You'll notice
The disable-sign-in setting now applies before verification and fails closed.
The disableDeploymentModeChooser setting ("Disable Claude.ai sign-in") now has remotePolicy.hybrid.scope: 'excluded', applyUnverified: true, and failClosedValue: true, so it applies before verification completes, defaults to blocking if verification fails, and is excluded from hybrid scope.
Names in the bundledisableDeploymentModeChooser
Documented inclaude-docs/government/deploy-desktop/configure
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Added since
A small documentation edit on Connect Claude Desktop to Claude for Government touched a line naming disableDeploymentModeChooser after this was published.
Once `bootstrapUrl`, `disableDeploymentModeChooser`, or any other recognized key except the automatic update settings is present in the profile, the device is managed. The in-app configuration window becomes read-only, and locally authored…government/deploy-desktop/configure see the edit
Confirmed since
Anthropic's documentation has since written up disableDeploymentModeChooser, on Configuration reference.
| <span id="disabledeploymentmodechooser" />Disable Claude.ai sign-in<br />`disableDeploymentModeChooser` | `boolean` | MDM + Bootstrap<br />Added in 1.3834.0 | `false` | Users see only this provider at the login screen. The option to sign…third-party/claude-desktop/configuration see the edit
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agrees
Anthropic's documentation has since written up disableDeploymentModeChooser, on Configuration reference.