One read of Claude Documentationclaude-docs-20261006T170710Z
1 pages moved out of 262 read.
Pages moved
1
significant first
Pages read
262
in this capture
Captured
17:07 UTC
Corpus hash
ab2cfee4b545
corpus-hash
What this read moved
1-1 of 1third-party/claude-desktop/installation Changed · +1 / -1 lines
from line 128
128128Run these checks on an affected device, or before rollout on a device that your policy applies to:
129129
130130* **Readiness check**: run the [readiness check](#check-device-readiness) on a device that has Virtual Machine Platform enabled. When the group lacks the right or is denied it, the **VM service logon right** line reads "SeServiceLogonRight not granted to S-1-5-83-0" or "SeDenyServiceLogonRight is set for S-1-5-83-0".
131* **Policy that sets the right**: in an elevated Command Prompt, run `gpresult /scope computer /h gpresult.html`, then open `gpresult.html` from the current folder. On an Arm64 device, run `%windir%\SysWOW64\gpresult.exe /scope computer /h gpresult.html` from a folder outside `%windir%\System32` instead. Microsoft's [gpresult reference](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/gpresult) says that on Arm64 versions of Windows, only the copy of `gpresult` in `SysWOW64` works with `/h`. Use the report to find which Group Policy Object sets **Log on as a service** for the device.
131* **Policy that sets the right**: in an elevated Command Prompt, run `gpresult /scope computer /h gpresult.html`, then open `gpresult.html` from the current folder. Use the report to find which Group Policy Object sets **Log on as a service** for the device.
132132* **Rights on the device**: in an elevated Command Prompt, run `secedit /export /cfg user-rights.inf /areas USER_RIGHTS`, then open `user-rights.inf` from the current folder. If a policy defines **Log on as a service**, the `SeServiceLogonRight` line must include `S-1-5-83-0`. If the file has a `SeDenyServiceLogonRight` line, that line must not include `S-1-5-83-0`.
133133
134134Group Policy overwrites a change made in a device's local security policy, so change the policy that sets the right: