Copilot Default Turns On Unconfigured Features as Codex and Claude Code Keep Sessions

At a glance

  • GitHub Copilot Business and Enterprise now have a Default policy for new features, and it is enabled by default. Unconfigured GA rows follow it starting 22 Oct 2026, which is 27 days from today.
  • Codex v0.157.0 puts GPT-6 Sol and Luna in the Amazon Bedrock catalogs and makes sessions harder to lose: background server, f to fork, /import on remote sessions.
  • Claude Code v2.1.282 tells you which telemetry settings it ignored and stops --resume and --continue from dropping earlier thinking.
  • Around the default: Copilot app local sandboxing (public preview, off by default) and proof of presence for Entra ID managed-user enterprises.

Wednesday was the price card and Thursday was the reviewer on the PR, so Friday is quieter on models and louder on policy. The model rows from earlier this week are already in the pickers. What changed overnight is the paperwork around them: a Copilot org default that turns on by itself if nobody touches it, two agent clients that now keep a session and its reasoning intact across a resume or a fork, and a Bedrock catalog that lets an AWS shop route its daily lane to Sol without a second vendor relationship.

Treat today as the day you set the Copilot org default before it sets itself, pin the clients that keep reasoning across a resume, and point Sol or Luna at Bedrock only if that is already how the shop buys tokens.

Top Stories

Copilot’s org default: 22 Oct is the date, Unconfigured is the trap

Practical dev impact: GitHub’s 24 Sep changelog adds a global Default policy for new features that covers generally available Copilot features and supported client capabilities on Copilot Business and Enterprise. Admins set it under AI Controls > Copilot to Enabled, Disabled, or Let organizations decide, and it reaches the eligible items on the enterprise Features & clients page, the Copilot code review policy on the Agents page, and the MCP servers in Copilot policy. Preview features stay opt-in and explicit enable or disable choices are preserved, so the rows at risk are the ones still marked Unconfigured. The control is live to configure now but does not change access until 22 October 2026, and GitHub’s docs are clear that the policy itself is enabled by default, which means a team that takes no action wakes up that morning with every Unconfigured GA row turned on. Settings shows a banner with the count of eligible rows still Unconfigured, so open AI Controls this morning, work from that banner rather than a guess, and set code review and MCP explicitly instead of letting them inherit. Leave the default on Enabled only if you already want every future GA Copilot surface on in every org.

Codex v0.157.0: Sol and Luna on Bedrock, and a session that outlives the terminal

Practical dev impact: Codex v0.156.1 put Sol and Luna in the local picker, and v0.157.0 (posted overnight, 25 Sep UTC) is the enterprise catch-up: the same models now sit in the Amazon Bedrock catalogs, with migration prompts when a session is still pinned to an older model. That is the difference between reading the price card and actually routing daily implementation to Sol through the AWS account the shop already uses. The rest of the release is session continuity. Fullscreen transcripts are on by default, eligible interactive sessions start a background server automatically and offer recovery when stored server settings cannot start, f forks a conversation already open in another Codex surface while keeping drafts and queued prompts, and /import now works in remote sessions and local background-server sessions instead of only locally. The fixes matter most on a locked-down laptop, because configured proxy routing now covers realtime and standalone web search, file uploads retry with a five-minute timeout, and network restrictions follow redirects and in-flight HTTP and WebSocket traffic, including cancelling when policy revokes access mid-stream. Upgrade laptops and any CI image that shells out to Codex to v0.157.0 today, run /model, accept the migration prompt if it names an old id, and confirm Bedrock is the upstream you think it is. Treat the new background server as something you inspect rather than a daemon you ignore, and do not call v0.157.0 a Plugin4Shell fix, because that floor is still v0.146.0 or later.

Claude Code v2.1.282: the client that admits what it ignored

Practical dev impact: Claude Code v2.1.281 was the gateway release, and v2.1.282 (24 Sep) is the honesty and resume release. Startup, /status, and claude doctor now list telemetry variables in the project’s settings files that were ignored or that turned telemetry off, so a “we thought OTel was on” thread finally has a client-side answer. The managed setting allowClaudeInChromeWithManagedMcp lets claude --chrome run next to an exclusive managed-mcp.json, and the block error now names that file. maxProseWidth keeps prose from spanning a 200-column terminal while tables and code stay full width, and gateway operators get store.readiness_grace_seconds so /readyz stays ready through a short Postgres failover. The fixes are the real reason to bump. Resumed and continued sessions were re-sending earlier messages in a changed form, which made the API drop Claude’s earlier reasoning, and extended thinking could also vanish after an immediate /model, /rename, or /artifacts during a think, or when --tools on resume left out a built-in tool from the prior turn. Web-search results the API cannot decrypt, which is typical behind a third-party gateway, no longer fail the whole conversation with a 400. Symlink paths with .. or /Network no longer pull a second CLAUDE.md or rules file into the load path, skipped Bash :* permission patterns now match with a warning, and a managed setting with a mistyped boolean lock now applies the lock and reports the error instead of being silently ignored. Pin laptops and images to v2.1.282, run claude doctor once on the repo you ship this week and read the telemetry lines with whoever owns observability, and upgrade before the next --resume on any long thread. If Chrome plus managed MCP is a real workflow, set allowClaudeInChromeWithManagedMcp in managed settings rather than asking developers to drop the MCP lock. The Plugin4Shell floor stays v2.1.179.

Copilot app sandbox and proof of presence: the controls next to the default

Practical dev impact: Two adjacent controls landed the same week. Copilot app local sandboxing (23 Sep, public preview) limits filesystem access, outbound and local network, and Git and GitHub CLI credentials for local repo sessions. It is off by default, you enable it per project with Sandbox new sessions or with /sandbox on in an active session, and it does not apply to cloud sandbox or remote-host sessions or to Copilot CLI. Proof of presence (24 Sep) is for managed-user enterprises on github.com and GHEC-DR that use Entra ID SSO: it requires re-authentication or MFA before creating tokens, editing webhooks or org security settings, or viewing recovery codes, and a pass is good for two hours in that browser session. Burke Holland’s 24 Sep post on when chat is the wrong UI explains why the sandbox matters, because the Copilot app is growing canvases that are small full-stack apps inside the client (a Winget UI, a SQLite UI, custom boards) that talk both ways with the agent and can run local code. If the Copilot app is in daily use, turn the sandbox on for one repo and watch what the agent can no longer read, and if you are an EMU plus Entra shop, route proof of presence through change control rather than treating it as a Copilot footnote. GitHub still had no agent-side Plugin4Shell patch at disclosure, so do not read sandboxing as that patch.

What did not move, so you do not redo Thursday

Practical dev impact: Gemini CLI stable is still v0.61.0 (23 Sep), v0.62.0 exists only as a nightly or preview build this morning, and unpaid and Google One users have been on Antigravity CLI since 18 Jun, so a paid seat should stay on v0.61.0 stable and CI should not pin a nightly. Cursor’s news is an integration note rather than a product ship: the Origin API changelog added a 24 Sep List Namespaces endpoint and a public visibility value that Update Repo will not set. Node 20 is gone from GitHub Actions runners as of 23 Sep, with Node 24 only and the insecure opt-out flag retired, so if Friday’s pipeline is red on a pinned JavaScript action, check for node20 and old action majors before you blame the agent. One Copilot date lands sooner than 22 Oct: GitHub’s 28 Aug notice says that no earlier than 28 Sep, Copilot Chat on github.com, Copilot Chat in GitHub Mobile, and cloud agent converge to one experience and one policy, and Copilot code review’s Default effort becomes Balanced. That is not today’s news, but it belongs on the same admin checklist as the org default.

Practical Impact Analysis

The through-line is that the model decisions are made and the risk has moved into defaults and sessions. Copilot Business and Enterprise now have a written rule for every future GA feature you do not configure, and because that rule starts as Enabled, putting it off until next quarter is how an org that never asked for MCP or code review ends up with both on 22 Oct. The fix is an hour of explicit choices, not a new policy framework.

The session is the second half of the same problem. A strong model only pays off if the work survives a --resume, a --continue, a background server restart, or a fork into another surface with its thinking and queued prompts intact, and v2.1.282 and v0.157.0 are the releases that make that less of a gamble. The telemetry lines in claude doctor belong here too, because a session you cannot observe is one you cannot trust to be the one you configured.

The bill path follows from both. Sol and Luna in the Bedrock catalog mean a shop that already buys inference through AWS can move its daily lane to Sol without another vendor login, while a shop that is not on Bedrock can skip that step and still take the client upgrade for the session fixes. Do all three on one team today, and keep a canvases design sprint and a gateway rewrite out of the same meeting.

Tutorial

Policy-and-session check on one repo you already ship. About twenty-five minutes. No new model bake-off. Numbered steps first; then one copy-paste block.

  1. Freeze the clients: Claude Code wants v2.1.282+ (Plugin4Shell floor remains v2.1.179), Codex wants v0.157.0+ (Plugin4Shell floor remains v0.146.0), and Gemini CLI stays on v0.61.0 stable if you still run it.
  2. Run claude doctor from the repo root and read the lines naming telemetry variables that were ignored or that turned telemetry off. If the board you expected is empty, fix the settings file, not the dashboard query.
  3. On a throwaway branch, start a Claude Code thread, let it think, run /model once mid-think, exit, and claude --resume the same session. If the thinking is gone, you are not on v2.1.282.
  4. In Codex, run /model, pick gpt-6-sol for daily work (Luna when the rate-limit prompt fires), accept any migration prompt, and if inference goes through Bedrock confirm Sol and Luna show up there. Press f to fork into the other Codex surface you use and confirm the drafts survived.
  5. In the enterprise or org, open Settings > AI Controls > Copilot and set Default policy for new features. Disabled or Let organizations decide is the safe Friday choice; leaving it untouched leaves Enabled. Then set every Unconfigured row on Features & clients, Agents (code review), and MCP servers in Copilot, using the count banner.
  6. If the Copilot app is in use on this repo, turn on Sandbox new sessions for the project or run /sandbox on in the current session. It does not cover cloud or remote-host sessions.
bash Tutorial
#!/usr/bin/env bash
# Policy-and-session check, run from the repo root.

echo "== Claude Code (want v2.1.282+; Plugin4Shell floor v2.1.179) =="
claude --version

echo "== Codex (want v0.157.0+; Plugin4Shell floor v0.146.0) =="
codex --version

echo "== Gemini CLI (v0.61.0 stable if you still run it; no nightlies) =="
gemini --version || true

# Telemetry variables in project settings that were ignored or turned telemetry off
claude doctor


... click "Show full code" below to expand
▸ Show full code (30 lines)
#!/usr/bin/env bash
# Policy-and-session check, run from the repo root.

echo "== Claude Code (want v2.1.282+; Plugin4Shell floor v2.1.179) =="
claude --version

echo "== Codex (want v0.157.0+; Plugin4Shell floor v0.146.0) =="
codex --version

echo "== Gemini CLI (v0.61.0 stable if you still run it; no nightlies) =="
gemini --version || true

# Telemetry variables in project settings that were ignored or turned telemetry off
claude doctor

# Claude Code resume check (interactive, throwaway branch):
#   think -> /model mid-think -> exit -> claude --resume  (thinking should survive)

# Codex (interactive):
#   /model  -> gpt-6-sol daily, gpt-6-luna on the rate-limit prompt; accept migration
#   /usage  -> confirm the ids that are billing (Bedrock catalog if that is your upstream)
#   f       -> fork into your other Codex surface; drafts and queued prompts survive

# Copilot app, this project only (public preview, off by default):
#   /sandbox on

# CI footnote: Node 20 is gone from Actions runners
grep -rn "node20" .github/ || echo "No node20 references under .github/"

echo "Next: Settings > AI Controls > Copilot, set the default before 22 Oct 2026."

Confirm client versions, a readable claude doctor telemetry report, one resume that kept its thinking, and zero Unconfigured rows in AI Controls before you call the week closed.

Recommended AI prompt

Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever you use.

You are a staff engineer helping me close out a policy-and-session Friday for one team. I will paste three things: the Copilot AI Controls rows that still show Unconfigured along with our current Default policy for new features setting, the telemetry lines that claude doctor prints on our main repo, and whether our Codex inference runs through Amazon Bedrock. Using only what I paste, tell me which value to set for the Copilot default before Unconfigured GA rows start following it on 22 Oct 2026 and which rows (code review, MCP servers, client features) to set explicitly, which client floors to enforce today given Claude Code v2.1.282 and Codex v0.157.0, whether moving our daily lane to GPT-6 Sol on Bedrock applies to us, and one resume or /sandbox on check I can finish in under 30 minutes. Keep your first reply to that four-item checklist, do not reopen model pricing or Cursor bot rollouts, do not invent settings or dashboards I did not name, and wait for my paste before expanding.

Recommended AI prompt

Explore each Top Story in Grok. Links open in a new tab. On phones, the same link may open the Grok app if you have it installed (via your device's normal link handling).

Article: Copilot Default Turns On Unconfigured Features as Codex and Claude Code Keep Sessions

Privacy: links open grok.com in your session only. AIDevPulse does not run your prompts through our API.

6 thoughts on “Copilot Default Turns On Unconfigured Features as Codex and Claude Code Keep Sessions”

Leave a Comment