GitHub now lets enterprise administrators enforce an Advanced Security configuration through organizations and repositories. A central policy can prevent both organization administrators and repository owners from changing protected settings.

Quick answer

ModeEffect
Don't enforceLocal customization remains possible.
Enforce for repository ownersRepositories cannot override it.
Enforce for repository and organization ownersEnterprise retains full control.

Closing an override layer

Earlier enforcement mainly stopped repository owners. An organization could still introduce divergence. The new level targets enterprises that must demonstrate consistent coverage.

Centralize without creating noise

Common configuration helps code, secret and dependency scanning, but repositories differ in language and criticality. Prepare several approved profiles instead of one policy that generates irrelevant alerts everywhere.

Manage exceptions

Technical enforcement does not replace an exception process. Record owner, reason, expiry and compensating control. Otherwise teams may move code into less visible spaces.

Roll out progressively

Measure non-compliant repositories, notify administrators and then enforce. Effective policy prevents silent disabling while preserving an auditable route for genuinely incompatible cases.