One read of Claude Documentation
5 pages moved out of 216 read.
government/org-admin/seat-tiers Changed · +1 / -0 lines
* Changing a tier's **Sort order** affects where newly provisioned users land, but it does not move anyone who already has a seat. * The spend limits are per user, not per tier. Ten users on a tier with a \$20 seven-day limit can together spend up to \$200 from the billing account over seven days. * Moving a user between tiers does not reset their usage counters. A user who has spent \$15 in the current 5-hour window carries that spend with them, and it is measured against the new tier's limit on their next request. +* Users choose among a tier's allowed models in the Claude Desktop model picker, described in [Models in Claude Desktop](/docs/government/desktop/models). For some models the picker also offers a **1M context window** entry, which Anthropic sets per model and which is not part of the tier.
government/config/settings Changed · +16 / -2 lines
### Block automatic updates ### Restart deadline for updates
# Available settings -> Reference for the product settings on the Config page in Claude for Government, including session timeout, maximum session length, telemetry, Claude Desktop banner, product availability, and the tool and connector cards. +> Reference for the product settings on the Config page in Claude for Government, including session timeout, maximum session length, telemetry, automatic updates, Claude Desktop banner, product availability, and the tool and connector cards. > **Who this is for:** Tenant administrators and organization owners who set product behavior for the people they manage.
Controls how long a member can stay signed in before they have to sign in again, even if they are active the whole time. The value must be a whole number of minutes from 60 to 525,600 (365 days), and by default there is no maximum. The maximum is an absolute limit on a session's lifetime that is independent of the session idle timeout, and a session ends as soon as it reaches either limit. This is a restriction, so each level can set or shorten the maximum but not lengthen it past what the level above allows, and the value that takes effect is always the shortest one in the chain. -A shorter maximum, or a new maximum where there was none before, also applies to members who are already signed in. Open sessions pick up the change while the member is active rather than instantly, so allow up to one session idle timeout period (24 hours by default) for it to reach everyone who is currently signed in. Any session that has not picked it up by then has already expired from inactivity. The maximum always counts from when the member originally signed in, so a session that is already older than the new maximum ends when it picks up the change and the member is prompted to sign in again. A longer maximum, or resetting the setting to remove a maximum set at your level, applies only at each member's next sign-in. Sessions that are already open keep the limit they already have, and raising or removing the maximum does not restore sessions that a shorter value has already shortened or ended. +A shorter maximum, or a new maximum where there was none before, also applies to members who are already signed in. Open sessions pick up the change while the member is active rather than instantly, so allow up to one session idle timeout period (24 hours by default) for it to reach everyone who is currently signed in. Any session that has not picked it up by then has already expired from inactivity. The maximum always counts from when the member originally signed in, so a session that is already older than the new maximum ends when it picks up the change and the member is prompted to sign in again. A longer maximum, or removing the maximum set at your level by clearing the value or resetting the setting, applies only at each member's next sign-in. Sessions that are already open keep the limit they already have, and raising or removing the maximum does not restore sessions that a shorter value has already shortened or ended. When a session ends because it reached the maximum, the member signs in again, just as they do after the idle timeout. Your identity provider decides whether that sign-in asks the member to authenticate again (for example with a password, a multi-factor prompt, or a PIV card) or passes them straight through, according to its own session and re-authentication policy. Examples of that policy are the sign-in frequency control in Microsoft Entra Conditional Access and authentication policies in Okta. If you want members to authenticate again when they sign back in after reaching the maximum, set your identity provider's re-authentication interval to no longer than the maximum session length.
Headers that Claude Desktop sends with every telemetry request, typically the credential your collector requires. Leave the setting empty if your collector does not require one. Because the value may contain a secret, it is never displayed after you save it; you see only that it is set. Write each header as `Name=value`, for example `Authorization=Bearer <token>`. To send more than one header, separate them with commas, as in `Authorization=Bearer <token>,X-Tenant=agency`. Because the comma is the separator, a header value itself cannot contain one. Spaces and `=` characters within a value are fine. + +### Block automatic updates + +Stops Claude Desktop from downloading and installing updates automatically. It is off by default, so Claude Desktop keeps itself updated. Turn it on only if your agency distributes Claude Desktop updates itself, and [lock](/docs/government/config/overview#locks) it if the levels below yours should not be able to turn updates back on. + +Claude Desktop applies this setting once a member has signed in and the app has loaded their configuration from Claude for Government. With that configuration loaded, the app follows this setting even when it is off, so a `disableAutoUpdates` value in the device's configuration profile does not stop a signed-in member's app from updating. When the app starts without a signed-in member, for example on a newly deployed device or when a member has to sign in again because their session expired, it follows the profile value instead, if one is set. To make sure devices never update themselves, turn this setting on and also have your IT administrators set `disableAutoUpdates` in the profile, as described under [Automatic updates](/docs/government/deploy-desktop/configure#automatic-updates) on the Connect Claude Desktop to Claude for Government page. + +### Restart deadline for updates + +How long a member can put off restarting Claude Desktop to install an update that the app has downloaded, as a whole number of hours from 1 to 72. When the deadline passes, the app restarts to install the update without waiting for the computer to be idle. Leave the value empty to allow 72 hours, after which the app restarts only once the computer is idle. While **Block automatic updates** is on, this setting has no effect, because the app downloads no updates. + +<Note> + Members who are running Claude Desktop when you change **Block automatic updates** or **Restart deadline for updates** may need to restart the app to pick up the change. +</Note> ### Claude Desktop banner
government/deploy-desktop/configure Changed · +20 / -13 lines
### Automatic updates
The configuration that the app downloads for a user includes the following settings, all of which you manage in this portal. -| What the app receives | Where it is set | -| --------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------- | -| Which of Chat, Cowork, and Code the user can open, and whether Advanced file analysis is on in Chat | [Product availability](/docs/government/config/settings#product-availability) on the Config page | -| The models the user can choose | The user's [seat tier](/docs/government/org-admin/seat-tiers) | -| Connectors, plugins, and the settings for the built-in tools | The [tool and connector cards](/docs/government/config/settings#tool-and-connector-cards) on the Config page | -| The hosts that tools may reach | [Allowed network hosts](/docs/government/config/settings#allowed-network-hosts) | -| The folders a user can choose as a workspace | [Allowed workspace folders](/docs/government/config/settings#allowed-workspace-folders) | -| The banner shown across the top of the app | [Claude Desktop banner](/docs/government/config/settings#claude-desktop-banner) | -| Where the app sends your agency's own telemetry, if you have set a collector | [Telemetry endpoint (Claude Desktop)](/docs/government/config/settings#telemetry-endpoint-claude-desktop) | +| What the app receives | Where it is set | +| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Which of Chat, Cowork, and Code the user can open, and whether Advanced file analysis is on in Chat | [Product availability](/docs/government/config/settings#product-availability) on the Config page | +| The models the user can choose | The user's [seat tier](/docs/government/org-admin/seat-tiers) | +| Connectors, plugins, and the settings for the built-in tools | The [tool and connector cards](/docs/government/config/settings#tool-and-connector-cards) on the Config page | +| The hosts that tools may reach | [Allowed network hosts](/docs/government/config/settings#allowed-network-hosts) | +| The folders a user can choose as a workspace | [Allowed workspace folders](/docs/government/config/settings#allowed-workspace-folders) | +| The banner shown across the top of the app | [Claude Desktop banner](/docs/government/config/settings#claude-desktop-banner) | +| Where the app sends your agency's own telemetry, if you have set a collector | [Telemetry endpoint (Claude Desktop)](/docs/government/config/settings#telemetry-endpoint-claude-desktop) | +| Whether automatic updates are blocked, and the restart deadline for an update the app has downloaded | [Block automatic updates](/docs/government/config/settings#block-automatic-updates) and [Restart deadline for updates](/docs/government/config/settings#restart-deadline-for-updates) on the Config page | ## Configure a single machine
| `bootstrapUrl` | `https://<claude-for-government-host>/gateway-api/user/bootstrap` | Required. Points the app at Claude for Government. | | `disableDeploymentModeChooser` | `"true"` | Recommended. Hides the claude.ai sign-in option so users can only sign in to Claude for Government. | -No other keys are needed; Claude for Government supplies everything else per user after sign-in. The profile contains no secrets, only a host. Keys documented for other Claude plans, such as `forceLoginOrgUUID` or `loginSsoOrgDomain`, apply only to claude.ai workspaces and are not used here. +No other keys are needed to connect the app; Claude for Government supplies everything else per user after sign-in. If your agency distributes Claude Desktop updates itself, [Automatic updates](#automatic-updates) below describes one more key to add. The profile contains no secrets, only a host. Keys documented for other Claude plans, such as `forceLoginOrgUUID` or `loginSsoOrgDomain`, apply only to claude.ai workspaces and are not used here. ### macOS
Most device management consoles, including Jamf and Intune, build the profile around these keys for you. For a complete `.mobileconfig` ready to upload, use the Export menu described in the single-machine path. -For a device-management rollout on macOS, also set `disableAutoUpdates` to the string `"true"` in the profile and push updates through your management system, so the in-app updater never prompts users for administrator rights. - ### Windows Claude Desktop reads string (`REG_SZ`) values by name under `HKLM\SOFTWARE\Policies\Claude`. Deliver them with Intune, Group Policy, or any tool that writes machine policy. The ADMX template from the Export menu makes both keys available in the policy editor. As a `.reg` file:
The app reads managed configuration at launch. After you change the profile on a device where the app is already running, have the user fully quit and reopen it. +### Automatic updates + +On macOS and Windows, Claude Desktop downloads and installs its own updates by default. If your agency distributes Claude Desktop updates itself, turn automatic updates off in both of the following places so that devices never update themselves. + +* **On the Config page.** Have a tenant administrator or organization owner turn on [Block automatic updates](/docs/government/config/settings#block-automatic-updates) and [lock](/docs/government/config/overview#locks) it, so that no level below theirs can turn updates back on. Claude Desktop applies this setting once a user has signed in and the app has loaded their configuration from Claude for Government. With that configuration loaded, the app follows this setting alone, whether it is on or off, and ignores the profile value. +* **In the profile.** Add `disableAutoUpdates` with the value `"true"` to the [macOS](#macos) and [Windows](#windows) profiles above. The app applies the profile value only when it starts without a signed-in user, for example on a newly deployed device or when a user opens the app and has to sign in again because their session expired. Without the Config page setting, the profile value does not stop signed-in devices from updating. + +Claude Desktop reads its update settings when it starts. If the app is already running on a device when you change the Config page setting or the profile, the change applies the next time the app starts. If you leave automatic updates on, [Restart deadline for updates](/docs/government/config/settings#restart-deadline-for-updates) on the Config page sets how long a user can put off the restart that installs a downloaded update. + ## Confirm it worked Run through these checks on a configured machine from either path.
* Configuration changes made in this portal do not need to be pushed to devices. The app re-checks Claude for Government for changes about every 30 minutes and at each launch, and prompts users to relaunch when something changed. * New and retired models appear in the model picker without any profile change or app update; model access is controlled through [seat tiers](/docs/government/org-admin/seat-tiers). -* Claude Desktop keeps itself updated by default. If your agency distributes software through its own pipeline, add `disableAutoUpdates` with the value `"true"` to the same profile and redistribute installers yourself. * The sign-in flow and what a user sees on the [Sessions](/docs/government/account/sessions) page after pairing a device are covered on that page.
government/desktop/models New page · 25 lines, new page
# Models in Claude Desktop ## Larger context window ## Model availability for administrators
A whole new page. There's nothing to diff it against, so here is what it says.
# Models in Claude Desktop > How the model picker in Claude Desktop works in Claude for Government, what the 1M context window entry does for long conversations that would otherwise be compacted at the standard 200K window, how to choose it, and what controls which models you see. > **Who this is for:** Anyone who uses Claude Desktop in Claude for Government. The last section is for administrators. The model picker shows which Claude model answers you and lets you switch to another. It sits at the bottom of the message box in Chat, Cowork, and Code. Which models it lists depends on the [seat tier](/docs/government/account/profile) your organization has assigned to you, so a colleague may see a different list. ## Larger context window Some models appear in the picker twice. In Chat and Cowork the second entry has **1M context window** under the model's name, and in Code it shows **1M** after the name. Both entries are the same model, and the difference is how much of a conversation Claude can keep in view at once, which is called the context window and is measured in tokens (a token is a short piece of text, roughly a word or part of one). The standard entry keeps up to about 200,000 tokens (200K) in view. The **1M context window** entry keeps up to about one million (1M), five times as much. When a long conversation or task gets close to filling the context window, Claude summarizes the earlier part to make room and carries on from the summary, which the app calls compacting. With the **1M context window** entry this happens much later, so long pieces of work keep their full detail for longer. Until a conversation outgrows the standard entry's window, the two entries behave the same and use the same amount of your [allowance](/docs/government/account/usage). Past that point the **1M context window** entry keeps sending Claude the whole conversation rather than a summary, so each further message uses more of your allowance and responses can take longer to start. To use the larger window, open the model picker and choose the model's entry marked **1M context window**, or **1M** in Code. The entry in use has a check mark next to it, and the model name in the message box reads the same for both entries in Chat and Cowork, so open the picker to check. If you have not picked a model before, the larger window may already be selected. The entry appears only for models where Claude for Government offers the larger window, so if no model in your picker has it, ask your organization's owner whether your seat tier can include a model that does. <Note> The **1M context window** entry appears in Claude Desktop 1.17377.1 and later. Claude Desktop 1.28929.0 and later also keep the entry you chose for new conversations and after a restart. Versions in between return to the standard entry each time, so choose the **1M context window** entry again when you start new work, or ask your IT administrator to update Claude Desktop. </Note> ## Model availability for administrators The models a member sees come from the **Allowed models** of their [seat tier](/docs/government/org-admin/seat-tiers). Whether a model also offers the **1M context window** entry is set by Anthropic for each model rather than in the admin portal. To see which models offer it, open the model picker in Claude Desktop, which shows the entries for your own seat tier. When you change a tier's allowed models, access changes straight away. A change of either kind, to a tier's allowed models or to which models offer the entry, shows in the picker's list the next time the member starts Claude Desktop. Usage on either entry counts against the same spend limits. A long conversation on the **1M context window** entry uses more only because each message carries more of the conversation.
government/deploy-desktop/windows-checklist Changed · +2 / -2 lines
## Configuration values -* **Two registry values.** Push the two values described under [Windows](/docs/government/deploy-desktop/configure#windows) as machine policy under `HKLM\SOFTWARE\Policies\Claude`: the required `bootstrapUrl` and the recommended `disableDeploymentModeChooser`. No other values are needed, because everything else reaches each user from Claude for Government at sign-in. +* **Two registry values.** Push the two values described under [Windows](/docs/government/deploy-desktop/configure#windows) as machine policy under `HKLM\SOFTWARE\Policies\Claude`: the required `bootstrapUrl` and the recommended `disableDeploymentModeChooser`. No other values are needed to connect the app, because everything else reaches each user from Claude for Government at sign-in. If your agency distributes Claude Desktop updates itself, also add the value described under [Automatic updates](/docs/government/deploy-desktop/configure#automatic-updates). * **Delivery order.** Deliver the values before the app wherever you can, so that users land directly on the Claude for Government sign-in screen, as [Order of deployment](/docs/government/deploy-desktop/configure#order-of-deployment) explains. ## Network access
* **Browser sign-in traffic.** Allow the browser on every device to reach the Claude for Government host, the Claude for Government sign-in service (a separate host that your Anthropic representative provides), and your agency's identity provider. Sign-in happens in each user's default browser, not in the app. * **`downloads.claude.ai`.** The app downloads the Cowork workspace and the Claude Code command-line tool from this host when a user starts a Cowork task, a Code session, or Advanced file analysis in Chat. The offline installer includes both, so devices installed with it need this host only for application updates while automatic updates are on. * **`www.claudeusercontent.com`.** This host serves the frame that displays artifact previews. -* **Update hosts.** While automatic updates are on, also allow the hosts listed under Auto-updates in [Required egress paths](/docs/third-party/claude-desktop/telemetry#required-egress-paths). The telemetry rows there never apply, because Claude for Government does not send telemetry to Anthropic. +* **Update hosts.** While [automatic updates](/docs/government/deploy-desktop/configure#automatic-updates) are on, also allow the hosts listed under Auto-updates in [Required egress paths](/docs/third-party/claude-desktop/telemetry#required-egress-paths). The telemetry rows there never apply, because Claude for Government does not send telemetry to Anthropic. * **Hosts your tools and connectors use.** Allow the hosts you add to [Allowed network hosts](/docs/government/config/settings#allowed-network-hosts) (such as package registries), the addresses of any connectors you configure on the Config page (including Microsoft 365 if you set up that connector), and your telemetry collector if you set one. * **Proxies.** The app and the Cowork workspace follow the operating system's proxy settings, including PAC files, as described under [Proxy support](/docs/third-party/claude-desktop/telemetry#proxy-support). If your proxy inspects TLS, validate sign-in, a chat, and a Cowork task on a pilot device before rollout.