Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20260926T040705Z

2 pages moved out of 255 read.

Pages moved 2 significant first
Pages read 255 in this capture
Captured 04:07 UTC
Corpus hash 74e76b1cc86c corpus-hash

What this read moved

1-2 of 2

government/tenant-admin/identity-and-access Changed · +7 / -3 lines

from line 18
1818 
1919## Domains
2020 
21Claude for Government routes users to your tenant by the domain of their email address, so at least one domain must be registered before anyone can sign in. The **Domains** section lists every domain registered to your tenant, along with whether it is verified and whether it was registered by Anthropic or by you.
21Claude for Government routes users to your tenant by the domain of their email address, so at least one domain must be registered before anyone can sign in. The **Domains** section lists every domain registered to your tenant, along with whether it is verified and whether it was registered by Anthropic or by you. Your tenant can have more than one domain. However many domains are registered here, your tenant has one set of [admin portals](/docs/government/tenant-admin/overview#tenants-and-organizations), and the [routing rules](#routing-rules) decide which organization each person joins.
2222 
2323Domains that Anthropic registered on your behalf during onboarding are already verified. To add one yourself, enter the domain in the **Claim a domain** field and click **Claim**. You will be shown a DNS TXT record to publish on that domain; once the record is live, click **Verify now** and the domain becomes active.
2424 
from line 26
2626 
2727## Single sign-on
2828 
29Every user signs in through your agency's identity provider (for example, Microsoft Entra, Okta, or ADFS). You register Claude for Government as an application in your identity provider, then enter your provider's connection details here. Once connected, sign-ins are redirected to your provider. A second sign-in from the same browser within a few minutes, such as connecting Claude Desktop right after signing in on the web, may not be redirected again.
29Every user signs in through your agency's identity provider (for example, Microsoft Entra, Okta, or ADFS). Your identity provider needs to support SAML 2.0 or OpenID Connect (OIDC).
3030 
31You register Claude for Government as an application in your identity provider, then enter your provider's connection details here. Once connected, sign-ins are redirected to your provider. A second sign-in from the same browser within a few minutes, such as connecting Claude Desktop right after signing in on the web, may not be redirected again.
32 
3133<Note>
3234 You need at least one verified domain before you can connect single sign-on. Until then, the Connect button is unavailable and a banner prompts you to verify a domain first. If single sign-on was already connected before your last domain was removed, the existing connection stays editable.
3335</Note>
from line 75
7375 
7476## SCIM provisioning
7577 
76SCIM is the standard protocol identity providers use to push users and groups to a connected service automatically, so that accounts are created, updated, and deactivated in step with your agency's directory. Connecting SCIM is optional; without it, users are created the first time they sign in.
78SCIM is the standard protocol identity providers use to push users and groups to a connected service automatically, so that accounts are created, updated, and deactivated in step with your agency's directory. Connecting SCIM is optional; without it, users are created the first time they sign in. With SCIM connected, a person your directory has never sent still gets an account the first time they sign in, if a [sign-in rule](#sign-in-rules) covers them.
79 
80[Provisioning rules](#provisioning-rules-scim), [group mappings](/docs/government/org-admin/provisioning), and [group-specific settings](/docs/government/config/overview#group-specific-settings) need SCIM, because they act on the [directory groups](#directory-groups) your identity provider pushes. Model access and usage limits come from each person's [seat tier](/docs/government/org-admin/seat-tiers), which an organization owner can assign on the [Users](/docs/government/org-admin/users) page without SCIM.
7781 
7882<Note>
7983 You need at least one verified domain before you can generate a SCIM token. Until then, **Generate token** is unavailable and a banner prompts you to verify a domain first.

government/tenant-admin/setup-wizard Changed · +1 / -1 lines

from line 42
4242 
4343## Step 4: Provisioning (optional)
4444 
45This step is optional. If your identity provider supports SCIM, which is a standard way for directory systems to push users and group memberships into other applications, you can connect it here so that accounts are created automatically rather than at first sign-in.
45This step is optional. If your identity provider supports SCIM, which is a standard way for directory systems to push users and group memberships into other applications, you can connect it here so that accounts are created automatically.
4646 
4747Like single sign-on, this step is unavailable until you have verified at least one domain on Step 2.
4848 
Feedback