Enterprise managed users hit GA on GitHub Enterprise Cloud

GitHub has announced that enterprise managed users (EMU) is now generally available for customers on GitHub Enterprise Cloud (GHEC). The feature is aimed at organizations that want to centralize user account administration while keeping the collaboration capabilities of GitHub Enterprise.

For individual developers on GitHub, nothing changes — accounts remain tied to a public identity. For companies on GHEC, EMU is designed to make it easier to manage users and code entirely in the cloud.

Connect your identity provider for automated account lifecycle management

GIF showing the ability to connect an IdP group with GitHub using enterprise managed users

Administrators who already use an identity provider (IdP) to manage employee digital identities and control access to web applications can now connect that same IdP to GitHub. EMU supports the automation of account creation, updates, and suspension through existing workflows, using either AzureAD or Okta as the identity provider.

The integration also extends to group management: security groups defined in the IdP can be linked to GitHub teams, so user and group administration stays unified across platforms.

Work accounts with centralized audit controls

Enterprises often want the collaboration features of GitHub Enterprise but need stronger administrative oversight of employee accounts. With EMU, organizations can create GitHub accounts for employees and gain additional audit visibility, including login events, on top of the audit logging already available to all GHEC customers. Enterprise owners can view, export, or stream audit log events for every user in the enterprise.

EMU accounts are standardized and synced with each employee's corporate identity in the IdP. That means GitHub usernames, email addresses, and display names are sourced directly from the company's identity provider, making it clear who users are collaborating with.

Restrictions on public repositories

To help prevent accidental exposure of intellectual property, repositories within an EMU enterprise account cannot be made public. This adds an extra safeguard for organizations moving code to the cloud.

Availability and next steps

EMU is available today for GHEC customers using AzureAD or Okta as their identity provider. Organizations interested in adopting the feature can review the documentation or contact their GitHub account manager for more details.