github / github/roadmap

OIDC EMU users can silently SSO into GitHub from the GH Copilot CLI without ever signing into GitHub [Public Preview]

Open
#1,285 0 comments 0 reactions 0 assignees View on GitHub
cloud Copilot Enterprise Copilot for Business Enterprise Public Preview
Dominant language
No language data
Stars
8.9k
Forks
1.8k
PR merge metrics
No merged PRs in 30d

Description

### Value Prop
Enterprise Managed Users on Windows can now sign in to the GitHub Copilot CLI using their existing Entra (Microsoft) account — no separate GitHub username, URL, or sign-in required. The CLI detects your Windows account and offers a one-tap sign-in experience that feels just like other Microsoft apps your team already uses. This removes a major onboarding hurdle for organizations adopting GitHub Copilot with Enterprise Managed Users.

### Expected Outcome
Getting developers productive on GitHub Copilot should be fast and frictionless, not a support event. By enabling silent single sign-on through Entra for OIDC-based EMU organizations, GitHub reduces the time it takes for new users to go from install to working — and lowers the burden on IT admins fielding sign-in questions during migrations and enablement. This feature lays the foundation for broader seamless access across more identity providers, enterprise configurations, and applications over time.

Contributor guide

Open the contributing guide

Research direction

The issue names no repository files, tests, or entry points; start by confirming the intended implementation scope for the GitHub Copilot CLI and Entra OIDC flow. Define the acceptance criteria for silent SSO on Windows and identify where validation should live before work begins.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
authentication, cli
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.