Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Yes. GitHub announced on October 7, 2026 that local Copilot sandboxing is generally available for VS Code sessions that use Agent Host. Turning it on takes one setting, a few platform prerequisites, and a new session. Once it is active, it limits the file, network, and credential access that agent-launched terminal commands can reach. It is a meaningful protection layer, but it is not full isolation, and the scope depends on which session type you use.

What GitHub announced and what it covers

GitHub’s changelog entry dated October 7, 2026 says local sandboxing is generally available in GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions that use Agent Host. The feature applies policy-based limits to file, network, credential, and other system access for tools and commands that the agent starts. GitHub names Microsoft eXecution Container (MXC) as the technology that translates a common policy into native operating-system controls on Windows, macOS, and Linux. GitHub also says the feature is included with GitHub Copilot at no additional cost.

The announcement names Agent Host sessions specifically. VS Code’s documentation describes two separate execution paths, Local and Agent Host, and their coverage differs. Do not assume that a statement about one applies to the other.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Local and Agent Host sessions compared

The VS Code documentation on trust and safety for AI agents sets out what each session type sandboxes. The table below summarizes that coverage.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Coverage item Local sessions Agent Host sessions
Terminal commands and their child processes Sandboxed Sandboxed; this is the primary coverage, mainly shell execution and child processes
Locally launched MCP servers Not stated in the reviewed VS Code documentation Can be sandboxed when the related Agent Host setting is active
Locally launched language servers Not stated in the reviewed VS Code documentation Can be sandboxed when the related Agent Host setting is active
Built-in and other non-process tools Outside the process sandbox; separate permission checks apply Outside the process sandbox; separate permission checks apply

Because the setup described below applies to Agent Host sessions, the remaining steps assume that session type.

Platform prerequisites

The VS Code guide to sandboxing Copilot Agent Host sessions lists prerequisites by operating system. Check the row for your platform before you enable the setting.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Platform Requirement Status in the guide
macOS No prerequisite listed Supported
Linux and WSL2 Install bubblewrap and socat; the guide provides apt and dnf commands Supported
WSL1 Not applicable Unsupported, because it lacks the Linux kernel features that bubblewrap requires
Windows 11 24H2 and 25H2 Install the applicable September 8, 2026 Windows security update, identified as KB5124008 Experimental
Windows 11 26H1 Install the applicable September 8, 2026 Windows security update, identified as KB5124012 Experimental

For a connected remote Agent Host, install these prerequisites on the remote execution host, not on the machine where you type. The same applies to settings and paths.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to enable Copilot sandboxing in VS Code

Follow these steps on the machine where the agent runs.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Install the prerequisites for your platform from the table above, and install the Windows update if you are on Windows.
  2. Set chat.agent.sandbox.enabled to on in VS Code settings by searching for the key. The setting accepts off or on, and the default is off.
  3. Start a new Agent Host session. The guide’s sequence applies the setting to a new session.
  4. Run /sandbox policy in the session. The report shows the execution host, whether sandboxing is enabled, the operating-system implementation, and the effective filesystem and network policy. The command does not start a model turn and does not change settings, so it is safe to run as a check.

The session’s Permissions menu also includes a sandbox toggle. A selection there applies only to that session and does not change your user or workspace settings for other sessions.

Customizing paths and network access

The Agent Host settings let you define:

  • read/write paths, read-only paths, and denied paths;
  • network destinations;
  • whether locally launched MCP servers and language servers run inside the sandbox.

The default working directory has read/write access. A development-tool access setting can grant access to tool directories, configuration, and caches. That setting makes it easy to leave sensitive developer state reachable, so it should not be read as a blanket denial of access to credentials or configuration. The /sandbox policy report is the accurate way to see what your configuration actually allows.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Approvals and sandboxing do different jobs

VS Code treats these as separate controls. Approval settings decide whether an action runs automatically or waits for your confirmation. The approvals and permissions documentation covers those settings. Sandboxing restricts file and network access for covered terminal commands and their child processes, and it applies regardless of the permission level, including Allow all and Autopilot. A permissive approval setting therefore does not switch off the sandbox, and a sandbox does not replace approvals.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What sandboxing does not cover

The feature narrows what the agent can reach. It does not make the session safe in every respect.

  • Outbound network access is not blocked by default. Enabling the sandbox does not cut off the internet. Domain filtering varies by terminal implementation and platform.
  • Some settings weaken isolation. VS Code warns that explicitly injected credentials, allowed paths, local or unrestricted networking, unsandboxed fallback, and bypass can each reduce the protection.
  • It is not a boundary of a different kind. VS Code’s trust-and-safety documentation states: “Agent sandboxing is an added layer for the processes it covers. It is not a virtual machine or user-account boundary, a standalone security boundary, or a replacement for endpoint security.”

Availability and what remains unclear

The general-availability date is October 7, 2026. Windows support is labeled experimental in the VS Code guide, even though the feature itself is generally available. The reviewed sources do not state a geographic rollout schedule or any enterprise entitlement rules, so do not assume a particular region or plan has access beyond what GitHub’s announcement says. Confirm the current state of the feature against the two linked VS Code pages and GitHub’s changelog before you rely on it in a managed environment.

Sandboxing is a useful addition to Copilot agent sessions, especially for limiting what terminal commands can reach. Treat it as one control among several: keep approvals on for actions you do not want to run unattended, review the policy report after changing settings, and keep your endpoint security in place.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.