cloud and local sandboxes for GitHub Copilot."

Copilot Local Sandboxing Is Now Generally Available | Yet Another Changelog