Skip to content

All MCP servers blocked by policy when GHE returns 404 on /copilot/mcp_registry #2498

Description

@grantborthwick

Describe the bug

On GitHub Enterprise (microsoft.ghe.com) with an Enterprise Copilot plan, all non-default MCP servers are blocked at startup with "19 MCP serverswere blocked by policy". The GHE instance returns HTTP 404 for GET /copilot/mcp_registry because it doesn't support the MCP registry API yet. The CLI treats this 404 as a policy fetch error and blocks all servers, rather than treating it as "no registries configured" (which should allow all).

The pLn() function in app.js throws on 404, and the NEe() catch block returns yEe([]) (empty registry = block all). A 404 should instead return { mcp_registries: [] } so it flows into the o.length === 0 path which uses the Wgn allow-all filter.

Log evidence:
[ERROR] Request to MCP registry policy at https://api.microsoft.ghe.com/copilot/mcp_registry failed with status 404 (request ID:
E1B4:18EBE6:19AB3B:B4DE37:69CEDD72)

Affected version

GitHub Copilot CLI 1.0.17

Steps to reproduce the behavior

  1. Be on a GHE instance where GET /copilot/mcp_registry returns 404 (e.g., microsoft.ghe.com)
  2. Have an Enterprise Copilot plan (copilot_plan: enterprise)
  3. Configure any MCP servers in .vscode/mcp.json or agency.toml
  4. Run copilot
  5. See warning: "19 MCP servers were blocked by policy: ..."
  6. Only the built-in github-mcp-server loads

Expected behavior

When /copilot/mcp_registry returns 404, the CLI should treat it as "no registries configured" and allow all MCP servers (same as the no_registries outcome path). The 404 means the feature isn't available on this GHE version, not that servers should be blocked

Additional context

  • Operating system: Windows 11, x86_64
  • Terminal emulator: Windows Terminal
  • Shell: PowerShell
  • Copilot plan: enterprise (access_type_sku: copilot_enterprise_seat_quota)
  • is_mcp_enabled: true
  • Proposed fix: In pLn(), add if (a.status === 404) return { mcp_registries: [] }; before the throw
  • This affects all Enterprise plan users on GHE instances without the MCP registry API

Activity

  1. added
    area:enterpriseGitHub Enterprise (GHE/GHES) support, org policies, and enterprise settings
    on Apr 6, 2026
  2. added
    area:mcpMCP server configuration, discovery, connectivity, OAuth, policy, and registry
    on Apr 6, 2026
  3. tuminoid commented on Apr 7, 2026

    @tuminoid

    Same here. On Enterprise Copilot, v1.0.19 and all the MCPs are disabled except the built-in one.

  4. VD-Techlead commented on Apr 7, 2026

    @VD-Techlead

    This is still an issue in GitHub Copilot CLI 1.0.20.

  5. JoannaaKL commented on Apr 7, 2026

    @JoannaaKL

    Hi @grantborthwick we are working on it, fix is incoming 🚀

  6. self-assigned this
    on Apr 7, 2026
  7. Semloh87 commented on Apr 8, 2026

    @Semloh87

    FYI still getting this issue with GitHub Copilot CLI 1.0.21

  8. gianni-rg commented on Apr 8, 2026

    @gianni-rg

    The same, still getting similar issue with GitHub Copilot CLI 1.0.21 (on different GHE account, without no registry configured or registry policy configured to AllowAll)

  9. VD-Techlead commented on Apr 8, 2026

    @VD-Techlead

    Same here . This is still an issue in GitHub Copilot CLI 1.0.21

  10. JoannaaKL commented on Apr 8, 2026

    @JoannaaKL

    Hi folks - please logout from your cli and login again. CLI will refetch the auth data including the mcp registry settings.

  11. VD-Techlead commented on Apr 8, 2026

    @VD-Techlead

    Yes this solved it!

  12. gianni-rg commented on Apr 8, 2026

    @gianni-rg

    Hi folks - please logout from your cli and login again. CLI will refetch the auth data including the mcp registry settings.

    Already done previously, but tested again right now, with /logout, terminate CLI, open CLI and /login again.
    Registry settings are not updated and the same issue is still present. It also seems that registry settings are not correcly retrieved:
    in the logs I can see the CLI tries to fetch "https://burger-mcp-registry.com" and "https://copilot-mcp-registry.github.com", which the IT admin never configured.

    Update: I've also double-checked on a different machine, with a different user account, which never had Copilot CLI installed (used v1.0.21 on Windows, no WSL). Same issue, with the same registry URLs checked for the policy (and fail with 404, given that those endpoints do not exist).

  13. szgergo commented on Apr 8, 2026

    @szgergo

    Solved it for me as well. Thanks!

  14. VD-Techlead commented on Apr 8, 2026

    @VD-Techlead

    Spoke to soon..

    It is partially fixed (under WSL atleast). As soon as I restart the copilot cli the MCP:servers are disabled again due to the same policy restricitons. So the fix is to once again /logout & /login without restarting the cli. Also be fast accepting the local storage of the keys. Taking to long in this step will make the MCP be disabled again and you have to /logout & /login again for it to work.

    This can only be regarded as a workaround, since loging out and logingn in each time you restart or start a new terminal is not the best experience.

  15. christiandt commented on Apr 8, 2026

    @christiandt

    It does seem like these "registry_only" entries should not have been pushed to production? (the same ones as @gianni-rg mentions above)

    $ gh api /copilot/mcp_registry
    {
      "mcp_registries": [
        {
          "url": "https://mcp.azure.com/",
          "registry_access": "allow_all",
          "owner": {
            "login": "github",
            "id": 1,
            "type": "Business",
            "parent_login": null,
            "parent_id": null,
            "priority": 1
          }
        },
        {
          "url": "https://burger-mcp-registry.com/",
          "registry_access": "registry_only",
          "owner": {
            "login": "bobs-burgers",
            "id": 3097,
            "type": "Organization",
            "parent_login": "github-inc",
            "parent_id": 2,
            "priority": 2
          }
        },
        {
          "url": "https://copilot-mcp-registry.github.com/",
          "registry_access": "registry_only",
          "owner": {
            "login": "standalone-org",
            "id": 507,
            "type": "Organization",
            "parent_login": null,
            "parent_id": null,
            "priority": 3
          }
        }
      ]
    }
    

    Per GitHub's MCP Allowlist Enforcement documentation:

    "When 'Registry only' is configured, the system restricts MCP servers to those registered in your organization's registry."

    "Stricter policies ('Registry only') take precedence over permissive ones ('Allow all')"

    Even though the first entry has allow_all at priority 1, the registry_only entries override it because stricter policies always win. Since the fake registries don't contain any real servers, all user MCP servers are blocked.

  16. grantborthwick commented on Apr 8, 2026

    @grantborthwick
    Author

    I'm still seeing this after /logout and /login on 1.0.21 and then starting a new session:

    Image
  17. JoannaaKL commented on Apr 8, 2026

    @JoannaaKL

    Hi again, please relogin one more time, the issue should be fixed now. Thank you for your patience!

  18. gianni-rg commented on Apr 8, 2026

    @gianni-rg

    Hi again, please relogin one more time, the issue should be fixed now. Thank you for your patience!

    Just tested. It seems working now. Thank you for the support!

  19. dynek commented on Apr 8, 2026

    @dynek

    Working on my side as well so far, thank you!

  20. grantborthwick commented on Apr 8, 2026

    @grantborthwick
    Author

    @JoannaaKL - it started working for me now without re-login again - thanks!

  21. Emprint commented on Apr 10, 2026

    @Emprint

    @JoannaaKL While this issue is fixed when running directly from the terminal (thank you very much for this!), the issue remains when running Copilot CLI from VS Code Insiders in both github.copilot.cli.newSession and workbench.action.chat.openNewSessionEditor.copilotcli, any idea what could cause this?

    Image

    I suppose I need to forward the issue to the VS Code team.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:enterpriseGitHub Enterprise (GHE/GHES) support, org policies, and enterprise settingsarea:mcpMCP server configuration, discovery, connectivity, OAuth, policy, and registry

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions