Skip to main content

Restrict MCP server access to a custom registry

You can configure an MCP registry URL and access control policy to determine which MCP servers developers can discover and use in supported IDEs and Второй пилот CLI.

Кто может использовать эту функцию?

Enterprise owners and organization owners

Копилот Энтерпрайз or Copilot бизнес

Внимание

This feature is in Публичный предварительный просмотр and is not the recommended method for restricting access to MCP servers. The more secure, generally available method is to define settings in your enterprise's managed-settings.json file. See Configuring an MCP server allowlist for your enterprise.

Prerequisites

Before you can fully configure MCP server access for your company, you need to create an MCP registry. See Настройте реестр MCP для вашей организации или предприятия.

Configuring the MCP allowlist policy for an enterprise

To ensure uniform access, you can set and maintain your MCP registry URL and allowlist policy at the enterprise level. Otherwise, if your teams have different needs, you should configure separate policies for each organization.

  1. Перейдите к своему предприятию. Например, на странице Enterprises на GitHub.com.

  2. В верхней части страницы нажмите Управление AI.

  3. На боковой панели нажмите MCP.

  4. Ensure MCP servers in Copilot is set to Enabled everywhere.

  5. In the MCP Registry URL section, enter the URL of your registry, then click Save.

    Примечание.

    Если вы настроили реестр MCP с помощью Azure API Center, введите базовый URL вашего API Center, включая путь к workspace, в формате:

    https://SERVICE-NAME.data.REGION.azure-apicenter.ms/workspaces/WORKSPACE-NAME
    

    Рассмотрим пример.

    https://contoso-apic.data.eastus.azure-apicenter.ms/workspaces/default
    

    Добавление дополнительных суффиксов маршрутов, например /v0.1/servers , вызовет ошибку в реестре, потому что GitHub Copilot автоматически добавляет путь MCP v0.1.

  6. In the Restrict MCP access to registry servers section, select the dropdown menu, then click one of the following options:

    • Allow all: No restrictions. All MCP servers can be used.
    • Registry only: Only servers from the registry may run.

    Your chosen policy will immediately apply to developers in your enterprise.

Configuring the MCP allowlist policy for an organization

  1. В правом верхнем углу GitHub, щелкните рисунок профиля, а затем выберите октикона "организация" aria-hidden="true" aria-label="organization" %} Ваши организации.

  2. Выберите организацию, кликнув по ней.

  3. Под именем организации щелкните Settings. Если вкладка "Параметры" не отображается, выберите раскрывающееся меню и нажмите кнопку "Параметры".

    Снимок экрана: вкладки в профиле организации. Вкладка "Параметры" выделена темно-оранжевым цветом.

  4. На боковой панели в разделе "Код, планирование и автоматизация", click Copilot, then click Policies.

  5. In the "Features" section, ensure MCP servers in Copilot is set to Enabled.

  6. In the MCP Registry URL (optional) field, enter the URL of your registry, then click Save.

    Примечание.

    Если вы настроили реестр MCP с помощью Azure API Center, введите базовый URL вашего API Center, включая путь к workspace, в формате:

    https://SERVICE-NAME.data.REGION.azure-apicenter.ms/workspaces/WORKSPACE-NAME
    

    Рассмотрим пример.

    https://contoso-apic.data.eastus.azure-apicenter.ms/workspaces/default
    

    Добавление дополнительных суффиксов маршрутов, например /v0.1/servers , вызовет ошибку в реестре, потому что GitHub Copilot автоматически добавляет путь MCP v0.1.

  7. In the Restrict MCP access to registry servers section, select the dropdown menu, then click one of the following options:

    • Allow all: No restrictions. All MCP servers can be used.
    • Registry only: Only servers from the registry may run.

    Your chosen policy will immediately apply to developers in your organization.

Next steps

For detailed information on MCP allowlist enforcement and limitations, see MCP private registry enforcement.

Further reading