# 企业托管设置参考

Copilot 客户端使用的企业托管设置架构参考。

使用此参考了解 `managed-settings.json` 中当前支持的密钥。

有关部署方法和支持的客户端，请参阅 [配置企业管理设置](/zh/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-agents/configure-enterprise-managed-settings)。

## 优先规则

当存在多个设置源时，此列表中的前面设置优先于列表中的设置：

1. 受 MDM 管理的设置
2. 由服务器管理的设置
3. 基于文件的配置
4. 用户级设置

## 支持的密钥

<div class="ghd-tool rowheaders">

| 密钥                                         | Purpose                                       | Copilot 命令行界面（CLI）                                                                                                                                                                                                                                                                                                       | VS Code                                                                                                                                                                                                                                                                                                                  | GitHub Copilot 应用                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ------------------------------------------ | --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `permissions.disableBypassPermissionsMode` | 禁用绕过或 YOLO 样式允许的所有行为                          | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg>                                                                                                            |
| `permissions.model`                        | 将自动模型选择设置为新对话的默认值                             | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg>                                                                                                            |
| `enabledPlugins`                           | 按密钥启用或禁用特定插件                                  | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg>                                                                                                            |
| `extraKnownMarketplaces`                   | 添加用户可以访问的插件市场                                 | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg>                                                                                                            |
| `strictKnownMarketplaces`                  | 仅允许从明确列出的应用市场安装插件                             | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg>                                                                                                            |
| `telemetry`                                | 配置 OpenTelemetry 导出，将 Copilot 使用数据路由到你所选择的收集器 | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-check" aria-label="Supported" role="img"><path d="M13.78 4.22a.75.75 0 0 1 0 1.06l-7.25 7.25a.75.75 0 0 1-1.06 0L2.22 9.28a.751.751 0 0 1 .018-1.042.751.751 0 0 1 1.042-.018L6 10.94l6.72-6.72a.75.75 0 0 1 1.06 0Z"></path></svg> | <svg version="1.1" width="16" height="16" viewBox="0 0 16 16" class="octicon octicon-x" aria-label="Not supported" role="img"><path d="M3.72 3.72a.75.75 0 0 1 1.06 0L8 6.94l3.22-3.22a.749.749 0 0 1 1.275.326.749.749 0 0 1-.215.734L9.06 8l3.22 3.22a.749.749 0 0 1-.326 1.275.749.749 0 0 1-.734-.215L8 9.06l-3.22 3.22a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042L6.94 8 3.72 4.78a.75.75 0 0 1 0-1.06Z"></path></svg> |

</div>

## 配置示例

以下示例在一个托管设置文件中显示这些密钥。

```json
{
  "permissions": {
    "disableBypassPermissionsMode": "disable",
    "model": "auto"
  },
  "enabledPlugins": {
    "my-plugin@agent-skills": true
  },
  "extraKnownMarketplaces": {
    "agent-skills": {
      "source": {
        "source": "github",
        "repo": "OWNER/REPO"
      }
    }
  },
  "strictKnownMarketplaces": [
    {
      "source": "github",
      "repo": "OWNER/REPO"
    }
  ],
  "telemetry": {
    "enabled": true,
    "endpoint": "https://otel-collector.example.com",
    "protocol": "http/protobuf",
    "captureContent": false,
    "lockCaptureContent": true,
    "serviceName": "copilot",
    "resourceAttributes": {
      "deployment.environment": "production"
    },
    "headers": {
      "Authorization": "Bearer TOKEN"
    }
  }
}
```

## `enabledPlugins`

定义为所有企业用户自动安装或禁止的插件。 每个条目使用格式 `PLUGIN-NAME@MARKETPLACE-NAME` 作为键，并带有布尔值： `true` 要求启用插件或 `false` 要求禁用插件。 请参阅“[关于企业管理的插件标准](/zh/copilot/concepts/agents/about-enterprise-plugin-standards)”。

## `extraKnownMarketplaces`

定义可供用户使用的其他插件市场。 每个条目都是包含属性 `source` 的命名市场对象。 支持以下源类型：

* `"github"` - 需要 `repo` 格式的 `OWNER/REPO`；可选的 `ref`（分支、标记或 SHA）和 `path`（子目录）
* `"git"` — 需要 `url`;可选 `ref` 和 `path`
* `"directory"` — 需要 `path`

请参阅“[关于企业管理的插件标准](/zh/copilot/concepts/agents/about-enterprise-plugin-standards)”。

## `strictKnownMarketplaces`

将插件安装限制为仅可从企业明确指定的应用市场进行安装。 空数组表示完全锁定。 每个条目都是一个市场对象，其中包含一个 `source` 指示源类型的属性。 支持以下源类型：

* `"github"` - 需要  `repo` 格式的 `OWNER/REPO`，可选 `ref` 和 `path`
* `"git"` — 需要 `url`;可选 `ref` 和 `path`
* `"url"` — 需要 `url`;可选 `headers` 对象
* `"npm"` — 需要 `package`
* `"file"` — 需要 `path`
* `"directory"` — 需要 `path`
* `"hostPattern"` - 需要 `hostPattern`（用于匹配市场主机的正则表达式）
* `"pathPattern"` - 需要 `pathPattern`（用于匹配市场路径的正则表达式）

## `permissions`

### `disableBypassPermissionsMode`

阻止用户启用绕过模式（也称为“YOLO 模式”）。 绕过模式允许代理在不请求批准的情况下运行命令、访问文件和提取 URL。

当您将 `disableBypassPermissionsMode` 设置为 `"disable"` 时，用户无法启用绕过模式：

* 在 Copilot 命令行界面（CLI） 中，`--yolo` 和 `--allow-all` 命令行选项以及 `/yolo` 和 `/allow-all` 斜杠命令被阻止。 单个标记（如`--allow-all-tools`和`--allow-all-paths`）不会被屏蔽。
* 在中 VS Code，全局自动批准设置（`chat.tools.global.autoApprove`）已关闭，无法重新启用。
* 在 GitHub Copilot 应用 的会话设置中，“工具权限”的“允许所有”设置被禁用。

### `model`

将自动模型选择设置为新对话的默认值。 请参阅“[关于 Copilot自动模型选择](/zh/copilot/concepts/models/auto-model-selection)”。

如果设置为`permissions.model``"auto"`，则新会话将使用自动模型，除非用户为每个会话指定不同的模型。

## `telemetry`

配置 OpenTelemetry 导出，将使用情况数据路由 Copilot 到所选收集器。

Copilot 命令行界面（CLI） 和 VS Code 支持此属性。

设置 `telemetry` 属性时， Copilot 遥测数据将发送到指定的终结点。 支持以下子属性：

* `enabled`：设置为 `true` 打开遥测导出，或 `false` 将其关闭。
* `endpoint`：OTLP 收集器的 URL（例如 `https://otel-collector.example.com`）。
* `protocol`：用于遥测导出的传输协议。 接受的值是 `"http/json"` 和 `"http/protobuf"`。
* `captureContent`：设置为 `true` 时，在遥测有效负载中包含提示和响应内容；设置为 `false` 时，则不包含这些内容。
* `lockCaptureContent`：设置为 `true` 阻止用户更改 `captureContent` 设置。
* `serviceName`：遥测服务名称的标签（例如 `"copilot"`）。
* `resourceAttributes`：一个包含 OpenTelemetry 资源属性的对象，用于附加到所有导出的遥测数据（例如 `{"deployment.environment": "production"}`）。
* `headers`：要随附于每个遥测请求的 HTTP 头的对象（例如，适用于收集器的 `Authorization` 头）。