The new validator closes a real hole.
GitHub's enterprise validator checks managed Copilot settings for malformed JSON, unsupported configuration, invalid team mappings, and related errors. It points administrators to the affected file and JSON path. The checked repository files include copilot/managed-settings.json, copilot/team-mappings.json, and the team files referenced by that map.[1]
This catches failures that used to look deceptively complete. A file could exist on the default branch while a bad key or team slug kept the intended rule from taking effect. The validator turns that hidden parse failure into a named repair.
Validation proves that the control plane can read the policy. It does not prove what one editor did with it.
Coverage changes by client and property.
GitHub lists Copilot CLI, VS Code, the GitHub Copilot app, the cloud agent, and JetBrains IDEs as supported clients. The same documentation warns that not every client supports every property. GitHub also documents team-specific overrides through team-mappings.json and separate files under copilot/teams/.[2]
That makes scope a separate test. Record the client, version, billing enterprise, team membership, and expected winning rule. "Valid JSON" is too small a receipt for a policy with inheritance and overrides.
Delivery has its own clock.
For server-managed settings, GitHub says supported clients receive updates within about an hour. Restarting the client or signing in again triggers a refresh. Mobile-device-management clients check hourly, while file-based deployments load an updated file after restart.[2]
A clean validator followed by an immediate spot check can produce a false alarm. A clean validator followed by no client check can produce false confidence. Put the delivery method and observation time in the packet.
Defaults can change the blast radius.
GitHub also announced a global default policy for eligible Copilot features. The options cover enabled, disabled, and delegated administration. GitHub says the policy applies to eligible settings on the Features and clients page, Copilot Code Review, and MCP servers in Copilot policy. The announced change takes effect on October 22 after a 28-day configuration period.[3]
A default is part of the policy, even when nobody touched a team file. Review it beside explicit overrides. Then test one expected allow and one expected deny on a real client.