7.3. Enterprise Managed Users and Org-Wide Copilot Policies
At Enterprise scale, identity and AI policy stop being per-account decisions and become centrally governed ones.
💡 First Principle: Enterprise Managed Users (EMU) shifts identity ownership from the individual to the company — accounts are provisioned and controlled entirely through the organization's identity provider (IdP), rather than being personal GitHub.com accounts an employee brings with them. This is a deliberate trade-off: it gives the enterprise full control over account lifecycle (created and deactivated automatically as employment changes) at the cost of the account not being usable outside that enterprise's GitHub environment. Organization-wide Copilot policy management extends this same centralization to AI: an Enterprise or Business admin can enforce access rules and usage policy for Copilot across every organization under their control, rather than leaving it to individual settings.
⚠️ Exam Trap: An Enterprise Managed User account is provisioned and controlled by the company's identity provider — it is not a personal GitHub.com account the employee owns and brings with them, and it isn't usable outside that enterprise's environment.
Reflection Question: A company using Enterprise Managed Users offboards an employee by deactivating their account in the company's identity provider. Does that alone remove their GitHub access, or does someone also need to manually deactivate a separate GitHub account?