Copilot CLI now waits for managed settings before letting any MCP server start
GitHub·high signal
The 1.0.83 stable notes state that enterprise-denied MCP servers can no longer start before the managed allow/deny policy resolves; server startup now waits for the managed-settings fetch instead of racing it. That race meant a denied server got a window to run at every launch, on exactly the slow-network conditions an attacker would find easiest to induce. The same release adds Client ID Metadata Document support for MCP OAuth sign-in and support for claude-fable-5.1.