diff --git a/content/billing/reference/product-and-sku-names.md b/content/billing/reference/product-and-sku-names.md
index 15262c6dfb6d..2a74156d0fdd 100644
--- a/content/billing/reference/product-and-sku-names.md
+++ b/content/billing/reference/product-and-sku-names.md
@@ -35,17 +35,19 @@ For **SkuPricing** budgets or to query usage by SKU, use one of the following va
* `actions_cache_storage` - Actions cache storage
* `actions_custom_image_storage` - Actions custom image storage
* `actions_linux` - Actions Linux runners
-* `actions_linux_2_core_advanced` - Actions Linux 2-core advanced
-* `actions_linux_2_core_arm` - Actions Linux 2-core ARM
+* `actions_linux_16_core` - Actions Linux 16-core
+* `actions_linux_16_core_arm` - Actions Linux ARM 16-core
+* `actions_linux_2_core_advanced` - Actions Linux Advanced 2-core
+* `actions_linux_2_core_arm` - Actions Linux ARM 2-core
* `actions_linux_32_core` - Actions Linux 32-core
-* `actions_linux_32_core_arm` - Actions Linux 32-core ARM
+* `actions_linux_32_core_arm` - Actions Linux ARM 32-core
* `actions_linux_4_core` - Actions Linux 4-core
-* `actions_linux_4_core_arm` - Actions Linux 4-core ARM
-* `actions_linux_4_core_gpu` - Actions Linux 4-core GPU
+* `actions_linux_4_core_arm` - Actions Linux ARM 4-core
+* `actions_linux_4_core_gpu` - Actions Linux GPU 4-core
* `actions_linux_64_core` - Actions Linux 64-core
-* `actions_linux_64_core_arm` - Actions Linux 64-core ARM
+* `actions_linux_64_core_arm` - Actions Linux ARM 64-core
* `actions_linux_8_core` - Actions Linux 8-core
-* `actions_linux_8_core_arm` - Actions Linux 8-core ARM
+* `actions_linux_8_core_arm` - Actions Linux ARM 8-core
* `actions_linux_96_core` - Actions Linux 96-core
* `actions_linux_arm` - Actions Linux ARM
* `actions_linux_slim` - Actions Linux slim
@@ -55,18 +57,20 @@ For **SkuPricing** budgets or to query usage by SKU, use one of the following va
* `actions_storage` - Actions storage
* `actions_windows` - Actions Windows runners
* `actions_windows_16_core` - Actions Windows 16-core
+* `actions_windows_16_core_arm` - Actions Windows ARM 16-core
* `actions_windows_2_core` - Actions Windows 2-core
-* `actions_windows_2_core_advanced` - Actions Windows 2-core advanced
-* `actions_windows_2_core_arm` - Actions Windows 2-core ARM
-* `actions_windows_4_core_arm` - Actions Windows 4-core ARM
+* `actions_windows_2_core_advanced` - Actions Windows Advanced 2-core
+* `actions_windows_2_core_arm` - Actions Windows ARM 2-core
* `actions_windows_32_core` - Actions Windows 32-core
-* `actions_windows_32_core_arm` - Actions Windows 32-core ARM
+* `actions_windows_32_core_arm` - Actions Windows ARM 32-core
* `actions_windows_4_core` - Actions Windows 4-core
-* `actions_windows_4_core_gpu` - Actions Windows 4-core GPU
+* `actions_windows_4_core_arm` - Actions Windows ARM 4-core
+* `actions_windows_4_core_gpu` - Actions Windows GPU 4-core
* `actions_windows_64_core` - Actions Windows 64-core
-* `actions_windows_64_core_arm` - Actions Windows 64-core ARM
+* `actions_windows_64_core_arm` - Actions Windows ARM 64-core
* `actions_windows_8_core` - Actions Windows 8-core
-* `actions_windows_8_core_arm` - Actions Windows 8-core ARM
+* `actions_windows_8_core_arm` - Actions Windows ARM 8-core
+* `actions_windows_96_core` - Actions Windows 96-core
* `actions_windows_arm` - Actions Windows ARM
diff --git a/content/copilot/concepts/models/default-availability.md b/content/copilot/concepts/models/default-availability.md
index 6d0ec2335f6f..41aaed3cc99b 100644
--- a/content/copilot/concepts/models/default-availability.md
+++ b/content/copilot/concepts/models/default-availability.md
@@ -17,7 +17,7 @@ On {% data variables.copilot.copilot_business_short %} and {% data variables.cop
-To give you time to prepare, this policy can be configured but **does not currently affect model availability**. On August 26, 2026, new GA models and existing unconfigured GA models will automatically follow the default set in the policy. These are models that you have not explicitly chosen a setting for. They will be relabeled as "inherits default" in the UI.
+To give you time to prepare, this policy can be configured but **does not currently affect model availability**. On August 26, 2026, new GA models and existing unconfigured GA models will automatically follow the default set in the policy. These models will be relabeled as "inherits default" in the UI.
To prepare for this change, you can disable the policy or explicitly disable models you don't want to be enabled.
diff --git a/content/copilot/how-tos/administer-copilot/manage-for-enterprise/enable-custom-models.md b/content/copilot/how-tos/administer-copilot/manage-for-enterprise/enable-custom-models.md
index 1a198b807f5c..85b428d5d7a4 100644
--- a/content/copilot/how-tos/administer-copilot/manage-for-enterprise/enable-custom-models.md
+++ b/content/copilot/how-tos/administer-copilot/manage-for-enterprise/enable-custom-models.md
@@ -30,7 +30,7 @@ After you've added your key and selected one or more models, you and members of
{% data reusables.enterprise-accounts.access-enterprise %}
{% data reusables.enterprise-accounts.ai-controls-tab %}
1. In the sidebar, click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
-1. Click **Configure allowed models**.
+1. Click **Configure custom models**.
{% data reusables.copilot.byok-add %}
## Managing availability of custom models in your organizations
diff --git a/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-availability-of-default-models.md b/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-availability-of-default-models.md
index 7bf1719595cd..c45915a1a1b5 100644
--- a/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-availability-of-default-models.md
+++ b/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-availability-of-default-models.md
@@ -32,9 +32,6 @@ This sets a baseline that you can add to with more granular controls. For models
{% data reusables.enterprise-accounts.ai-controls-tab %}
{% data reusables.enterprise-accounts.copilot-sidebar %}
{% data reusables.enterprise-accounts.configure-allowed-models %}
-1. Above the list of models, click **Add models**.
-1. In the modal, select or deselect the checkboxes next to the models you want to make available or remove.
-1. Click **Save**.
1. Select a status for each model in the list:
* **Enabled**: Enabled for everyone.
@@ -76,7 +73,7 @@ Before opting in to the preview, we recommend you create enterprise teams and be
For each team, you can use the **default models** tab to configure the model access that the team will receive. These settings do not apply until you opt in to the preview.
-Make sure your new setup will not cause regressions for users. Although models that are explicitly "enabled" or "disabled" at the enterprise level will keep those settings once you opt in to the preview, models that are "optional" or unconfigured will be unavailable by default until they are enabled for specific teams. Identify these models and choose which teams will receive access to them.
+Make sure your new setup will not cause regressions for users. Although models that are explicitly "enabled" or "disabled" at the enterprise level will keep those settings once you opt in to the preview, models that are "optional" or unconfigured will be unavailable by default until they are enabled for specific teams. Filter your enterprise's model policy page by status to identify these models and choose which teams will receive access to them.
For information on creating teams, see [AUTOTITLE](/enterprise-cloud@latest/admin/managing-accounts-and-repositories/managing-users-in-your-enterprise/create-enterprise-teams).
diff --git a/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-enterprise-policies.md b/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-enterprise-policies.md
index b463f142c793..b3628cc5a50b 100644
--- a/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-enterprise-policies.md
+++ b/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-enterprise-policies.md
@@ -30,7 +30,8 @@ Enterprise owners can define a policy for the whole enterprise, or delegate the
1. Navigate to the page containing the policies you want to manage:
* To view policies for **AI agents**, in the sidebar, click {% octicon "agent" aria-hidden="true" aria-label="agent" %} **Agents**.
- * To view policies for **{% data variables.product.prodname_copilot_short %}**, in the sidebar, click {% octicon "copilot" aria-hidden="true" aria-label="copilot" %} **{% data variables.product.prodname_copilot_short %}**.
+ * To view administration, privacy, model, billing, and usage policies for **{% data variables.product.prodname_copilot_short %}**, in the sidebar, click {% octicon "copilot" aria-hidden="true" aria-label="copilot" %} **{% data variables.product.prodname_copilot_short %}**.
+ * To view policies for **{% data variables.product.prodname_copilot_short %}** features and clients, in the sidebar, click {% octicon "copilot" aria-hidden="true" aria-label="copilot" %} **{% data variables.product.prodname_copilot_short %}**, then, under "Features & clients," click **Configure features & clients**.
* To view policies for **Model Context Protocol (MCP)**, in the sidebar, click {% octicon "mcp" aria-hidden="true" aria-label="mcp" %} **MCP**.
1. Configure your policies as follows:
* For policies with a **dropdown menu**, select the menu and click an enforcement option.
@@ -43,7 +44,7 @@ Enterprise owners can define a policy for the whole enterprise, or delegate the
## Opting in to feedback collection
-If you enable "{% data variables.product.prodname_copilot_short %} in {% data variables.product.prodname_dotcom_the_website %}" from the "{% data variables.product.prodname_copilot_short %}" page of the "AI Controls" tab, you can also opt in to user feedback collection to help {% data variables.product.github %} improve {% data variables.product.prodname_copilot_short %} features.
+If you enable "{% data variables.product.prodname_copilot_short %} in {% data variables.product.prodname_dotcom_the_website %}" from the "Features & clients" page, you can also opt in to user feedback collection to help {% data variables.product.github %} improve {% data variables.product.prodname_copilot_short %} features.
## Further reading
diff --git a/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-spark.md b/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-spark.md
index 28c91824c3b9..851f29b3c0ed 100644
--- a/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-spark.md
+++ b/content/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-spark.md
@@ -33,7 +33,7 @@ To use {% data variables.product.prodname_spark_short %}, your enterprise must b
By default, {% data variables.product.prodname_spark_short %} is **disabled** for users who receive a {% data variables.copilot.copilot_enterprise_short %} license from an enterprise-owned organization.
-You can allow members to use {% data variables.product.prodname_spark_short %} from the AI Controls tab for your enterprise. See [AUTOTITLE](/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-enterprise-policies#defining-policies-for-your-enterprise).
+You can allow members to use {% data variables.product.prodname_spark_short %} from the "Features & clients" page of the AI Controls tab for your enterprise. See [AUTOTITLE](/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-enterprise-policies#defining-policies-for-your-enterprise).
{% data reusables.enterprise-accounts.policy-enablement-next-steps %}
diff --git a/content/copilot/how-tos/administer-copilot/manage-for-organization/enable-custom-models.md b/content/copilot/how-tos/administer-copilot/manage-for-organization/enable-custom-models.md
index a70d09ef9b0d..9bfe6786cd3f 100644
--- a/content/copilot/how-tos/administer-copilot/manage-for-organization/enable-custom-models.md
+++ b/content/copilot/how-tos/administer-copilot/manage-for-organization/enable-custom-models.md
@@ -35,6 +35,7 @@ After you've added your key and selected one or more models, you and your organi
{% data reusables.profile.org_settings %}
1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
1. Under "Copilot", click **Models**.
+1. Click the **Custom models** tab.
{% data reusables.copilot.byok-add %}
## Further reading
diff --git a/content/copilot/how-tos/copilot-cli/administer-copilot-cli-for-your-enterprise.md b/content/copilot/how-tos/copilot-cli/administer-copilot-cli-for-your-enterprise.md
index 8dabe088b3e4..a3201415c77b 100644
--- a/content/copilot/how-tos/copilot-cli/administer-copilot-cli-for-your-enterprise.md
+++ b/content/copilot/how-tos/copilot-cli/administer-copilot-cli-for-your-enterprise.md
@@ -23,7 +23,8 @@ You can control the use of {% data variables.copilot.copilot_cli_short %} by con
{% data reusables.enterprise-accounts.access-enterprise %}
{% data reusables.enterprise-accounts.ai-controls-tab %}
1. To manage policies for **{% data variables.product.prodname_copilot_short %}**, in the sidebar, click {% octicon "copilot" aria-hidden="true" aria-label="copilot" %} **{% data variables.product.prodname_copilot_short %}**.
-1. In the "{% data variables.product.prodname_copilot_short %} Clients" section, for {% data variables.copilot.copilot_cli_short %}, select your preferred policy.
+1. Under "Features & clients," click **Configure features & clients**.
+1. In the "Clients" section, for {% data variables.copilot.copilot_cli_short %}, select your preferred policy.
> [!NOTE]
> Disabling {% data variables.copilot.copilot_cli_short %} does not disable the {% data variables.copilot.github_copilot_app %}. The app is governed by its own policy. For more information, see [AUTOTITLE](/copilot/concepts/agents/github-copilot-app).
diff --git a/content/copilot/how-tos/use-ai-models/change-the-chat-model.md b/content/copilot/how-tos/use-ai-models/change-the-chat-model.md
index 349ff59381b8..7f21f8dc2c5f 100644
--- a/content/copilot/how-tos/use-ai-models/change-the-chat-model.md
+++ b/content/copilot/how-tos/use-ai-models/change-the-chat-model.md
@@ -75,7 +75,7 @@ You can expand the model options that are available to power {% data variables.c
* Depending on the provider or model you choose, you may need to supply an API key, or model ID, from the provider, or a {% data variables.product.github %} {% data variables.product.pat_generic %} (PAT).
* To add models from the AI Toolkit for {% data variables.product.prodname_vscode %}, you must install the AI Toolkit extension.
-* If you are a {% data variables.copilot.copilot_business_short %} or {% data variables.copilot.copilot_enterprise_short %} customer and want to use third-party models in {% data variables.product.prodname_vscode %}, the **Bring Your Own Language Model Key in {% data variables.product.prodname_vscode_shortname %}** policy must be enabled. For more information, see the [{% data variables.product.prodname_copilot_short %} settings page](https://github.com/settings/copilot/features) in {% data variables.product.prodname_dotcom_the_website %}.
+* If you are on a {% data variables.copilot.copilot_business_short %} or {% data variables.copilot.copilot_enterprise_short %} plan and want to use third-party models in a supported IDE, the **Bring Your Own Language Model Key in Select IDEs** policy must be enabled. For more information, see [AUTOTITLE](/copilot/how-tos/administer-copilot/manage-for-organization/manage-policies) or [AUTOTITLE](/copilot/how-tos/administer-copilot/manage-for-enterprise/manage-enterprise-policies).
### Adding models
diff --git a/content/copilot/how-tos/use-copilot-agents/copilot-memory/manage-as-administrator.md b/content/copilot/how-tos/use-copilot-agents/copilot-memory/manage-as-administrator.md
index a98bc0d1d00e..73f6fa226dfb 100644
--- a/content/copilot/how-tos/use-copilot-agents/copilot-memory/manage-as-administrator.md
+++ b/content/copilot/how-tos/use-copilot-agents/copilot-memory/manage-as-administrator.md
@@ -27,6 +27,7 @@ Once {% data variables.copilot.copilot_memory %} is enabled, the feature is on f
{% data reusables.enterprise-accounts.access-enterprise %}
{% data reusables.enterprise-accounts.ai-controls-tab %}
1. In the sidebar, click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
+1. Under "Features & clients," click **Configure features & clients**.
1. Under "Features", scroll down to the **{% data variables.copilot.copilot_memory %}** setting and select a policy from the dropdown.
### Enabling {% data variables.copilot.copilot_memory %} for an organization
diff --git a/content/copilot/reference/copilot-cli-reference/cli-command-reference.md b/content/copilot/reference/copilot-cli-reference/cli-command-reference.md
index d7a024000ca4..0cfa323644a2 100644
--- a/content/copilot/reference/copilot-cli-reference/cli-command-reference.md
+++ b/content/copilot/reference/copilot-cli-reference/cli-command-reference.md
@@ -19,6 +19,7 @@ docsTeamMetrics:
| Command | Purpose |
|------------------------|----------------------------------------------------|
| `copilot` | Launch the interactive user interface. |
+| `copilot app` | Open the {% data variables.copilot.github_copilot_app %} in the current directory, deep-linking straight to a new session. Falls back to opening the app's download page in a browser if the deep link can't be handled, or prints the URL to open manually if no browser is available. |
| `copilot completion SHELL` | Print a shell script for the chosen shell that can be used to enable tab completion for {% data variables.copilot.copilot_cli_short %}. Supported shells: `bash`, `zsh`, `fish`. See [Using `copilot completion`](#using-copilot-completion). |
| `copilot help [TOPIC]` | Display help information. Help topics include: `billing`, `config`, `commands`, `environment`, `logging`, `monitoring`, `permissions`, `providers`, and `sandbox`. |
| `copilot init` | Initialize {% data variables.product.prodname_copilot_short %} custom instructions for this repository. |
@@ -189,12 +190,14 @@ With `--skill`, pass either a skill name or the path to a custom skill directory
| Ctrl+L | Clear the screen. |
| Ctrl+Enter or Ctrl+Q | Queue a message to send while the agent is busy. |
| Ctrl+R | Reverse search through command history. |
+| Ctrl+Space | Toggle voice dictation on or off (alias for Ctrl+X then `v`). Hold Space to record instead of toggling. |
| Ctrl+V | Paste from clipboard as an attachment. |
| Alt+V | Paste image from clipboard as an attachment. |
| Ctrl+X then `/` | After you have started typing a prompt, this allows you to run a slash command—for example, if you want to change the model without having to retype your prompt. |
| Ctrl+X then `e` | Edit the prompt in an external editor (`$EDITOR`). |
| Ctrl+X then `b` | Promote the running task or shell command to the background. |
| Ctrl+X then `o` | Open the most recent link from the timeline. |
+| Ctrl+X then `v` | Toggle voice dictation on or off. |
| Ctrl+Z | Suspend the process to the background (Unix). |
| Shift+Enter or Option+Enter (Mac) / Alt+Enter (Windows/Linux) | Insert a newline in the input. |
| Shift+Tab | Cycle between standard, plan, and autopilot mode. |
@@ -322,6 +325,7 @@ These are the slash commands you can use from within an interactive CLI session.
| `/copy` | Copy the last response to the clipboard. |
| `/cwd`, `/cd [PATH]` | Change the working directory or display the current directory. |
| `/delegate [PROMPT]` | Delegate changes to a remote repository with an AI-generated pull request. See [AUTOTITLE](/copilot/how-tos/copilot-cli/use-copilot-cli/delegate-tasks-to-cca). |
+| `/diagnose [PROMPT]`, `/diagnose` | Analyze the current session log for errors, unexpected behavior, and other issues. Optionally include a custom prompt to focus the diagnosis on a specific problem. |
| `/diff` | Review changes in the current directory; auto-switches to branch diff when the working tree is clean (experimental). |
| `/downgrade VERSION` | Download and restart into a specific CLI version. Available for team accounts. |
| `/env` | Show loaded environment details (instructions, MCP servers, skills, agents, hooks, plugins, LSPs, extensions). |
@@ -487,13 +491,21 @@ For a complete list of commands and options, run `copilot help`.
You can use `--remote` with `--resume ` to resume a remote task locally. This works even when the task was originally created outside a Git repository.
+If a session was still open when its CLI process went away, for example due to a crash or a machine restart, the next time you start `copilot` you're offered the option to restore it. You can review the sessions available to restore or start a fresh session instead. A restored session whose agent was mid-turn automatically resumes that work.
+
### Plan-then-autopilot
Plan-then-autopilot lets a session start in plan mode and automatically continue into autopilot mode once the plan is ready, without waiting for a human to approve the transition. Enable it with `--plan --mode autopilot`, or with the `COPILOT_PLAN_THEN_AUTOPILOT` environment variable for harnesses that can only inject environment variables and not command-line options. If both are set, the explicit options take precedence and the CLI displays a warning that the environment variable was ignored.
### Enterprise-managed sandbox floor
-An enterprise-managed policy can force the OS-level shell sandbox on as a floor that `--no-sandbox` cannot lift. `--sandbox` is unaffected by this floor, since it only ever turns sandboxing on. When a managed floor overrides `--no-sandbox`, the CLI reports the override as a warning in the interactive timeline (or on stderr when using `-p`), so it isn't mistaken for the option failing to work. Contact your administrator to change the policy. {% data reusables.copilot.experimental %}
+An enterprise-managed policy can enforce OS-level shell sandboxing as a minimum floor. In other words, even if you pass `--no-sandbox`, the policy can still force sandboxing on. This is a policy override, not a failure of the flag itself. By contrast, `--sandbox` is unaffected because it only turns sandboxing on and never removes it.
+
+When a managed policy overrides your setting, the CLI shows a warning in the interactive timeline (or on stderr when using `-p`) so it is clear that the behavior comes from policy enforcement rather than the option failing to work. Contact your administrator if you need the policy changed. {% data reusables.copilot.experimental %}
+
+The CLI also warns when a managed policy enables sandboxing in a session that you did not request, not only when it overrides `--no-sandbox`. This includes sessions where the policy arrives after startup, because server-managed settings are only available after login. The warning is omitted if your own settings or the `--sandbox` option already requested sandboxing, since the session state would then be expected.
+
+If a device has a managed policy that could not be read, the CLI still reports that sandboxing is enforced at its most restrictive level as a fail-closed measure, and directs you to your administrator instead of implying that a specific policy is in effect.
### Restricting the --allow-all options
@@ -501,6 +513,8 @@ When `permissions.disableBypassPermissionsMode` is set to `"disable"`, all of th
Set `permissions.disableBypassPermissionsMode` to `"allow-auto-only"` to block full allow-all permissions but permit `/permissions assisted` (LLM-assisted permission approval). Assisted approval still prompts for each request, but attaches an LLM safety recommendation so the CLI can auto-approve requests the model evaluates as acceptable.
+If `permissions.disableBypassPermissionsMode` is set to an unrecognized value, the CLI no longer rejects it outright. Instead, the CLI logs the issue and enforces `"disable"` as a fail-closed default, so a malformed managed policy still restricts the allow-all options instead of silently allowing them.
+
Three sources can set this restriction, in increasing order of permanence:
| Source | Scope | Cleared by account switch? |
diff --git a/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md b/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md
index 5799b5c803bc..bb4b39074afa 100644
--- a/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md
+++ b/content/copilot/reference/copilot-cli-reference/cli-config-dir-reference.md
@@ -649,7 +649,7 @@ Only the following keys are supported in MDM managed settings.
> When `remoteControl.mode` is `"requireSSO"`, list the allowed organizations in `remoteControl.githubDotComOrganizations`. The client must be SSO-authorized for at least one listed {% data variables.product.prodname_dotcom_the_website %} organization—it no longer needs to be authorized for all of them.
> [!NOTE]
-> Set `permissions.disableBypassPermissionsMode` to `"disable"` in MDM managed settings to enforce the restriction at the device level. Account switches cannot override this policy. Set it to `"allow-auto-only"` to block full allow-all escalation while still permitting `/permissions assisted` (LLM-assisted permission approval). See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-command-reference#restricting-the---allow-all-options).
+> Set `permissions.disableBypassPermissionsMode` to `"disable"` in MDM managed settings to enforce the restriction at the device level. Account switches cannot override this policy. Set it to `"allow-auto-only"` to block full allow-all escalation while still permitting `/permissions assisted` (LLM-assisted permission approval). If an unrecognized value is set, the CLI logs the issue and enforces `"disable"` as a fail-closed default, so a malformed managed policy still restricts the allow-all options instead of silently allowing them. See [AUTOTITLE](/copilot/reference/copilot-cli-reference/cli-command-reference#restricting-the---allow-all-options).
> [!NOTE]
> Most managed keys lock the entire row: a local edit is silently overridden by the managed value on the next load. `enabledPlugins` and `extraKnownMarketplaces` are the exception—the managed layer merges these maps with your own entries field-by-field instead of replacing them outright. This means the lock applies **per entry**, not to the whole key: a plugin or marketplace pinned by a managed policy can't be re-enabled, disabled, or repointed locally, but other entries in the same map remain fully user-controlled.
diff --git a/content/copilot/reference/enterprise-administrators/policy-conflicts.md b/content/copilot/reference/enterprise-administrators/policy-conflicts.md
index 76de262eac28..f7cbaa1e34ba 100644
--- a/content/copilot/reference/enterprise-administrators/policy-conflicts.md
+++ b/content/copilot/reference/enterprise-administrators/policy-conflicts.md
@@ -42,7 +42,7 @@ Feature, model, and privacy settings for users are set according to the **least
| {% data variables.product.prodname_copilot_short %} can search the web | Least restrictive organization | [AUTOTITLE](/copilot/responsible-use/chat) |
| {% data variables.copilot.copilot_mobile_short %} | Least restrictive organization | [AUTOTITLE](/copilot/responsible-use/chat) |
| {% data variables.copilot.copilot_chat_short %} in the IDE | Least restrictive organization | [AUTOTITLE](/copilot/responsible-use/chat) |
-| {% data variables.copilot.copilot_chat_short %} agent mode in the IDE | Least restrictive organization | [AUTOTITLE](/copilot/responsible-use/chat) |
+| {% data variables.product.prodname_copilot_short %} Agent Mode in IDE Chat | Least restrictive organization | [AUTOTITLE](/copilot/responsible-use/chat) |
| {% data variables.copilot.copilot_code-review_short %} | Least restrictive organization | [AUTOTITLE](/copilot/responsible-use/agents) |
| {% data variables.copilot.copilot_cloud_agent %} | Least restrictive organization | [AUTOTITLE](/copilot/responsible-use/agents) |
| {% data variables.product.prodname_spark_short %} | Least restrictive organization | [AUTOTITLE](/copilot/responsible-use/agents) |
diff --git a/content/copilot/reference/supported-surfaces-for-policies.md b/content/copilot/reference/supported-surfaces-for-policies.md
index 543a920ece30..9f55ccfe606a 100644
--- a/content/copilot/reference/supported-surfaces-for-policies.md
+++ b/content/copilot/reference/supported-surfaces-for-policies.md
@@ -22,12 +22,12 @@ A dedicated policy exists to enable or disable each supported feature or surface
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Editor preview features | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} |
| {% data variables.product.prodname_copilot_short %} can search the web | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} |
-| Enable custom models | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} |
+| Configure custom models | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} |
| Suggestions matching public code | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %}[^1] | {% octicon "check" aria-label="Supported" %}[^1] | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} |
| MCP servers in {% data variables.product.prodname_copilot_short %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} |
| Restrict MCP access to registry servers | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} |
| Content exclusion | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} |
-| Configure allowed models | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} |
+| Configure models | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} |
| {% data variables.copilot.copilot_memory %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "x" aria-label="Not supported" %} | {% octicon "check" aria-label="Supported" %} | {% octicon "x" aria-label="Not supported" %} |
{% endrowheaders %}
diff --git a/data/reusables/copilot/byok-add.md b/data/reusables/copilot/byok-add.md
index e4f5d61f9f88..bb84a2e53cbb 100644
--- a/data/reusables/copilot/byok-add.md
+++ b/data/reusables/copilot/byok-add.md
@@ -1,4 +1,3 @@
-1. Click the **Custom models** tab.
1. Above the list of API keys, click **Add API key**.
1. Under "Provider", select the LLM provider you want to use.
1. Under "Name", type a name for this key. This will be shown in the model picker.
diff --git a/src/content-pipelines/state/copilot-cli.sha b/src/content-pipelines/state/copilot-cli.sha
index 989108b35a74..6acc26c8081d 100644
--- a/src/content-pipelines/state/copilot-cli.sha
+++ b/src/content-pipelines/state/copilot-cli.sha
@@ -1 +1 @@
-fa27de3c246b786e858f573853d46277efb8333d
+db430d61ac5226363782e2e8480ec2a900a021bb