# Restrict MCP server access to a custom registry

> You can configure an MCP registry URL and access control policy to determine which MCP servers developers can discover and use in supported IDEs and Copilot CLI.

- 网址：https://funcoding.ai/agents/github-copilot/how-tos/administer-copilot/manage-mcp-usage/restrict-based-on-registry/
- 来源：GitHub Copilot 官方文档原文（英文），CC-BY-4.0 许可，同步于 2026-10-11
- 官方原文：https://docs.github.com/en/copilot/how-tos/administer-copilot/manage-mcp-usage/restrict-based-on-registry

---
<div class="callout callout-note">

This feature is in public preview and is not the recommended method for restricting access to MCP servers. The more secure, generally available method is to define settings in your enterprise's `managed-settings.json` file. See [AUTOTITLE](https://funcoding.ai/agents/github-copilot/how-tos/administer-copilot/manage-mcp-usage/configure-enterprise-allowlist/).

</div>

## Prerequisites

Before you can fully configure MCP server access for your company, you need to create an MCP registry. See [AUTOTITLE](https://funcoding.ai/agents/github-copilot/how-tos/administer-copilot/manage-mcp-usage/configure-mcp-registry/).

## Configuring the MCP allowlist policy for an enterprise

To ensure uniform access, you can set and maintain your MCP registry URL and allowlist policy at the enterprise level. Otherwise, if your teams have different needs, you should configure separate policies for each organization.

1. Navigate to your enterprise. For example, from the [Enterprises](https://github.com/settings/enterprises?ref_product=ghec&ref_type=engagement&ref_style=text) page on GitHub.com.

1. At the top of the page, click **copilot AI controls**.
1. In the sidebar, click mcp **MCP**.
1. Ensure **MCP servers in Copilot** is set to **Enabled everywhere**.
1. In the **MCP Registry URL** section, enter the URL of your registry, then click **Save**.

<div class="callout callout-note">

If you set up your MCP registry using Azure API Center, enter the base URL for your API Center, including the workspace path, in the format:

```text
https://SERVICE-NAME.data.REGION.azure-apicenter.ms/workspaces/WORKSPACE-NAME
```

For example:

```text
https://contoso-apic.data.eastus.azure-apicenter.ms/workspaces/default
```

Including additional route suffixes like `/v0.1/servers` will cause the registry to error out, because GitHub Copilot appends the MCP v0.1 path automatically.

</div>

1. In the **Restrict MCP access to registry servers** section, select the dropdown menu, then click one of the following options:
   * **Allow all**: No restrictions. All MCP servers can be used.
   * **Registry only**: Only servers from the registry may run.

    Your chosen policy will immediately apply to developers in your enterprise.

## Configuring the MCP allowlist policy for an organization

1. In the upper-right corner of GitHub, click your profile picture, then click **organization Organizations**.
1. Select an organization by clicking on it.
1. Under your organization name, click **gear Settings**. If you cannot see the "Settings" tab, select the **More** dropdown menu, then click **Settings**.

   ![Screenshot of the tabs in an organization's profile. The "Settings" tab is outlined in dark orange.](https://funcoding.ai/official-assets/github-copilot/assets/images/help/discussions/org-settings-global-nav-update.webp)
1. In the sidebar, under "Code, planning, and automation", click **copilot Copilot**, then click **Policies**.
1. In the "Features" section, ensure **MCP servers in Copilot** is set to **Enabled**.
1. In the **MCP Registry URL (optional)** field, enter the URL of your registry, then click **Save**.

<div class="callout callout-note">

If you set up your MCP registry using Azure API Center, enter the base URL for your API Center, including the workspace path, in the format:

```text
https://SERVICE-NAME.data.REGION.azure-apicenter.ms/workspaces/WORKSPACE-NAME
```

For example:

```text
https://contoso-apic.data.eastus.azure-apicenter.ms/workspaces/default
```

Including additional route suffixes like `/v0.1/servers` will cause the registry to error out, because GitHub Copilot appends the MCP v0.1 path automatically.

</div>

1. In the **Restrict MCP access to registry servers** section, select the dropdown menu, then click one of the following options:
   * **Allow all**: No restrictions. All MCP servers can be used.
   * **Registry only**: Only servers from the registry may run.

    Your chosen policy will immediately apply to developers in your organization.

## Next steps

For detailed information on MCP allowlist enforcement and limitations, see [AUTOTITLE](https://funcoding.ai/agents/github-copilot/reference/enterprise-administrators/mcp-private-registry-enforcement/).

## Further reading

* [AUTOTITLE](https://funcoding.ai/agents/github-copilot/reference/supported-surfaces-for-policies/)
