# MCP private registry enforcement

> Understand the logic and limitations of MCP private registry enforcement using a private registry server.

- 网址：https://funcoding.ai/agents/github-copilot/reference/enterprise-administrators/mcp-private-registry-enforcement/
- 来源：GitHub Copilot 官方文档原文（英文），CC-BY-4.0 许可，同步于 2026-10-11
- 官方原文：https://docs.github.com/en/copilot/reference/enterprise-administrators/mcp-private-registry-enforcement

---
<div class="callout callout-note">

This feature is in public preview and is not the recommended method for restricting access to MCP servers. The more secure, generally available method is to define settings in your enterprise's `managed-settings.json` file. See [AUTOTITLE](https://funcoding.ai/agents/github-copilot/how-tos/administer-copilot/manage-mcp-usage/configure-enterprise-allowlist/).

</div>

## Supported surfaces

The following table lists where MCP private registry features are supported.

| Surface | Registry display | Allowlist enforcement |
|---|:---:|:---:|
| Copilot CLI | Supported | Supported v1.0.11+ |
| Copilot cloud agent | Not supported | Not supported |
| Eclipse | Supported | Supported v4.38+ |
| JetBrains | Supported | Supported v1.5.64+ |
| Visual Studio | Supported | Supported v18.4.0+ |
| VS Code | Supported | Supported v1.109.3+ |
| Xcode | Supported | Supported v0.47.0+ |

<div class="callout callout-note">

For Eclipse, JetBrains, and Xcode, MCP management features are supported in the pre-release versions of Copilot.

</div>

## Current enforcement limitations

MCP private registry enforcement currently has the following limitations:

* Enforcement is based only on server name/ID matching, which can be bypassed by editing configuration files.
* Strict enforcement that prevents installation of non-registry servers is not yet available. For stricter URL-based enforcement that users cannot override locally, see [AUTOTITLE](https://funcoding.ai/agents/github-copilot/how-tos/administer-copilot/manage-mcp-usage/configure-enterprise-allowlist/).

## Enforcement for local servers

MCP private registry enforcement applies to both remote and local MCP servers. When "Registry only" is configured, local servers must be included in your registry with the correct server ID, which must exactly match the installed server ID. A server's canonical ID is often defined in its documentation or manifest.

## Policy resolution for users with multiple seats

MCP private registry enforcement is always tied to the organization or enterprise that assigns the GitHub Copilot seat. If a user has multiple seats, GitHub automatically resolves conflicts and applies a single active policy and registry.

The resolution logic is:

1. **Scope**: Policies set by a parent enterprise override those set by an organization. Enterprise policies trickle down to all organizations and members within that enterprise.
1. **Enforcement strictness**: Since `Registry only` is more restrictive than `Allow all`, it will always take precedence.
1. **Recency of registry upload**: If two policies have the same scope and strictness, the most recently uploaded registry will be applied.
