Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
5,689 changes: 2,848 additions & 2,841 deletions content/.metadata.json

Large diffs are not rendered by default.

9 changes: 9 additions & 0 deletions content/claude/government/changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,15 @@

> Release notes for Claude for Government

<Update label="2026.09.15.1">
* Fixed directory provisioning (SCIM) rejecting some of the user updates that Microsoft Entra ID sends by default.
* Changed what removing a tenant admin does for someone who is not yet in an organization: they can no longer request an emailed sign-in link and are placed by the sign-in routing rules at their next single sign-on, like any other member.
* Changed where Claude Desktop looks for Anthropic's published model catalog (model names, descriptions and effort options): starting with the first Claude Desktop release that supports the setting, the app asks your Claude for Government host for it instead of `downloads.claude.ai`, and keeps using the catalog it already has when the host has no copy.
* Improved how service updates are applied so that answers still being generated when an update begins have longer to finish.
* Added more checks of your identity provider's signing certificate when you save SAML single sign-on.
* Added the "Let members create skills" setting under Config > Integrations, on by default: turning it off stops members from creating or uploading skills of their own in Claude Desktop.
</Update>

<Update label="2026.09.11.1">
* (breaking) Changed the **Telemetry endpoint** setting on the Config page to check its host name more strictly when you save; an address that is already saved stays until the setting is next changed.
* Changed plugin uploads to ask for the Runs code confirmation when a plugin's `settings.json` sets anything other than its default agent or a `$schema` reference, such as a status line.
Expand Down
14 changes: 8 additions & 6 deletions content/claude/government/config/settings.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

# Available settings

> Reference for the product settings on the Config page in Claude for Government, including session timeout, maximum session length, organization instructions, telemetry, automatic updates, Claude Desktop banner, product availability, member-added plugins, and the tool and connector cards.
> Reference for the product settings on the Config page in Claude for Government, including session timeout, maximum session length, organization instructions, telemetry, automatic updates, Claude Desktop banner, product availability, member-added plugins, member skill creation, and the tool and connector cards.

> **Who this is for:** Tenant administrators and organization owners who set product behavior for the people they manage.

Expand Down Expand Up @@ -84,10 +84,6 @@ The content that Claude Desktop adds to the telemetry it sends to your collector

**Tool results** content is delivered only while **Telemetry traces** is on. Captured content goes only to your collector and is never sent to Anthropic. [Content capture](/docs/third-party/claude-desktop/telemetry#content-capture) in the Claude Desktop telemetry reference shows what each category adds.

<Note>
**Telemetry content capture** applies to Claude Desktop 1.15962.0 and later. Earlier versions ignore the setting.
</Note>

### Application event level (Claude Desktop)

How much of Claude Desktop's own event log goes to your collector, in addition to the usage telemetry from Chat, Cowork, and Code. These records arrive under the `claude-desktop` service name. The default, **Errors only**, sends failures such as a crash or a request that could not complete. **Off** sends no application events while usage telemetry is still sent, the two levels between **Errors only** and **Debug** add warnings and then routine events such as sign-in, updates, and settings changes, and **Debug** adds verbose diagnostic events for use while troubleshooting with support. At **Informational** and **Debug**, the application events also include each conversation's title. The title text is sent only when **Prompts** is selected in **Telemetry content capture**.
Expand Down Expand Up @@ -132,7 +128,7 @@ The system-use notification shown at sign-in is separate from this banner. It is

### Product availability

A group of separate switches that control which Claude products and features are available to members. Each switch appears as its own row: **Claude Desktop**, **Chat in Claude Desktop**, **Advanced file analysis in Chat**, **Cowork in Claude Desktop**, **Code in Claude Desktop**, **Claude Code**, and **Claude for Microsoft 365**. All are on by default.
A group of separate switches that control which Claude products and features are available to members. Each switch appears as its own row: **Claude Desktop**, **Chat in Claude Desktop**, **Advanced file analysis in Chat**, **Cowork in Claude Desktop**, **Code in Claude Desktop**, **Claude Code**, and **Claude for Microsoft 365**. These switches are on by default, except for **Claude Code** and **Claude for Microsoft 365**.

Turning off one of the three product switches (**Claude Desktop**, **Claude Code**, or **Claude for Microsoft 365**) makes Claude for Government stop serving that application your organization's configuration. From then on, Claude Desktop and the Claude for Microsoft 365 add-in are refused the organization's configuration when they request it, and Claude Code that is signed in to Claude for Government exits when it next starts (or right after sign-in) with a message that it couldn't load settings from the cloud gateway. Claude Code that is already running is not cut off and keeps working until it is next started. The product switches are not an access control on the Claude for Government service itself. What a member can reach is governed by their account, their [seat tier](/docs/government/org-admin/seat-tiers), and your agency's device and network management. To cut a member off at once, deactivate their account, after which they cannot sign in and requests from their existing sign-ins are refused (see [Deactivated users](/docs/government/org-admin/users#deactivated-users)). Turning off one of the other four switches removes that feature from Claude Desktop, as described below.

Expand All @@ -152,6 +148,12 @@ Two switches that control whether members can add plugins of their own in Claude

While a switch is off, Claude Desktop hides the corresponding controls from members. Marketplaces and plugins that members added earlier keep working, and members can still install plugins from those marketplaces.

### Let members create skills

Controls whether members can create or upload skills of their own in Claude Desktop. The **Let members create skills** switch is on by default.

While the switch is off, members cannot create new skills or upload skill files, and Claude does not offer to create or update skills in conversations. Skills that members already made, skills your organization provides, and built-in skills keep working.

### Allowed network hosts

A list of hostnames that tools in Claude Desktop may reach, for example to install packages or fetch web pages. This covers the tools Claude uses during Cowork tasks, web fetch in Chat, and the sandboxed shell commands of Code sessions on macOS and Linux. For how the list applies to Code sessions on each operating system, see [Code in Claude Desktop](/docs/government/security/security-and-data-handling#code-in-claude-desktop). The connection to Claude is always allowed and does not need to be listed. An empty list shows as **Claude connection only**. Use **Add package registries** to add npm, PyPI, GitHub, crates.io, and other common registries so that Claude can install libraries; hosts added this way appear together as a single **Package registries** pill with a count.
Expand Down
2 changes: 1 addition & 1 deletion content/claude/government/connectors/microsoft-365.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,7 +109,7 @@ On the [Config](/docs/government/org-admin/configuration) page, expand the **Mic
| **Azure cloud** | **Commercial** for most tenants, including Microsoft 365 GCC. Choose **US Government GCC-High** or **US Government DoD** only if your Microsoft tenant is in one of those clouds. |
| **Access** | The Microsoft Graph permissions the connector requests when a member signs in. The standard read-only permissions are already selected; add or remove permissions as needed. See [Choose which Microsoft 365 permissions to allow](#choose-which-microsoft-365-permissions-to-allow). |

Save the card. The connector reaches each member's Claude Desktop the next time it starts or the member signs in to Claude for Government. Members who already have Claude Desktop open are prompted to relaunch the next time the app checks for changes, which it does about every 30 minutes, and the connector appears after the relaunch.
Save the card. The connector reaches each member's Claude Desktop the next time it starts or the member signs in to Claude for Government. Members who already have Claude Desktop open are prompted to relaunch the next time the app checks for changes, which it does about every 10 minutes (about every 30 minutes on Claude Desktop versions earlier than 1.46388.1), and the connector appears after the relaunch.

## Choose which Microsoft 365 permissions to allow

Expand Down
4 changes: 2 additions & 2 deletions content/claude/government/deploy-desktop/configure.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ The address is the same for every device and user in your agency and carries no

When a user chooses **Sign in with your organization**, the app asks the Claude for Government host to start a sign-in, shows the pairing code it receives, and opens the host's sign-in page in the user's default browser. That page asks for the user's agency email address, then sends the browser to the sign-in service and on to your agency's identity provider. After signing in, the user acknowledges the system-use notification, confirms that the code shown in the browser matches the one in the app, and approves.

Claude for Government then issues the app a session for that user, which the app stores encrypted on the device. The app presents that session, and nothing from the profile, when it downloads the user's configuration from this address and when it sends chat traffic to the same host. It re-checks the configuration about every 30 minutes and at each launch.
Claude for Government then issues the app a session for that user, which the app stores encrypted on the device. The app presents that session, and nothing from the profile, when it downloads the user's configuration from this address and when it sends chat traffic to the same host. It re-checks the configuration about every 10 minutes (about every 30 minutes on Claude Desktop versions earlier than 1.46388.1) and at each launch.

A session lasts until the user has gone without using Claude for longer than the [Session idle timeout](/docs/government/config/settings#session-idle-timeout) your tenant administrators set, which is 24 hours unless they change it, or until it reaches the [Maximum session length](/docs/government/config/settings#maximum-session-length) if one is set. Using Claude extends the session, but leaving the app open on an idle, locked, or sleeping device does not. When a session has ended, the app keeps the user's configuration and asks them to sign in again, with a message and a **Sign in again** button while the app is open, or with the sign-in screen the next time it starts, and it reloads the configuration once they sign in. Claude Desktop 1.34493.0 or later shows these prompts. Earlier versions can report an ended session as a **Configuration sync issue**, so update them.

Expand Down Expand Up @@ -255,6 +255,6 @@ For anything else, the app writes its log to `~/Library/Logs/Claude-3p/main.log`

## Things to know

* Configuration changes made in this portal do not need to be pushed to devices. The app re-checks Claude for Government for changes about every 30 minutes and at each launch, and prompts users to relaunch when something changed.
* Configuration changes made in this portal do not need to be pushed to devices. The app re-checks Claude for Government for changes about every 10 minutes (about every 30 minutes on Claude Desktop versions earlier than 1.46388.1) and at each launch, and prompts users to relaunch when something changed.
* New and retired models appear in the model picker without any profile change or app update; model access is controlled through [seat tiers](/docs/government/org-admin/seat-tiers).
* The sign-in flow and what a user sees on the [Sessions](/docs/government/account/sessions) page after pairing a device are covered on that page.
2 changes: 1 addition & 1 deletion content/claude/government/org-admin/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -81,4 +81,4 @@ The navigation groups the pages into three sections.

Most changes you make in this portal take effect immediately. Changing a user's seat tier, updating a spend limit, or resetting a user's rate limits applies to their very next request. Group mapping changes trigger an immediate re-sync so you do not need to wait for a scheduled cycle.

Settings on the [Config](/docs/government/org-admin/configuration) page that govern the Claude applications themselves, such as the Claude Desktop banner and telemetry, reach each user's application the next time it starts or the user signs in. Claude Desktop also checks for changes about every 30 minutes while it is running and prompts the user to relaunch when something has changed.
Settings on the [Config](/docs/government/org-admin/configuration) page that govern the Claude applications themselves, such as the Claude Desktop banner and telemetry, reach each user's application the next time it starts or the user signs in. Claude Desktop also checks for changes about every 10 minutes (about every 30 minutes on Claude Desktop versions earlier than 1.46388.1) while it is running and prompts the user to relaunch when something has changed.
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,9 @@ On Windows, there is no operating-system-level sandbox for Code sessions. Shell

On every operating system, the application starts a Code session only in a folder that **Allowed workspace folders** permits when that setting is configured, and Claude's file reading and editing tools then work only inside the permitted folders. Administrators can also require a prompt on every shell command, in every permission mode, with the **Require approval for each command** sub-setting on the **Shell commands** card of the [Config](/docs/government/config/settings#tool-and-connector-cards) page.

Code sessions in Claude for Government run on the local workstation only, and the environment options for Windows Subsystem for Linux (WSL) and SSH remote hosts are not available. Commands that belong to Claude Code's terminal interface, such as `/sandbox`, are not part of Code sessions in the desktop application. See [how your configuration reaches Code sessions](/docs/third-party/claude-desktop/code). If your agency also deploys Claude Code's own managed settings to the same devices, those settings take precedence over the sandbox policy described above unless they opt in to merging, as that page explains.
Code sessions in Claude for Government run on the local workstation by default. SSH remote sessions are off unless your agency allows specific hosts in Claude Code's managed settings on the device; see [Interaction with Claude Code managed settings on the device](/docs/third-party/claude-desktop/ssh-remote-sessions#interaction-with-claude-code-managed-settings-on-the-device). On Windows, Code sessions inside a Windows Subsystem for Linux (WSL) distribution are not available.

Commands that belong to Claude Code's terminal interface, such as `/sandbox`, are not part of Code sessions in the desktop application. See [how your configuration reaches Code sessions](/docs/third-party/claude-desktop/code). If your agency also deploys Claude Code's own managed settings to the same devices, for example to allow SSH hosts, those settings take precedence over the sandbox policy described above unless they opt in to merging, as that page explains.

### Network egress, required domains, and proxies

Expand Down Expand Up @@ -146,7 +148,7 @@ In Claude for Government, Anthropic-bound error and usage telemetry is always di
</Accordion>

<Accordion title="What is logged for connector actions and outbound requests?">
Chat, Cowork, and Code sessions write a local audit log to the user's disk recording tool invocations, permission decisions, and file operations; that log never leaves the device. The desktop can also export OpenTelemetry events to a collector you specify: tool name, connector, outcome, duration, and approval status are sent. Prompt text, Claude's responses, and tool inputs and results are included only for the categories you select in the **Telemetry content capture** setting on the [Config](/docs/government/config/settings#telemetry-content-capture) page. See [Telemetry and egress](/docs/third-party/claude-desktop/telemetry) for what the export can include. Server-side, the [Compliance API](/docs/government/org-admin/compliance-api) records identity and configuration events but never tool calls or conversation content.
Chat and Cowork sessions write a local audit log to the user's disk recording tool invocations, permission decisions, and file operations; that log never leaves the device. The desktop can also export OpenTelemetry events to a collector you specify: tool name, connector, outcome, duration, and approval status are sent. Prompt text, Claude's responses, and tool inputs and results are included only for the categories you select in the **Telemetry content capture** setting on the [Config](/docs/government/config/settings#telemetry-content-capture) page. See [Telemetry and egress](/docs/third-party/claude-desktop/telemetry) for what the export can include. Server-side, the [Compliance API](/docs/government/org-admin/compliance-api) records identity and configuration events but never tool calls or conversation content.
</Accordion>
</AccordionGroup>

Expand Down
Loading
Loading