Enterprise environments managing large-scale development workflows are gaining new levers for controlling how developers interact with GitHub Copilot within JetBrains IDEs. The latest update introduces a suite of enterprise-managed settings that allow administrators to enforce consistent governance policies directly from the organization level.
What Changed
The core capability added is the ability to centrally configure plugin availability and MCP server access for all users on an enterprise Copilot plan. Administrators can now define three distinct controls regarding plugins: requiring specific tools via enabledPlugins, exposing approved sources through extraKnownMarketplaces, or restricting installations entirely using strictKnownMarketplaces. Additionally, the system introduces allowlists and denylists for Model Context Protocol (MCP) servers.
Beyond tooling access, administrators can now centrally configure OpenTelemetry settings. This includes defining collector endpoints, protocols, service names, resource attributes, and content-capture policies. Crucially, these managed values take precedence over any local developer configurations, ensuring telemetry is consistently routed to approved collectors regardless of individual machine state.
Operational Implications
This change fundamentally alters the operational model for managing AI agents in an enterprise context. Previously, governance relied heavily on user compliance or post-incident remediation. Now, platform teams can proactively prevent unauthorized plugin installations and restrict connections to unvetted MCP servers.
For security engineers, this represents a significant reduction in attack surface related to supply chain risks from third-party plugins. By enforcing strictKnownMarketplaces, organizations effectively block the installation of potentially malicious or non-compliant extensions before they can be executed within the IDE environment.
Security and Permission Modes
The update also introduces controls over permission modes, specifically allowing administrators to disable bypass capabilities. By setting permissions.disableBypassPermissionsMode, organizations prevent Copilot agents from utilizing features like Bypass Approvals or Autopilot without explicit administrative oversight.
What This Means For Practitioners
The introduction of these managed settings signals a maturation in how AI tools are integrated into enterprise infrastructure. It moves the conversation away from "how do we allow this?" to "what specific constraints must be applied here?" Platform engineers should evaluate their current plugin inventory against new marketplace restrictions and prepare migration paths for MCP server configurations.
For teams relying on OpenTelemetry, verifying that managed values correctly override local settings is essential. This ensures compliance with data residency requirements without requiring developers to manually adjust telemetry pipelines every time a policy changes. The ability to centrally manage these controls reduces the operational overhead of maintaining consistent AI governance across distributed development environments.
Practitioners should review their existing feedback channels, such as in-product options or community repositories, when testing new configurations. Understanding how these settings interact with your specific JetBrains setup is critical before rolling out enterprise-wide policies that might impact developer productivity workflows.



