One read of Claude Documentationclaude-docs-20260930T160705Z
7 pages moved out of 258 read.
What this read moved
1-7 of 7government/account/sessions Changed · +4 / -4 lines
government/config/settings Changed · +39 / -7 lines
### Claude Code ### Bypass-permissions mode and Auto mode ### Microsoft 365 features ### File access rules (Microsoft 365)
government/deploy-claude-code/configure New page · 170 lines, new page
# Connect Claude Code to Claude for Government ## Before you begin ## The managed settings ### Before sign-in ### Optional: web proxy settings in the managed settings ## Deploy the settings ### macOS ### Windows ### Linux and Windows Subsystem for Linux ### A single machine set up by hand ## Sign in ## Confirm it worked ## Troubleshooting ## Things to know
A whole new page. There's nothing to diff it against, so here is what it says.
# Connect Claude Code to Claude for Government
> Deploy the managed settings that send the Claude Code command-line tool to Claude for Government sign-in, limit what it contacts before a user signs in, and verify the result on macOS, Windows, and Linux.
> **Who this is for:** IT administrators who install the Claude Code command-line tool on agency devices and connect it to Claude for Government.
In Claude for Government, Claude Code is in early access. To request access for your agency, contact your Anthropic representative.
A fresh install of Claude Code asks the user to sign in with a claude.ai or Claude Console account. To connect it to Claude for Government instead, each device needs a small managed settings file that sends users to your agency's Claude for Government sign-in. Everything else that governs Claude Code is set on the [Config](/docs/government/config/settings) page in this portal and delivered to Claude Code after the user signs in.
This page covers the device side: the managed settings, where to put them on each operating system, how a user signs in, and how to confirm a device is set up. Claude Code built into Claude Desktop (the **Code** tab) is configured through Claude Desktop instead, as [Connect Claude Desktop to Claude for Government](/docs/government/deploy-desktop/configure) describes.
## Before you begin
* **Claude Code is turned on for the organization.** A tenant administrator or organization owner turns on the **Claude Code** switch under [Product availability](/docs/government/config/settings#product-availability) on the **Config** page. It is off by default, and while it is off Claude Code exits right after the user signs in.
* **User accounts exist.** Claude Code signs users in to the same accounts as this portal. Each user needs a [routing rule](/docs/government/tenant-admin/identity-and-access) that covers them and a [seat tier](/docs/government/org-admin/seat-tiers) with at least one model enabled.
* **Claude Code is current.** This setup requires Claude Code 2.1.267 or later (`claude --version`).
* **Claude Desktop is current.** Update Claude Desktop to [the supported version](/docs/government/deploy-desktop/configure#before-you-begin) before turning on Claude Code for the terminal.
* **Devices can reach Claude for Government.** Claude Code must reach the gateway address over HTTPS on port 443, and the user's browser must reach the Claude for Government host, its sign-in service, and your agency's identity provider, the same hosts that [Claude Desktop sign-in](/docs/government/deploy-desktop/configure#before-you-begin) needs.
* **You can place a system-level file or policy.** The settings count only from a system-level location: a file in a system directory, a macOS configuration profile, or a machine-level Windows registry policy. Deliver them through your device management system or by hand with administrator rights.
## The managed settings
Claude Code reads device-level policy from what it calls managed settings. For Claude for Government they contain two keys that turn on gateway sign-in, an `env` block, and one key recommended on devices that also run Claude Desktop.
| Key | Value | Purpose |
| - | - | - |
| `forceLoginMethod` | `"gateway"` | Required. Replaces Claude Code's sign-in choices with a single **Cloud gateway** screen. |
| `forceLoginGatewayUrl` | The Claude for Government gateway address | Required. The address the **Cloud gateway** screen connects to. |
| `env` | The eight variables shown below | Required. Keeps Claude Code's telemetry to Anthropic and its pre-sign-in background connections off from the first launch, and sets its request headers, request body fields, and certificate checking as described below. |
| `parentSettingsBehavior` | `"merge"` | Recommended on devices that also run Claude Desktop, harmless elsewhere: Code sessions inside Claude Desktop then keep Claude Desktop's own restrictions alongside these settings, as [Interaction with Claude Code's own managed settings](/docs/third-party/claude-desktop/code#interaction-with-claude-code%E2%80%99s-own-managed-settings) describes. |
As a `managed-settings.json` file:
```json theme={null}
{
"forceLoginMethod": "gateway",
"forceLoginGatewayUrl": "https://<claude-for-government-gateway-address>",
"env": {
"CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC": "1",
"DISABLE_TELEMETRY": "1",
"DISABLE_ERROR_REPORTING": "1",
"CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL": "1",
"ANTHROPIC_CUSTOM_HEADERS": "",
"CLAUDE_CODE_EXTRA_BODY": "",
"NODE_TLS_REJECT_UNAUTHORIZED": "1",
"NODE_EXTRA_CA_CERTS": ""
},
"parentSettingsBehavior": "merge"
}
```
Your Anthropic representative provides the gateway address. Replace `<claude-for-government-gateway-address>` with it so the value is the full address starting with a single `https://`, including any path. The address is the same for every device and contains no credentials, so one file serves your whole fleet.
Claude Code honors the two sign-in keys only from a system-level location and ignores them in a user's own settings or a per-user registry policy.
### Before sign-in
Your organization's settings reach Claude Code only after a user has signed in. Until then, the first four variables keep Claude Code's release-notes download, update checks, automatic setup of the official plugin marketplace, and usage telemetry and error reporting to Anthropic off from the first launch. After sign-in the organization's settings keep them off.
The last four variables are required as shown. `ANTHROPIC_CUSTOM_HEADERS` and `CLAUDE_CODE_EXTRA_BODY` set to empty strings keep extra request headers and extra request body fields off. `NODE_TLS_REJECT_UNAUTHORIZED` set to `"1"` keeps certificate checking on. `NODE_EXTRA_CA_CERTS` names your agency's certificate authority bundle if your devices need one, and is otherwise left empty.
For what each variable controls, see [Environment variables](https://code.claude.com/docs/en/env-vars) in the Claude Code documentation.
### Optional: web proxy settings in the managed settings
If your devices use a web proxy that you manage, add `HTTPS_PROXY` and `HTTP_PROXY` (the proxy's address, for example `http://proxy.example.gov:8080`) and `NO_PROXY` (your bypass list, keeping `localhost`, `127.0.0.1`, and `::1`) to the same `env` block, each under both its uppercase and lowercase name. Claude Code then uses that proxy wherever the device connects from, in place of any other proxy setting on the device. If your devices connect directly, leave these variables out rather than setting them to empty strings, because an empty value switches off a proxy a user would otherwise use. On a device that also runs Claude Desktop, Claude Desktop applies the same proxy values to the sessions it runs, as [Interaction with Claude Code managed settings](/docs/third-party/claude-desktop/network-proxy#interaction-with-claude-code-managed-settings) describes.
## Deploy the settings
Deliver the settings through your device management system wherever you can, and before users start Claude Code for the first time, so that their first launch lands on the **Cloud gateway** screen. Claude Code reads managed settings when it starts; a user who had it open when the settings arrived quits and starts it again. Use one location per device. If a device receives more than one, Claude Code uses the macOS profile or machine-level Windows policy and ignores the file.
### macOS
Place the JSON above at `/Library/Application Support/ClaudeCode/managed-settings.json`, or deploy a configuration profile that sets the same top-level keys in the `com.anthropic.claudecode` managed preferences domain, with `env` as a dictionary of strings.
### Windows
Place the JSON above at `C:\Program Files\ClaudeCode\managed-settings.json`, or deliver it as machine policy: a string (`REG_SZ`) value named `Settings` under `HKLM\SOFTWARE\Policies\ClaudeCode` whose data is the whole JSON document on one line. As a `.reg` file:
```text theme={null}
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ClaudeCode]
; substitute the Claude for Government gateway address
"Settings"="{\"forceLoginMethod\":\"gateway\",\"forceLoginGatewayUrl\":\"https://<claude-for-government-gateway-address>\",\"env\":{\"CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC\":\"1\",\"DISABLE_TELEMETRY\":\"1\",\"DISABLE_ERROR_REPORTING\":\"1\",\"CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL\":\"1\",\"ANTHROPIC_CUSTOM_HEADERS\":\"\",\"CLAUDE_CODE_EXTRA_BODY\":\"\",\"NODE_TLS_REJECT_UNAUTHORIZED\":\"1\",\"NODE_EXTRA_CA_CERTS\":\"\"},\"parentSettingsBehavior\":\"merge\"}"
```
A value under `HKEY_CURRENT_USER` does not turn on gateway sign-in.
### Linux and Windows Subsystem for Linux
On Linux, place the JSON above at `/etc/claude-code/managed-settings.json` (root required).
Claude Code inside Windows Subsystem for Linux (WSL) reads that same path inside each distribution. To manage the setting from Windows instead, add `"wslInheritsWindowsSettings": true` to the machine-level Windows policy or file alongside the keys above; Claude Code inside WSL then reads the Windows settings first and needs no file inside the distribution.
### A single machine set up by hand
To try the setup before a fleet rollout, create the file at the path for the machine's operating system from an administrator account, then start Claude Code as an ordinary user.
## Sign in
With the settings in place, a user's first sign-in on a device goes as follows.
<Steps>
<Step title="Start Claude Code">
The user runs `claude` in a terminal. After the first-run theme choice, the **Cloud gateway** screen shows the gateway address, and the user presses **Enter** to connect.
</Step>
<Step title="Confirm the gateway certificate">
The first time each user connects from a device, Claude Code shows the first 16 characters of the gateway's TLS certificate fingerprint (SHA-256) and asks them to trust it. Publish the expected fingerprint to your users with the rollout (they compare it ignoring colons and letter case), and again when Anthropic renews the certificate, because users are asked again after a renewal. Your Anthropic representative provides it.
</Step>
<Step title="Finish sign-in in the browser">
Claude Code opens the Claude for Government sign-in page in the default browser and shows a one-time code in the terminal. The user signs in with your identity provider, checks that the code on the page matches the terminal, and approves.
</Step>
<Step title="Return to the terminal">
If the terminal shows **Signed in to Cloud gateway as** followed by the user's email address, the user confirms with **Yes, continue**. The terminal then shows **Connected to Cloud gateway**, and Claude Code downloads the organization's settings and restarts to apply them. If those settings include items Claude Code asks users to approve, such as a [Telemetry endpoint](/docs/government/config/settings#telemetry-endpoint), it shows a **Managed settings require approval** prompt the first time and whenever those settings change; **No** exits Claude Code. Unattended runs such as `claude -p` apply the settings without prompting.
</Step>
</Steps>
A sign-in lasts until the organization's [Session idle timeout](/docs/government/config/settings#session-idle-timeout) or [Maximum session length](/docs/government/config/settings#maximum-session-length) is reached, and at most 30 days. It also ends when the user's account is deactivated, or when the user signs in to Claude Code on more devices than Claude for Government allows at once (six), which ends the sign-in closest to expiring (see [Sessions](/docs/government/account/sessions#how-long-sessions-last)). Claude Code then asks the user to sign in again, which they do with `/login`.
## Confirm it worked
Run through these checks on one configured device before the wider rollout.
<Steps>
<Step title="Check the sign-in screen">
Start `claude` as a user who has not signed in. The only sign-in option is the **Cloud gateway** screen showing your gateway address. If Claude Code offers claude.ai or Claude Console sign-in instead, the managed settings did not reach it.
</Step>
<Step title="Check the background connections are off">
Before signing in, run `claude doctor`. On the standard installer it reports auto-updates as disabled by `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC`, which shows the `env` block reached Claude Code. (Homebrew, WinGet, and Linux package installs report updates as managed by the package manager instead.)
</Step>
<Step title="Check the setting sources">
After sign-in, run `/status` inside Claude Code. The API provider reads **Cloud gateway** with your gateway address, and **Setting sources** lists **Enterprise managed settings (remote)**.
</Step>
<Step title="Check that organization settings arrived">
Change one visible Claude Code setting on the [Config](/docs/government/config/settings#claude-code) page for a test organization, start a new Claude Code session as a member of it, and confirm the change took effect.
</Step>
</Steps>
## Troubleshooting
| What you see | Likely cause | What to do |
| - | - | - |
| Claude Code offers claude.ai and Claude Console sign-in instead of the **Cloud gateway** screen | The managed settings did not reach Claude Code: wrong path, a Windows value under `HKEY_CURRENT_USER` or with another name, a misspelled key, or Claude Code was already running | Check the location for the operating system above, then quit and restart Claude Code |
| The **Cloud gateway** screen says to contact your IT administrator | `forceLoginGatewayUrl` is missing or empty | Add the gateway address to the same managed settings and restart Claude Code |
| Claude Code reports that it could not resolve the gateway host, or another connection error for the address shown | The address in `forceLoginGatewayUrl` is not exactly the one your Anthropic representative provided, or the device cannot reach it | Correct the address, or restore the device's route to the gateway over HTTPS on port 443, then restart Claude Code |
| `Unable to connect to Anthropic services` at first start, before any sign-in screen | The sign-in keys did not reach Claude Code from a system-level location, or Claude Code is out of date | Update Claude Code, or check the settings location, then start it again |
| `claude doctor`, run before sign-in on the standard installer, reports auto-updates as enabled | The `env` block did not reach Claude Code | Compare the deployed settings with the sample above, then restart Claude Code |
| When it starts or right after sign-in, Claude Code exits with `Cloud gateway <address> refused managed settings for this account (403): Claude Code may not be enabled for your organization` | The **Claude Code** switch is off at a level that applies to the user (tenant, organization, or directory group) | Turn on the **Claude Code** switch under [Product availability](/docs/government/config/settings#product-availability) at that level (at the tenant level, **Reset to default** instead lets each organization's own switch decide), then have the user start Claude Code again. [**Compare config across levels**](/docs/government/config/overview#comparing-settings-across-levels) on the **Config** page shows which level turns it off for a user |
| When it starts or right after sign-in, Claude Code exits with `Couldn't load settings from Cloud gateway <address>` | Claude Code could not reach the gateway while loading the organization's settings | Confirm the device reaches the gateway over HTTPS on port 443, then have the user start Claude Code again. If it persists on a connected device, contact your Anthropic representative |
| In a session that was working, every request fails with a 403 error saying the product is not available for the organization | The **Claude Code** switch was turned off while Claude Code was running | Turn the switch back on at the level that turned it off; the next request then succeeds |
| Before the user has signed in, Claude Code exits with `Administrator policy requires a Cloud gateway sign-in on this machine` | A credential from earlier use is present: `ANTHROPIC_API_KEY` or `ANTHROPIC_AUTH_TOKEN` in the environment, an `apiKeyHelper` in the user's settings, or a saved Claude Console key | Remove the variable or the `apiKeyHelper` entry, or have the user run `claude auth logout`, then start `claude` and sign in |
| Claude Code says the gateway's TLS certificate changed and asks the user to run `/login` | The gateway certificate was renewed | Confirm the new fingerprint with your Anthropic representative, send it to users, and have them run `/login` and accept it |
## Things to know
* Only the gateway sign-in described on this page delivers the organization's settings to Claude Code.
* A claude.ai sign-in left on a device from earlier use is ignored once these settings are in place. A leftover `ANTHROPIC_API_KEY`, `ANTHROPIC_AUTH_TOKEN`, `apiKeyHelper`, or saved Claude Console key is not: until the user has signed in through the gateway, Claude Code stops and asks for its removal, as [Troubleshooting](#troubleshooting) describes.
* Where the Claude Code extension for VS Code is used, have users remove an earlier claude.ai sign-in with `claude auth logout` or the extension's **Claude Code: Logout** command before they sign in through the gateway, not after: both commands clear every credential Claude Code has stored, the gateway sign-in included.
* To take a device out of this setup, have its users sign out with `claude auth logout` before you remove the settings.
* After sign-in, the organization's settings turn off the Claude Code settings that run a helper command (`apiKeyHelper`, `proxyAuthHelper`, `awsAuthRefresh`, `awsCredentialExport`, `gcpAuthRefresh`, `otelHeadersHelper`), wherever it is set. If your devices reach the network through a proxy that needs a helper command to authenticate, raise this with your Anthropic representative before you deploy.
* With these settings Claude Code does not check for or install updates in the background. Distribute new versions through your software deployment tooling, or have users run `claude update` (standard installer) or their package manager.
* Code sessions inside Claude Desktop sign in through Claude Desktop, not through these settings, but on a device that has this file its `env` block applies to them too, and `parentSettingsBehavior` set to `"merge"` keeps Claude Desktop's own restrictions in force alongside it.
government/deploy-microsoft-365/configure New page · 154 lines, new page
# Deploy Claude for Microsoft 365 in Claude for Government ## Before you begin ## Download the manifest ## Deploy from the Microsoft 365 admin center ### Deploy from the Add-ins page ### Deploy from Integrated apps ## What users see ## Confirm the deployment
A whole new page. There's nothing to diff it against, so here is what it says.
# Deploy Claude for Microsoft 365 in Claude for Government
> Download the Claude for Microsoft 365 manifest from your Claude for Government host and deploy the add-in to users from the Microsoft 365 admin center.
> **Who this is for:** Microsoft 365 administrators who make the Claude for Microsoft 365 add-in available to agency users in Excel, Word, and PowerPoint.
In Claude for Government, Claude for Microsoft 365 is in early access. To request access for your agency, contact your Anthropic representative.
Claude for Microsoft 365 is an Office add-in that opens Claude in a pane beside the workbook, document, or presentation a user is editing. In Claude for Government, Office loads the add-in from your Claude for Government host, and the add-in sends its sign-in and chat traffic to that host. The host is written into the add-in's manifest, a small XML file that tells Office where to load the add-in from. You make the add-in available from the Microsoft 365 admin center by uploading the manifest and assigning it to users.
Microsoft 365 Government tenants can't use the public add-in store, so you deploy the manifest yourself (see Microsoft's [guidance for Office Add-ins on government clouds](https://learn.microsoft.com/en-us/office/dev/add-ins/publish/government-cloud-guidance)).
This page covers the add-in that runs inside Office. The [Microsoft 365 connector](/docs/government/connectors/microsoft-365), which lets Claude Desktop read your agency's Outlook, OneDrive, SharePoint, and Teams content, is a separate feature with its own setup.
## Before you begin
Confirm each of the following before you deploy the manifest.
* **Claude for Microsoft 365 is turned on for the organization.** Check the **Claude for Microsoft 365** switch under [Product availability](/docs/government/config/settings#product-availability). It is off by default. While it is off, users who sign in from the add-in are told that Claude for Microsoft 365 is not turned on for their organization.
* **User accounts exist.** The add-in signs users in to the same accounts as this portal. Each user needs a [routing rule](/docs/government/tenant-admin/identity-and-access) that covers them and a [seat tier](/docs/government/org-admin/seat-tiers) with at least one model enabled.
* **Office is a supported version.** The add-in needs the Office builds listed under supported versions for [Excel](/docs/office-agents/excel#supported-versions), [Word](/docs/office-agents/word#supported-versions), and [PowerPoint](/docs/office-agents/powerpoint#supported-versions).
* **Devices can reach your Claude for Government host.** Office on every device must reach your Claude for Government host over HTTPS (port 443). That host serves the add-in and carries its sign-in requests and chat traffic.
* **Devices can reach Microsoft's Office add-in library.** At startup the pane loads Microsoft's `office.js` library from one of these Microsoft hosts, chosen by the `?officecdn=` parameter you add when you [download the manifest](#download-the-manifest):
* no `?officecdn=` parameter: `appsforoffice.microsoft.com`
* `?officecdn=gcc`: `appsforoffice.gcc.cdn.office.net`
* `?officecdn=gcch`: `appsforoffice.gcch.cdn.office.net`
* `?officecdn=dod`: `appsforoffice.dod.cdn.office.net`
* **Your telemetry collector accepts the add-in's requests.** When a [**Telemetry endpoint**](/docs/government/config/settings#telemetry-endpoint) is set, the pane on each device sends traces and logs directly to that collector. The collector must be reachable from users' networks and must accept cross-origin requests from your Claude for Government host, which is the add-in's origin.
* **Your connectors accept the add-in's requests.** The pane on each device connects directly to every connector that applies to Claude for Microsoft 365 (see the [**Connectors** card](/docs/government/config/settings#tool-and-connector-cards)). Each connector must be reachable from users' networks and must accept cross-origin requests from your Claude for Government host, which is the add-in's origin.
* **Browsers can reach sign-in.** Sign-in happens in the user's default web browser, not in the pane. Browsers on each device must reach your Claude for Government host, the Claude for Government sign-in service (a separate host that your Anthropic representative provides), and your agency's identity provider. These are the same hosts [Claude Desktop sign-in](/docs/government/deploy-desktop/configure#before-you-begin) needs.
* **You can deploy add-ins in the Microsoft 365 admin center.** Users need the Microsoft 365 Apps versions and Exchange Online mailboxes listed in Microsoft's [requirements for Centralized Deployment](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/centralized-deployment-of-add-ins).
## Download the manifest
Your Claude for Government host serves the manifest at the fixed path `/office/manifest-fedstart.xml`. If you are unsure of your host, ask your Anthropic representative.
```text theme={null}
https://<claude-for-government-host>/office/manifest-fedstart.xml
```
If your tenant is in GCC High or DoD, add `?officecdn=gcch` or `?officecdn=dod` to the end of the address, and in GCC you can add `?officecdn=gcc`. The pane then loads Microsoft's `office.js` library from the Office CDN inside your cloud, as Microsoft's [guidance for Office Add-ins on government clouds](https://learn.microsoft.com/en-us/office/dev/add-ins/publish/government-cloud-guidance) recommends.
```text theme={null}
https://<claude-for-government-host>/office/manifest-fedstart.xml?officecdn=gcch
```
Choose the cloud before your first deployment. To change it later, remove the add-in in the admin center, download the file again with the new parameter, and deploy the new file.
Open the address in a browser and save the file. Open the saved file and check that the `SourceLocation` line names your Claude for Government host. If it doesn't, contact your Anthropic representative.
If your host answers to more than one name, pick one name and always download from it. The add-in's identity follows the host name in the address, so files downloaded under two names install as two separate add-ins.
The manifest installs Claude in Excel, Word, and PowerPoint and asks Office for permission to read and change the open document, which is how Claude edits the file a user is working in. The admin center and Office list the add-in as **Claude for Government**, and the ribbon button is labeled **Claude**.
## Deploy from the Microsoft 365 admin center
Microsoft doesn't offer its **Integrated apps** page in its [government clouds](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/test-and-deploy-microsoft-365-apps), so GCC, GCC High, and DoD tenants deploy from **Settings** > **Add-ins** (Microsoft's [Centralized Deployment](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/centralized-deployment-of-add-ins)). If your admin center shows **Integrated apps** instead, follow [Deploy from Integrated apps](#deploy-from-integrated-apps). In either case, upload the file you saved rather than entering its web address, so that Microsoft's service doesn't have to reach your Claude for Government host.
### Deploy from the Add-ins page
<Steps>
<Step title="Open the Microsoft 365 admin center">
Sign in to the Microsoft 365 admin center for your cloud with an account that can deploy add-ins.
</Step>
<Step title="Open the Add-ins page">
In the left pane, select **Show all**, then select **Settings** > **Add-ins**.
</Step>
<Step title="Start a custom deployment">
Select **Deploy Add-in**, then select **Next**.
</Step>
<Step title="Choose a custom upload">
Under **Deploy a custom add-in**, select **Upload custom apps**.
</Step>
<Step title="Upload the manifest">
Choose the option to upload a manifest file from your device, browse to the `manifest-fedstart.xml` file you saved, and select **Upload**.
</Step>
<Step title="Choose users">
On the **Configure add-in** page, choose who gets the add-in: **Everyone**, **Specific users/groups**, or **Just me**. Deploying to yourself or a small group first lets you confirm the add-in works on a representative device before a wider rollout.
</Step>
<Step title="Deploy">
Select **Deploy**.
</Step>
</Steps>
### Deploy from Integrated apps
<Steps>
<Step title="Open the Microsoft 365 admin center">
Sign in to the Microsoft 365 admin center with an account that can deploy add-ins.
</Step>
<Step title="Open Integrated apps">
Select **Settings** > **Integrated apps**.
</Step>
<Step title="Start a custom upload">
Select **Upload custom apps** and choose **Office Add-in** as the app type.
</Step>
<Step title="Upload the manifest">
Choose the option to upload the manifest file from your device and upload `manifest-fedstart.xml`.
</Step>
<Step title="Choose users">
Assign the add-in to everyone, specific users or groups, or just yourself. A small group first lets you confirm it works before a wider rollout.
</Step>
<Step title="Review the summary">
Select **Next** through the remaining pages and review the summary.
</Step>
<Step title="Finish the deployment">
Select **Finish deployment**.
</Step>
</Steps>
A deployment can take up to 24 hours to reach every assigned user, and users may need to restart the Office application before the add-in appears.
To change who has the add-in or to remove it later, see Microsoft's [Manage add-ins in the Microsoft 365 admin center](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-addins-in-the-admin-center).
## What users see
Once the deployment reaches a user, a **Claude** button appears on the **Home** tab of the ribbon in Excel, Word, and PowerPoint. The add-in is also listed under **Admin Managed** in Office's add-ins window. Selecting the button opens the Claude pane, which shows a **Log in** button.
When the user selects **Log in**, the pane shows a short code and opens the Claude for Government sign-in page in the user's default browser. If the browser doesn't open, the user selects **Continue in browser** under the code. The code is valid for 10 minutes, after which the pane offers **Start over**. In the browser, the user:
1. Enters their agency email address.
2. Signs in through your agency's identity provider.
3. Acknowledges the U.S. Government system-use notification.
4. Checks that the code shown matches the one in the pane, then selects **Approve**.
When the user returns to the pane it shows **You're signed in**, and selecting **Continue** opens Claude. On a user's first sign-in the pane shows a short welcome and a notice to acknowledge before the chat box appears. For what users can do once signed in, see the Claude for Microsoft 365 guides for [Excel](/docs/office-agents/excel), [Word](/docs/office-agents/word), and [PowerPoint](/docs/office-agents/powerpoint).
## Confirm the deployment
<Steps>
<Step title="Open the pane">
As a user you assigned the add-in to, open Excel, Word, or PowerPoint, select the **Claude** button on the **Home** tab of the ribbon, then select **Log in** in the pane.
</Step>
<Step title="Sign in">
Complete sign-in in the browser as described under [What users see](#what-users-see), select **Continue** if the pane shows it, and step through the welcome screens.
</Step>
<Step title="Ask Claude about the file">
Ask Claude a question about the open file and confirm it answers.
</Step>
</Steps>
government/security/security-and-data-handling Changed · +18 / -4 lines
## Claude Code command-line tool