SNACK: 3-line summary
- GitHub Copilot local sandboxing is now generally available in Copilot CLI, the Copilot app, and VS Code sessions using Agent Host.
- Developers can restrict agent-run tools’ access to files, networks, and Git or GitHub CLI credentials on their own computers.
- Sandboxing is off by default unless enterprise policy requires it; the CLI and app must be configured separately.
GitHub made Copilot’s local sandboxing generally available on October 7, 2026. Copilot-run shell commands normally inherit your account’s access, so sandboxing lets you give those commands narrower permissions on your own computer. The local feature is included with Copilot at no additional charge.

Snackgirls react
AIKO: I’d like to compare different models under the same tool permissions. I’m curious how each responds when a command hits the boundary.
Nea: I’d like the agent to work on the code while leaving my notes and reference folders untouched. I’d rather keep those unfinished ideas close at hand than move them aside for every task.
Turning it on does not block every connection or credential
You can grant read-only or read/write access to specific paths, or mark paths as denied. The default policy still permits writes in the working directory, so folders containing notes or unrelated projects may need their own rules.
The app allows outbound internet, local-network access, and authenticated Git and GitHub CLI operations by default. Enabling sandboxing alone does not remove those permissions; you can turn them off individually when a task does not need them.
The policy applies to tool execution regardless of the model Copilot uses. Choosing a local model does not turn sandboxing on or make the session offline.
Enable the CLI and app separately
In a Copilot CLI session, enter /sandbox enable; the setting persists into future sessions. Use /sandbox to configure access and /sandbox policy to inspect the effective rules. Enterprise policies can require sandboxing and prevent developers from changing managed settings.
In the Copilot app, open Settings > Projects, select your project, then open Sandbox and turn on Sandbox new sessions. This applies to new local repository and working-tree sessions, not sessions already running. To enable sandboxing in an existing local app session, use /sandbox on.
Changing the app’s settings does not change the CLI’s settings, or vice versa. In the app, file, network, and credential policy changes apply to new sessions or after you restart an existing session with /restart-session.
Some tools sit outside the OS sandbox
Microsoft eXecution Container (MXC) maps policy to native OS controls: Windows uses ProcessContainer’s BaseContainer tier, macOS uses Seatbelt, and Linux uses bubblewrap. Copilot’s local sandbox uses lightweight process-level restrictions, not a separate virtual machine or container image.
Shell commands and, by default, supported local Model Context Protocol (MCP) and language servers run inside the boundary. The CLI itself is not OS-sandboxed: its built-in file tools make best-effort policy checks in-process. Remote MCP servers are outside the local process sandbox.
When proxy or host rules are configured, macOS and Linux force sandboxed outbound connections through a local proxy. On Windows, programs that ignore proxy settings can connect directly and bypass host rules.

Sources and checked date: October 8, 2026

Comments
0No login needed. Edit or delete your comment from the same browser.
All comments 0
한국어 · English · 日本語No comments yet. Start the conversation.