Skip to content
← Back to blog
GitHubArticle

GitHub Copilot on 22 October 2026: Review the Default Policy

GitHub Copilot's default feature policy takes effect on 22 October. Check Unconfigured features, explicit admin choices, previews and team access.

Author

Syntalith

Published Updated 2 min read

GitHub Copilot Business and Enterprise administrators have a new default feature-availability policy to review. Announced on 24 September, it takes effect on 22 October 2026. The interval gives organisations time to decide how eligible features left without an explicit choice should behave.

Explicitly enabled or disabled settings are preserved. Preview features remain opt-in. The change concerns eligible generally available features marked Unconfigured. GitHub announcement, checked on 1 October 2026.

Find the setting

GitHub specifies AI Controls → Copilot → Default policy for new features. The available choices are Enabled, Disabled and Let organizations decide. The last option delegates the decision to organisation administrators within GitHub's documented scope.

Eligible settings include Features & clients, the Copilot Code Review policy and the policy for MCP servers in Copilot. Check the eligibility details linked from the announcement. The setting's name should not be read as covering every product capability.

Review the current states

Current stateWhat to check before 22 October
Explicitly enabledOwnership and the accepted scope of use
Explicitly disabledWhether the decision remains appropriate; the global change preserves it
Eligible GA feature marked UnconfiguredWhich selected default it will follow
Preview featureWhether someone previously opted in
Decisions delegated to organisationsWhether each organisation has a responsible administrator

Enabling a capability does not replace authentication to another service. Permitting MCP does not create a CRM account or grant access to a private database. Review the actual tools configured in the organisation separately.

Run a short review with the team

List the organisations and current settings. Record the date, feature, state and decision owner. Keep tokens and repository contents out of this register.

Select a small user group and a representative task for any capability you intend to introduce. Check the resulting access. Record both the decision and what would trigger another review, such as adding an MCP server.

Explain the changes to developers before adjusting broader defaults. After 22 October, confirm the effective behaviour using an ordinary member account. An administrator's settings view does not establish the complete member experience.

Make tool decisions specific

A documentation server might permit reading material already available to the user. A tool that creates issues also needs write and retry rules. These are example organisational decisions; they must be implemented for the particular server rather than assumed to be universal Copilot settings.

Record the owner, permitted operations and how access will be withdrawn. The Copilot MCP and Code Review guide explains the difference between feature policy and tool permissions.

Scope the work before pricing it

A configuration review depends on the number of organisations, integrations and required deliverables. There is no single price for every Copilot environment. Syntalith's process audit starts at €600 excluding VAT; technical team enablement needs a separate scope. See pricing.

For a free initial discussion, bring the number of organisations, the features used and a description of the developers' work. We can help prepare decisions, configuration and a repository trial. The useful outcome is an understood, controlled tool setup that the team can maintain.

Free process scan

Start with a free process scan.

  • A 30-minute call with the engineer who would lead the work.
  • A review of the processes that cost you the most time and money.
  • A written summary: a possible direction, missing information and the next step.

The scan chooses one process to assess, and within 2 business days you receive a recommendation, including when a simpler route is the better fit.

€0

30 minutes · written takeaway within 2 business days

Book a free process scan (30 min)

Times are shown in your own time zone. We work with clients across time zones.

Describe the process in the form