What
The admin configuration schema is the list of settings an organisation can enforce. Claude Code bundles this schema and shares it with the desktop app. It adds five keys:
disableBypassPermissionsMode: removes the bypass permissions mode from Code sessions and Cowork tasks, so Claude always follows the permission policy. Off by default. It fails closed, meaning the stricter behaviour applies when the value cannot be read.blockReadsOutsideWorkingDirectories: available in the 3p and 1p scopes, and also fails closed.egressProxyUrl: read only from MDM, the device-management software organisations use to push settings to machines.egressProxyPacUrl: also read only from MDM.usageMetricsEnabled: derived by the server and hidden.
The key relaunchEnforcementHours is removed. coworkEgressAllowedHosts now fails closed to an empty list ([]). The documentation reference to requireFullVmSandbox is corrected to requireCoworkFullVmSandbox.
Why
Administrators get a way to take bypass permissions mode away entirely, and a way to set an outbound proxy through MDM. Any managed configuration that still sets relaunchEnforcementHours refers to a key the schema no longer contains.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
The finding does not say what `usageMetricsEnabled` controls or what replaces `relaunchEnforcementHours`.
Anthropic's release notes agree
Added Claude apps gateway support for newer Claude Desktop keys in desktop policy blocks, including blockReadsOutsideWorkingDirectories and…