You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: content/copilot/how-tos/administer-copilot/manage-for-enterprise/use-managed-settings/override-settings-for-teams.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -18,9 +18,9 @@ To make a key eligible for team overrides, you will mark it as `overridable` in
18
18
19
19
## Supported keys
20
20
21
-
The `{ "overridable": <VALUE> }` syntax applies to the `model`, `permissions.disableBypassPermissionsMode`, `permissions.deny`, `permissions.ask`, `permissions.allow`, `allowedMcpServers`, and `deniedMcpServers` keys.
21
+
The `{ "overridable": <VALUE> }` syntax applies to the `model`, `permissions.disableBypassPermissionsMode`, `permissions.deny`, `permissions.ask`, `permissions.allow`, `allowedMcpServers`, `deniedMcpServers`, `extraKnownMarketplaces`, `strictKnownMarketplaces`, and `sandbox` keys.
22
22
23
-
`enabledPlugins`and `extraKnownMarketplaces` work additively. The enterprise `{% data variables.copilot.managed_setting_file %}` sets a baseline, and an enterprise team file can add more plugins and marketplaces on top of it.
23
+
`enabledPlugins`works additively. The enterprise `{% data variables.copilot.managed_setting_file %}` sets a baseline, and an enterprise team file can add more plugins on top of it.
24
24
25
25
For a full description of these keys and their syntax, see [AUTOTITLE](/copilot/reference/enterprise-administrators/enterprise-managed-settings).
26
26
@@ -64,7 +64,7 @@ You will use `copilot/{% data variables.copilot.team_mappings_file %}` and the `
64
64
}
65
65
```
66
66
67
-
1. Create the team settings file under `copilot/{% data variables.copilot.team_settings_directory %}`. You can include any keys you marked as overridable, plus the additive keys `enabledPlugins` and `extraKnownMarketplaces`. Every other key stays governed by your enterprise default.
67
+
1. Create the team settings file under `copilot/{% data variables.copilot.team_settings_directory %}`. You can include any keys you marked as overridable, plus the additive key `enabledPlugins`. Every other key stays governed by your enterprise default.
Copy file name to clipboardExpand all lines: content/copilot/reference/enterprise-administrators/enterprise-managed-settings.md
+48Lines changed: 48 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -144,6 +144,25 @@ The following source types are supported:
144
144
145
145
See [AUTOTITLE](/copilot/concepts/enterprise/plugin-standards).
146
146
147
+
For server-managed enterprise team overrides, wrap the complete marketplace map in `overridable`:
148
+
149
+
```json
150
+
{
151
+
"extraKnownMarketplaces": {
152
+
"overridable": {
153
+
"enterprise-plugins": {
154
+
"source": {
155
+
"source": "github",
156
+
"repo": "OWNER/REPO"
157
+
}
158
+
}
159
+
}
160
+
}
161
+
}
162
+
```
163
+
164
+
A team file can then provide a regular marketplace map to replace this default. Include any default marketplaces that the team should retain. If the team omits the key, the enterprise default remains.
165
+
147
166
## strictKnownMarketplaces
148
167
149
168
Restricts plugin installation to only the marketplaces explicitly defined by the enterprise. An empty array means complete lockdown. Each entry is a marketplace object with a `source` property indicating the source type. The following source types are supported:
@@ -157,6 +176,20 @@ Restricts plugin installation to only the marketplaces explicitly defined by the
This key is overridable for enterprise teams. Wrap the complete allowlist in `overridable` at the enterprise level:
180
+
181
+
```json
182
+
{
183
+
"strictKnownMarketplaces": {
184
+
"overridable": [
185
+
{ "source": "github", "repo": "OWNER/REPO" }
186
+
]
187
+
}
188
+
}
189
+
```
190
+
191
+
Use a regular array in the team file to replace the default allowlist. Omitting the key retains the enterprise default. An explicit empty array, `[]`, means complete lockdown, not an unmanaged policy.
192
+
160
193
## model
161
194
162
195
Sets your preferred model as the default for new conversations. This lets you choose the default model that best fits your enterprise's workflows. Users can still select a different model on a per-conversation basis.
@@ -288,6 +321,21 @@ The following sub-properties are supported:
288
321
*`allowDevToolAccess`: `false` prevents automatic access to development-tool configuration, caches, registries, and toolchains. These locations can contain package registry credentials or tokens. Disabling access can cause package restoration, authenticated registry operations, or builds that use shared caches to fail unless you explicitly grant the required paths.
289
322
*`userPolicy`: An object that configures filesystem, network, and macOS-specific Seatbelt restrictions. The supported properties are described in the following sections.
290
323
324
+
For server-managed enterprise team overrides, wrap the entire sandbox object in `overridable`:
325
+
326
+
```json
327
+
{
328
+
"sandbox": {
329
+
"overridable": {
330
+
"enabled": true,
331
+
"allowBypass": false
332
+
}
333
+
}
334
+
}
335
+
```
336
+
337
+
The wrapper must be the only property directly inside `sandbox`. Individual sub-properties, such as `sandbox.enabled`, cannot use their own `overridable` wrappers. A team file's regular sandbox object replaces the entire wrapped default, so include every restriction that should remain. Omitting `sandbox` retains the enterprise default.
338
+
291
339
### `sandbox.userPolicy.filesystem`
292
340
293
341
Configures filesystem access for sandboxed processes. Paths should be absolute. Managed grant lists are matched against user-configured lists by exact path string, not by parent or child path coverage.
0 commit comments