Use GitHub Copilot with desktop apps: setup, approvals and stop controls
GitHub Copilot computer use is a public preview for the local Copilot CLI and Copilot app on macOS and Windows. It is disabled by default. Enable it with /computer on or the app’s Computer Use settings, check /computer show, and review app access under Tool Permissions. Start with a disposable, low-impact task. Saved Always allow approvals affect later sessions, so choose them carefully and use /computer off when you no longer need computer use.
Start with the current requirements ↓1. Check the task, operating system and local policy
GitHub’s announcement and concept guide describe public preview support in the local Copilot CLI and Copilot app, on macOS and Windows. This guide does not claim Linux, cloud-agent or universal account rollout support.
Computer use can inspect accessible app content and screenshots, click controls, type or edit text, press keys, scroll, drag and move between applications. It is useful when the task genuinely requires a desktop application’s UI.
GitHub recommends a more structured tool when one can do the job: API, MCP, terminal, filesystem or a dedicated browser tool. Those interfaces are generally more predictable than screen coordinates and changing UI. For a browser-only workflow, use our MCP browser automation guide. Copilot Agent Skills covers reusable workflow instructions; Skills do not themselves grant desktop-app access.
2. Enable computer use and check what loaded
Follow the CLI instructions in an interactive Copilot CLI session:
/computer on
/computer show
on enables the bundled computer-use plugin and saves the preference. show reports whether the plugin, MCP server and associated skills are enabled. Read the actual status before asking for a desktop action.
In the Copilot app, open Settings → Computer Use → Enable Computer Use. The /computer commands are also available. Check Tool Permissions under Settings → Sessions; in the CLI use /permissions show.
On macOS, grant the required Accessibility and Screen Recording permissions to the relevant app when prompted. Use Check again if the app does not detect the permission change. These OS permissions are separate from Copilot’s app/tool approvals. The documented macOS permission steps are not Windows instructions.
If computer use stays unavailable, inspect /computer show, whether the computer-use plugin is enabled in /plugin, its MCP connection in /mcp, OS permissions and managed policy. Repeatedly enabling the preference will not override an organization restriction.
3. Understand Allow, Always allow and denial
Computer use follows Tool Permissions. When the current mode requires a prompt, GitHub documents these choices:
- Allow: approve the application for the current computer-use session.
- Always allow: save an application approval for later sessions on this computer.
- Decline / Cancel: deny that request.
Saved app approvals are shared between the Copilot app and CLI on the same computer. Always allow can remove future prompts for that app; do not assume every click, field edit or operation asks again. Explicit deny rules take precedence over saved or automatic approvals. App approval documentation.
Review the app identity and sensitivity before approving. Avoid persistent approval for email, finance, account settings or other high-impact applications unless you deliberately accept that scope. This caution is an operational recommendation grounded in GitHub’s permission and risk guidance, not a claim that those applications are technically blocked.
4. Try a bounded task, then check the actual result
Editorial example, not a hands-on result: open a disposable document containing synthetic text in an approved editor, then ask:
Inspect the open sample document and report its title and first sentence. Do not type, save, send, delete or switch to another app. Stop if the document is not the expected sample.
Review any requested application approval before proceeding. Compare the response with the visible document. If Copilot chooses the wrong window or control, stop before broadening the task. A completed tool call is not proof that the intended app state was reached.
For a later edit test, specify one reversible change and inspect the resulting text yourself. Keep real secrets and unrelated sensitive documents off-screen. These are suggested checks based on GitHub’s limitations, not additional official commands or tested guarantees.
5. Stop an action, disable use and remove saved approvals
The CLI guide documents Esc twice to stop an in-progress computer-use action. In the app, use Stop or Esc. Stopping does not undo an action that already happened; inspect the application afterward.
To disable computer use:
/computer off
/computer show
To remove a saved application approval, use Settings → Computer Use → Always allowed apps in the Copilot app. Removal affects saved approvals for both local surfaces. It does not revoke access already granted to a running session. Stop the current operation and end that session to revoke its existing app access; do not treat removing the saved entry as an emergency cancellation. Saved-approval lifecycle.
6. Organization policy can block local enablement
The enterprise managed settings reference defines features.computerUse. Setting it to false disables computer use and prevents the user from enabling it locally. true or omission permits the local choice; it does not automatically turn the feature on.
When access comes through an organization entitlement, the relevant Copilot CLI organization policy must also permit CLI use. Check both entitlement and managed settings before diagnosing a missing toggle as a plugin failure. A personal preference does not override the organization boundary.
7. Screen interaction needs close verification
The official risk guidance lists unreliable targeting and changing UI among the reasons to prefer structured tools. A task can select a wrong control or text field, repeat an action, encounter unexpected screen content, or behave differently when timing and window state change. Nonstandard app controls can also be difficult to interpret.
Screenshots and accessible content may expose sensitive information. A cross-app request can reach a more consequential application than the one you started with. Limit the visible data, name the allowed app and operation, review permission prompts, and keep high-impact actions under direct supervision. Approval is an access decision, not proof that the agent understood the content correctly.
If a structured API, MCP server or dedicated browser tool can complete the task, use that path first. Desktop computer use does not provide unrestricted control over the entire computer, and the documented permission model does not promise a prompt before every action.
FAQ
Where is GitHub Copilot computer use available?
The source-checked public preview covers the local Copilot CLI and Copilot app on macOS and Windows. This guide does not establish Linux or cloud-agent availability.
Is computer use enabled by default?
No. Enable it explicitly with /computer on or the app’s Computer Use setting, subject to organization policy and OS permissions.
Does Copilot ask before every desktop action?
No such guarantee is documented. Prompts follow Tool Permissions, and saved Always allow app approvals can apply in later sessions.
Are saved app approvals shared with the CLI?
Yes. The Copilot app and CLI share saved application approvals on the same computer. Explicit deny rules still take precedence.
Does deleting an Always allow entry revoke a running session?
No. It removes the saved approval for future use but does not revoke existing session access. Stop the operation and end the session to revoke that access.
Can an organization disable computer use?
Yes. Managed features.computerUse set to false prevents local enablement. True or omission allows the local choice without enabling it automatically.
Did AgentSkillsHub test a desktop workflow?
No. This guide is source-checked only. We did not enable computer use, approve an app or run a Copilot desktop workflow during this update.
Primary sources
Source-checked 2026-10-02. Published documentation, account availability and hands-on behavior are separate evidence. Examples and checklists here are editorial material.