Importante
This feature is in prévia pública and is not the recommended method for restricting access to MCP servers. The more secure, generally available method is to define settings in your enterprise's managed-settings.json file. See Configuring an MCP server allowlist for your enterprise.
Prerequisites
Before you can fully configure MCP server access for your company, you need to create an MCP registry. See Configurar um registro MCP para sua organização ou empresa.
Configuring the MCP allowlist policy for an enterprise
To ensure uniform access, you can set and maintain your MCP registry URL and allowlist policy at the enterprise level. Otherwise, if your teams have different needs, you should configure separate policies for each organization.
-
Navegue até sua empresa. Por exemplo, na página Enterprises em GitHub.com.
-
Na parte superior da página, clique em controles de IA.
-
Na barra lateral, clique em MCP.
-
Ensure MCP servers in Copilot is set to Enabled everywhere.
-
In the MCP Registry URL section, enter the URL of your registry, then click Save.
Observação
Se você configurar o registro do MCP usando o Azure API Center, insira a URL base do Azure API Center, incluindo o caminho do workspace, no formato:
https://SERVICE-NAME.data.REGION.azure-apicenter.ms/workspaces/WORKSPACE-NAMEPor exemplo:
https://contoso-apic.data.eastus.azure-apicenter.ms/workspaces/defaultIncluir sufixos de rota adicionais, como
/v0.1/servers, fará com que o registro apresente erro, pois GitHub Copilot acrescenta automaticamente o caminho do MCP v0.1. -
In the Restrict MCP access to registry servers section, select the dropdown menu, then click one of the following options:
- Allow all: No restrictions. All MCP servers can be used.
- Registry only: Only servers from the registry may run.
Your chosen policy will immediately apply to developers in your enterprise.
Configuring the MCP allowlist policy for an organization
-
No canto superior direito de GitHub, clique na foto de perfil e clique em Your organizations.
-
Selecione uma organização clicando nela.
-
No nome da organização, clique em Settings. Caso não consiga ver a guia "Configurações", selecione o menu suspenso , clique em Configurações.

-
Na barra lateral, em "Código, planejamento e automação", click Copilot, then click Policies.
-
In the "Features" section, ensure MCP servers in Copilot is set to Enabled.
-
In the MCP Registry URL (optional) field, enter the URL of your registry, then click Save.
Observação
Se você configurar o registro do MCP usando o Azure API Center, insira a URL base do Azure API Center, incluindo o caminho do workspace, no formato:
https://SERVICE-NAME.data.REGION.azure-apicenter.ms/workspaces/WORKSPACE-NAMEPor exemplo:
https://contoso-apic.data.eastus.azure-apicenter.ms/workspaces/defaultIncluir sufixos de rota adicionais, como
/v0.1/servers, fará com que o registro apresente erro, pois GitHub Copilot acrescenta automaticamente o caminho do MCP v0.1. -
In the Restrict MCP access to registry servers section, select the dropdown menu, then click one of the following options:
- Allow all: No restrictions. All MCP servers can be used.
- Registry only: Only servers from the registry may run.
Your chosen policy will immediately apply to developers in your organization.
Next steps
For detailed information on MCP allowlist enforcement and limitations, see MCP private registry enforcement.