{"version":"2.1.281","anchor":"desktop-managed-config-schema-new-keys-disablebypasspermiss","canonical_anchor":"desktop-managed-config-schema-new-keys-disablebypasspermiss","heading":"Desktop managed config schema: new keys disableBypassPermissionsMode, blockReadsOutsideWorkingDirectories, egressProxyUrl, egressProxyPacUrl, usageMetricsEnabled; relaunchEnforcementHours removed","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/desktop-managed-config-schema-new-keys-disablebypasspermiss","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Desktop managed config schema: new keys disableBypassPermissionsMode, blockReadsOutsideWorkingDirectories, egressProxyUrl, egressProxyPacUrl, usageMetricsEnabled; relaunchEnforcementHours removed\n\nThe admin config schema adds five keys, including `disableBypassPermissionsMode`, and removes `relaunchEnforcementHours`\n\n**Unclear.** The finding does not say what `usageMetricsEnabled` controls or what replaces `relaunchEnforcementHours`.\n\n**What**\n\nThe admin configuration schema is the list of settings an organisation can enforce. Claude Code bundles this schema and shares it with the desktop app. It adds five keys:\n\n- `disableBypassPermissionsMode`: removes the bypass permissions mode from Code sessions and Cowork tasks, so Claude always follows the permission policy. Off by default. It fails closed, meaning the stricter behaviour applies when the value cannot be read.\n\n- `blockReadsOutsideWorkingDirectories`: available in the 3p and 1p scopes, and also fails closed.\n\n- `egressProxyUrl`: read only from MDM, the device-management software organisations use to push settings to machines.\n\n- `egressProxyPacUrl`: also read only from MDM.\n\n- `usageMetricsEnabled`: derived by the server and hidden.\n\nThe key `relaunchEnforcementHours` is removed. `coworkEgressAllowedHosts` now fails closed to an empty list (`[]`). The documentation reference to `requireFullVmSandbox` is corrected to `requireCoworkFullVmSandbox`.\n\n**Why**\n\nAdministrators get a way to take bypass permissions mode away entirely, and a way to set an outbound proxy through MDM. Any managed configuration that still sets `relaunchEnforcementHours` refers to a key the schema no longer contains."}