GitHub has promoted local sandboxing for Copilot from preview to general availability, extending the boundary to Copilot CLI, the Copilot app and VS Code sessions that run through Agent Host. The feature limits what tools and commands launched by a Copilot agent can reach — files, network connections and credentials — according to policies set by individual developers or their organizations.
The enforcement layer is Microsoft eXecution Container, or MXC, which translates a single policy model into native operating-system controls on Windows, macOS and Linux. GitHub says sandboxing comes at no extra cost and applies no matter which model Copilot is running, so switching between cloud and local models does not change what the agent is allowed to touch.
The organization-level control is the part enterprises will notice. Administrators can require sandboxing and enforce settings that individual developers cannot weaken — a meaningful shift from prompt-based guardrails, which a user can talk an agent around. MXC constrains the processes and local services an agent launches: read-only source trees, restricted network ranges, and Git or GitHub CLI credentials that stay out of reach unless explicitly granted.
The release lands alongside a batch of related changes. Claude Haiku 5.5 is now available to Copilot Pro, Pro+, Max, Business and Enterprise users. The /model command in Copilot CLI can discover models from a running local Ollama instance, so developers can route work to machines sitting on their own desk. VS Code 1.141 adds a grid view for running agent sessions side by side plus a worktree cleanup command, and the JetBrains plugin gains enterprise-managed default models and a setting that disables automatic MCP server startup — while dropping support for JetBrains IDE 2025.1.
Timing matters here. GitHub moved every Copilot plan to usage-based billing on June 1, replacing premium requests with GitHub AI Credits that are consumed per token at each model's published API rate. Under that system, routing work to a free local model directly lowers the bill — which makes local-model discovery as much a pricing feature as a privacy one.
The boundary also has known seams. Coverage is uneven: shell commands and local MCP servers get OS-level limits, built-in file tools rely on checks inside the agent harness, and remote MCP servers sit outside the local sandbox altogether. GitHub's own documentation notes that a remote provider can still receive prompts and code context even when the CLI is running in offline mode.
The direction is clear regardless. Two weeks ago GitHub put computer use into public preview, letting agents drive local desktop apps on macOS and Windows; sandboxing narrows what those agents can reach once they are there. Shipping both in the same fortnight suggests GitHub sees permission controls as the price of admission for wider agent access — and that whether an agent can be audited, limited and reversed is displacing raw model quality as the question enterprise buyers ask first.
Comments (0)
Log in to join the discussion
Log InNo comments yet