Files
vscode/extensions/github-authentication
TylerLeonhardtandCopilot c46161fa18 chat: offer Microsoft sign-in when an Entra account links to GitHub (#338823)
* chat: offer Microsoft sign-in when an Entra account links to GitHub

Sign-in surfaces can now offer "Continue with Microsoft" only to users who can
actually use it: those with a Microsoft work or school account that GitHub links
to a GitHub account (for example an Enterprise Managed User).

The workbench checks this silently in the background, through two session
options that only the workbench can set (extensions' getSession requests have
every `_workbench*` option stripped):
- microsoft-authentication returns silent tokens for the broker's work and
  school accounts, including ones not yet approved for VS Code, without
  approving, caching, persisting or announcing anything.
- github-authentication exchanges those tokens for a `read:user` token, reads
  the linked account, and revokes the token when the host and build allow it.

`chat.microsoftAuthentication.enabled` becomes `auto` / `always` / `never`,
defaulting to `never` and rolled out through experimentation (legacy `true` and
`false` keep their meaning). The chat setup dialog and the first-run onboarding
screen follow the result without ever waiting for it.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chat: forget a found Microsoft link when accounts change

Adding or removing a Microsoft account now forgets a previously found link
and probes again, so signing out can no longer leave "Continue with
Microsoft" offered. A probe still running when the accounts change has its
answer discarded, since it answers for accounts that may be gone. Token
refreshes, which only report `changed`, are ignored so they do not mint
GitHub tokens.

Also stop promising unconditional revocation of the probe's GitHub token,
and describe the setting as covering sign-in surfaces, including the
welcome screen.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-09-29 21:13:00 -07:00
..
…

GitHub Authentication for Visual Studio Code

Notice: This extension is bundled with Visual Studio Code. It can be disabled but not uninstalled.

Features

This extension provides support for authenticating to GitHub. It registers the github Authentication Provider that can be leveraged by other extensions. This also provides the GitHub authentication used by Settings Sync.

GitHub Enterprise

For GitHub Enterprise Cloud (GHE.com) or GitHub Enterprise Server, set your instance URL:

{
	"github-enterprise.uri": "https://github.example.com"
}

GitHub.com accounts do not need this setting.