GitHub will auto-enable new Copilot features for Business and Enterprise orgs on October 22 unless admins opt out
A new global default policy means unconfigured Copilot features, including MCP server access and AI code review, will switch on automatically for enterprise customers in 28 days unless administrators choose otherwise.
A 28-day window before Copilot features switch on
GitHub published a changelog entry on September 24, 2026 introducing a new global "Default policy for new features" for Copilot Business and Copilot Enterprise customers. The policy can be configured immediately through the enterprise's AI Controls settings, but GitHub says it will not change any user's access until it takes effect on October 22, 2026 -- a 28-day window for administrators to make an explicit choice.
Administrators can choose one of three settings: Enabled, which switches on current and future eligible features by default; Disabled, which keeps current features off and requires approval for new ones; or "Let organizations decide," which delegates the choice to individual organization admins. GitHub's own default for the policy itself is Enabled, meaning any feature an administrator leaves unconfigured will automatically turn on for users on October 22 if no explicit decision is made. The policy covers every setting on the enterprise's "Features & clients" page, plus two items GitHub names specifically: the Copilot Code Review policy and the "MCP servers in Copilot" policy.
Why MCP servers and code review matter
The MCP servers policy determines whether Copilot clients across an entire company can run Model Context Protocol servers at all -- the mechanism that lets an AI agent call external tools and reach company data and credentials, according to IT advisory outlet Digital Applied, which published its own checklist analysis of the change the same day as GitHub's announcement.
GitHub's documentation, quoted by Digital Applied, states the policy "is enabled by default. If you don't take action, unconfigured features will be enabled on October 22." GitHub's stated rationale, per the same documentation, is that the enabled-by-default approach lets users "benefit from the latest features and models without the need for administrator intervention."
What's preserved and what's excluded
Not everything is up for grabs. Any feature an administrator has already explicitly enabled or disabled is preserved and will not be overridden when the global default takes effect. Features still in preview remain opt-in regardless of the new policy, and if an admin has already opted into a preview feature, that choice carries over once it reaches general availability.
- Three settings are excluded from the new default policy by name: two restrictive Copilot model policies tied to GitHub's data-residency and FedRAMP enterprise offerings, and the "Store local sessions in the Cloud" setting for Copilot CLI and VS Code.
- A separate, already-active default-availability policy governs which AI models are available; models left unconfigured carry a "Delegate to Default Policy" label.
- Regardless of that model policy's setting, GitHub disables by default: pre-GA models, open-weight models including DeepSeek, Kimi K2.7 Code and Kimi K3, and models not covered by GitHub's data retention agreement, including Claude Fable 5 and Claude Fable 5.1.
How to lock down MCP access
GitHub already provides a way to restrict which MCP servers can run. On August 6, 2026 it introduced enterprise managed settings with "allowedMcpServers" and "deniedMcpServers" keys in a managed-settings.json file, now generally available. Under that mechanism, policies fail closed -- meaning a malformed or unverifiable configuration is blocked rather than allowed -- and a server must pass every applicable policy layer.
GitHub also offers an alternative route: a custom registry that administrators host themselves. But per Digital Applied's analysis of GitHub's documentation, that route remains in public preview, is not prioritized for further development by GitHub, and can be bypassed by users editing local configuration files -- unlike the enforced managed-settings file.
The admin checklist before October 22
The changelog states the policy applies at both the enterprise and organization level, so administrators without an enterprise account should still check whether their organization has the same unconfigured settings. Digital Applied recommends that enterprises set the MCP servers policy to Enabled paired with an administrator-controlled allowlist, rather than leaving it to switch on silently on October 22.
- By roughly October 1: inventory every feature's current state on the Features & clients, Agents and MCP pages, using the banner that shows how many policies remain unconfigured.
- By roughly October 8: decide the MCP allowlist mechanism and the code-review policy explicitly, rather than letting them inherit the global default.
- By roughly October 15: set the global default -- Enabled, Disabled or Let organizations decide -- for everything still unconfigured, ahead of the October 22 effective date.
What's still unknown
It is not yet known how many enterprises will leave the policy unconfigured by October 22, or what practical effects -- security or otherwise -- will follow once features including MCP server access switch on by default at organizations that take no action. GitHub has not published adoption figures showing how many Business or Enterprise customers have set the policy since the September 24 announcement.
Sources and context
- Default Enablement of Copilot features for Copilot Business and EnterpriseGitHub (GitHub Blog Changelog)
- GitHub Copilot Features Turn On by Default Oct 22: Check NowDigital Applied
- MCP allowlists in enterprise managed settingsGitHub (GitHub Blog Changelog)
AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.
About NewsJaws Desk
AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.