Skip to content

allowedMcpServers entries using serverName never match #4989

Description

@rpstester

Describe the bug

allowedMcpServers entries using serverName never match — named servers are blocked as "not permitted by enterprise managed allow list"

serverName matchers in a server-managed allowedMcpServers policy don't match anything. A server whose label exactly matches a serverName entry is blocked the same way as a server that isn't on the list. In the same session, serverUrl and serverCommand entries in the same policy work as expected.

The docs say serverName "matches the user-assigned server label exactly" and applies to "any server":
https://docs.github.com/en/copilot/reference/enterprise-administrators/enterprise-managed-settings#allowedmcpservers

The docs don't describe any condition that disables serverName matching. For example, they don't say it applies only when the list has no serverUrl or serverCommand entries. If that is the intended behavior, it isn't documented.

This is Copilot CLI 1.0.89, GitHub Copilot app 1.1.23, Windows 11 (build 26200).

This is a server-managed team policy file (.github-private), applied through overridable at the enterprise level. Here is a shortened version. The client cache shows the full list was received (keys=[allowedMcpServers,...], all entries present):

{
  "allowedMcpServers": [
    {"serverUrl": "https://learn.microsoft.com/api/mcp"},
    {"serverName": "workiq"},
    {"serverName": "azure-devops"},
    {"serverName": "miro-mcp"},
    {"serverUrl": "https://mcp.miro.com"},
    {"serverCommand": ["npx", "-y", "next-devtools-mcp@latest"]}
  ]
}

Affected version

GitHub Copilot CLI 1.0.89.

Steps to reproduce the behavior

  1. Apply a server-managed policy like the one above.
  2. Add these servers with --additional-mcp-config. Use a minimal stdio MCP server for node mini.js.
    {"mcpServers":{
      "workiq":           {"type":"local","command":"node","args":["mini.js"]},
      "zz-not-listed":    {"type":"local","command":"node","args":["mini.js"]},
      "appian-dev-tools": {"type":"http","url":"https://mcp-probe.invalid/mcp"}
    }}
  3. Run:
    copilot -p "Reply OK" --additional-mcp-config @extra.json --log-level all --log-dir ./logs

Expected behavior

workiq and appian-dev-tools should start, because they match serverName entries. zz-not-listed should be blocked.

Instead, all three are blocked with identical messages. The remote probe URL is never contacted.

[DEBUG] Skipping MCP server "zz-not-listed": not permitted by enterprise managed allow list
[DEBUG] Skipping MCP server "appian-dev-tools": not permitted by enterprise managed allow list
[DEBUG] Skipping MCP server "workiq": not permitted by enterprise managed allow list

In the same run, servers that match a serverUrl entry (for example Microsoft Learn and Miro) or a serverCommand entry (for example next-devtools-mcp) connect normally.

Before we added serverUrl/serverCommand entries, 8 of our 10 configured servers were blocked even though every one of them had an exact serverName entry. Only the 2 servers with serverUrl entries loaded. Adding serverUrl/serverCommand duplicates is our workaround.

Additional context

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:enterpriseGitHub Enterprise (GHE/GHES) support, org policies, and enterprise settingsarea:mcpMCP server configuration, discovery, connectivity, OAuth, policy, and registry

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions