GitHub Copilot、管理デバイスに限定したリモート制御機能を導入
GitHub は Copilot のリモート制御機能に対して、管理されたデバイスに制限をかける新設定を導入し、管理者が SSO 認証や個別デバイスのアクセス権限を細かく定義できる機能を強化した。
AI深層分析を開く2026年7月31日 01:32
AI深層分析
キーポイント
管理デバイスへの制限機能追加
企業はリモート制御セッションを実行可能なデバイスを制限できるようになり、管理者がアクセス許可範囲を厳密にコントロール可能になった。
新しい設定による階層化制御
「remoteControl」設定により、特定の組織への SSO 認証要求や個別デバイスごとのアクセス調整が可能となり、既存のポリシーと組み合わせて多層的な管理を実現する。
3 つの導入メカニズム
サーバー管理(.github-private リポジトリ)、MDM 管理、ファイルベースの 3 つの方法を通じて、この設定を企業環境に展開できる。
重要な引用
Enterprises and organizations can now restrict which devices are eligible to host remotely controlled Copilot sessions
The new remoteControl enterprise managed setting gives administrators the ability to define exactly how remote control works on managed devices
Together, this gives you layered control from broad access down to per-device restrictions
編集コメントを表示
編集コメント
Copilot のリモート制御機能を「管理されたデバイス」に限定できる機能は、セキュリティ意識の高い企業にとって必須のアップデートである。管理者がデバイスの状態に応じてアクセス権限を細かく調整できる点は、実運用におけるリスク管理を大幅に強化する。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
企業や組織では、リモートコントロール可能な Copilot セッションをホストできる端末を制限できるようになりました。これにより、管理者はリモートコントロールアクセスが許可される場所を細かく制御できます。
新しい「remoteControl」エンタープライズ管理設定を使えば、管理者は管理された端末でのリモートコントロールの動作方法を正確に定義できます。例えば、特定の組織に対して SSO 認証を必須としたり、端末ごとにアクセス権限を調整したりすることが可能です。この設定は、「ユーザーがリモートコントロールを利用できるかどうか」を制御する既存のエンタープライズポリシーと併用されます。これにより、広範なアクセス制限から端末ごとの細かい制限まで、多層的な制御が可能になります。
始め方
モードを設定して「requireSSO」にすれば SSO 認証が必須となり、「disabled」にするとリモートコントロール自体をブロックできます。「enabled」に設定すれば、制限なく利用可能になります。
また、copilot-settings.json ファイルに remoteControl キーを追加することも可能です。
この設定は以下の 3 つのメカニズムを通じて展開できます:
- サーバー管理(.github-private リポジトリ): 企業内のユーザーアカウントに適用されます。
- MDM 管理: 特定の端末に適用され、管理されたマシンでのポリシー強制に適しています。
- ファイルベース: ファイルを受け取ったあらゆるマシンに適用されます。
エンタープライズ管理設定の詳細については、GitHub のドキュメントをご覧ください。
本記事は The GitHub Blog に掲載されました。
原文を表示
Enterprises and organizations can now restrict which devices are eligible to host remotely controlled Copilot sessions, giving administrators fine-grained control over where remote control access is permitted.
The new remoteControl enterprise managed setting gives administrators the ability to define exactly how remote control works on managed devices, whether that means requiring SSO authorization for specific organizations or tailoring access on a per-device basis. This setting works alongside the existing enterprise policy, which controls whether remote control is available to users at all. Together, this gives you layered control from broad access down to per-device restrictions.
Getting started
Set mode to requireSSO to enforce SSO authorization, disabled to block remote control entirely, or enabled to allow it without restriction.
You can also add the remoteControl key to your copilot-settings.json file.
You can deploy this setting through three mechanisms:
Server-managed (.github-private repository): Applies to user accounts in your enterprise.
MDM-managed: Applies to specific devices and is ideal for enforcing policies on managed machines.
File-based: Applies to any machine that receives the file.
For more information on enterprise managed settings, check out the GitHub docs.
The post Limit remote control to managed devices appeared first on The GitHub Blog.
AI算出
主要ニュースainew評価標準
AI エージェント(Copilot)の運用管理における重要なセキュリティ制御機能が追加されたため、AI 関連度と新規性は高い。ただし、これはグローバルな開発ツールへのアップデートであり、日本固有のコンプライアンスや価格変更などの情報は含まれていないため、日本関連性は低めとなる。
6つの評価軸を見る
- AI関連度
- 75
- 情報源の信頼性
- 25
- 新規性
- 75
- 調べる価値
- 75
- 重複の少なさ
- 100
- 日本での有用性
- 25
関連記事
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み