Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
One capture · claude-docs

One read of Claude Documentation

3 pages moved out of 223 read.

claude-docs-20260903T140704Z

Pages moved 3 significant first
Pages read 223 in this capture
Captured 14:07 UTC
Corpus hash b43a458ceb74 corpus-hash

What this read moved

1–3 of 3

government/changelog Changed · +7 / -0 lines

from line 2
22 
33> Release notes for Claude for Government
44 
5<Update label="2026.09.02.1">
6 * Fixed the Sessions page under Account showing every app sign-in as "Desktop app": each sign-in now names its app, or reads "Claude app" when the app is not known.
7 * (breaking) Changed the "Telemetry endpoint" setting under Config > Compliance and telemetry to refuse an address products can't use, such as one with a password or a `?` query; an address you already saved is checked only when you next change the setting.
8 * (breaking) Changed the "Telemetry resource attributes" setting under Config > Compliance and telemetry to refuse a value longer than 255 bytes, where a space or an accented letter counts as three or more bytes; values you already saved are checked only when you next change the setting.
9 * (breaking) Changed the "Advanced file analysis in Chat" setting under Config > Product availability to apply only on Claude Desktop 1.14271.0 or later; on 1.13576.0, the only earlier version with this feature, it is off until the app is updated.
10</Update>
11 
512<Update label="2026.08.28.1">
613 * Improved screen reader and keyboard support in the Admin Console: actions such as revoking a key or saving seats now announce their result, and keyboard focus returns to the control you used instead of being lost.
714 * Changed the main button on the sign-in pages to a dark button with a white label so it is easier to read; the page an emailed sign-in link opens now announces its result to screen readers.

government/config/settings Changed · +2 / -0 lines

from line 130
130130 
131131The **Web search** card controls whether Claude can search the web in Claude Desktop. It is off by default. When you turn it on you are shown a short description of how search works and asked to acknowledge it before the setting is saved. A **Require approval for each search** sub-setting sits below the toggle and becomes available once web search is on; it is on by default, and turning it off lets each member choose whether to approve every search or allow searches to run automatically.
132132 
133Once you turn web search on, each member's Claude Desktop picks it up the next time the app starts and shows it in the message box's **+** menu, under **Connectors**, as a **Web Search** switch that the member can turn off for themselves. If one member has no **Web Search** switch after restarting Claude Desktop while others do, select [**Compare config across levels**](/docs/government/config/overview#comparing-settings-across-levels) at the top of the Config page and type the member's name into the search box to check whether another level, such as a [directory group](/docs/government/config/overview#group-specific-settings), turns web search off for them. If every level shows web search on, check whether that member's network is blocking it, as described in the troubleshooting table in [Connect Claude Desktop to Claude for Government](/docs/government/deploy-desktop/configure#troubleshooting).
134 
133135The **Web fetch** card controls whether Claude can fetch web pages in Claude Desktop. It is on by default, and fetches are subject to the Allowed network hosts list above. A **Require approval for each fetch** sub-setting sits below the toggle. Turning it on asks the member to approve every page fetch before it runs; when it is off (the default), each member chooses whether to approve fetches or allow them automatically.
134136 
135137The **Shell commands** card controls whether Claude can run shell commands during tasks in Claude Desktop. It is on by default, and turning it off also turns off Advanced file analysis in Chat. A **Require approval for each command** sub-setting sits below the toggle. Turning it on asks the member to approve every shell command before it runs; when it is off (the default), each member chooses whether to approve commands or allow them automatically. Chat always asks before each command regardless of this setting.

government/deploy-desktop/configure Changed · +1 / -0 lines

from line 231
231231| An **Apply settings from your organization?** window appears after sign-in or at every launch, or the app quits when the user dismisses that window | The bootstrap address was entered in the app or set per user (for example under `HKEY_CURRENT_USER`), so the app asks each user to allow the gateway address that Claude for Government sends before it applies any of the organization's settings, and the user has not yet clicked **Allow**. Choosing **Quit**, pressing Esc, or closing the window quits the app, and it asks again on the next launch. | Have the user expand **Gateway base URL** in that window, confirm that the address is on your Claude for Government host, and click **Allow**. The window does not take focus when it opens, so have the user switch to the Claude app to find it. If the address is not on your host, check the bootstrap address configured on that device. To stop the prompt across a fleet, deliver the bootstrap address through machine-wide device management, as described under [Deploy to your fleet](#deploy-to-your-fleet). Versions earlier than 1.32352.0 that ask for this approval also show a **Configuration sync issue** banner that says "bootstrap response is missing required field(s): inferenceGatewayBaseUrl" for the same cause. Update the app to the latest version, then answer the prompt. |
232232| During sign-in, the browser shows a Microsoft page titled "You cannot access this right now", sometimes in one browser but not in another | Microsoft Entra ID shows this page when one of your agency's Conditional Access policies blocks the sign-in, for example a policy that limits which browsers, devices, or locations can sign in. The refusal happens before the sign-in reaches Claude for Government, so nothing in the app or in this portal changes it. | Ask your identity team to find the failed sign-in in the identity provider's sign-in logs. In the Microsoft Entra admin center, the sign-in event's **Conditional Access** tab names the policy that blocked it and the condition that was not met. Adjust the policy, or have the user sign in from a browser or device the policy allows (Claude Desktop opens sign-in in the computer's default browser). |
233233| The app shows **Your session has expired** or **You've been signed out** with a **Sign in again** button, or a device that was already set up opens to the sign-in screen | The user's Claude for Government session ended, most often because they had not used Claude for longer than your tenant's [Session idle timeout](/docs/government/config/settings#session-idle-timeout). A device left idle, locked, or asleep does not keep a session alive. A session also ends at the Maximum session length, or when the user or an administrator signs it out. | Have the user sign in again. The app keeps its configuration and reconnects. If people are asked to sign in more often than you intend, ask a tenant administrator to review **Session idle timeout** and **Maximum session length** on the [Config](/docs/government/tenant-admin/configuration) page. On Claude Desktop versions earlier than 1.34493.0 the same situation can appear as a **Configuration sync issue** banner instead, so update the app. |
234| Web search is on for your organization, but a user does not have it, and under **Customize**, then **Connectors**, **Web Search** shows as not connected and **Connect** fails, while chat works | A firewall or secure web gateway on that user's network path filters traffic by application. Claude Desktop connects to web search on your Claude for Government host over HTTPS, and such equipment can classify that connection as Model Context Protocol (MCP) traffic and block it even when the host itself is allowed. | Ask your network team to allow this traffic to your Claude for Government host for the affected users. The user's `main.log` records each failed attempt, including any block page the network returned. Then have the user select **Connect** next to **Web Search**, or restart the app. |
234235 
235236For anything else, the app writes its log to `~/Library/Logs/Claude-3p/main.log` on macOS, `%LOCALAPPDATA%\Claude-3p\logs\main.log` on Windows, and `~/.config/Claude-3p/logs/main.log` on Linux. The log records which configuration keys were read or dropped and why. The diagnostic report from the verification checklist produces a bundle, without conversation content, that you can send to your Anthropic representative.
236237