{"version":"2.1.281","anchor":"gateway-config-warns-that-dictationenabled-has-no-route","canonical_anchor":"managed-config-allowoptionalclientauth-deprecated-in-a-new","heading":"Claude Desktop admin config schema: new keys, stricter validation and a November deprecation","tier":"notice","area":"Gateway","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/gateway-config-warns-that-dictationenabled-has-no-route","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Claude Desktop admin config schema: new keys, stricter validation and a November deprecation\n\nThe bundled Claude Desktop admin schema adds dictation, SSH, M365 and stream-timeout keys, validates forceLoginOrgUUID and deprecates allowOptionalClientAuth\n\n**What**\n\nClaude Code carries a copy of the configuration schema that administrators use to manage Claude Desktop. This schema is the list of admin keys, their allowed values and their descriptions, and it comes from a config package the two apps share. These are mostly Desktop settings. The version numbers below are the Claude Desktop versions each key needs.\n\nNew keys:\n\n- `inferenceStreamIdleTimeoutSec`: a gateway-only key from 1.44121.1, accepting 300 to 1800 seconds. It maps to Claude Code's `CLAUDE_STREAM_IDLE_TIMEOUT_MS` for sessions the app starts, and overrides the managed setting.\n\n- `dictationEnabled`: from 1.44121.1, marked public-undocumented. If a gateway-served config sets it to true and the gateway has no dictation route, a warning says the dictation control in Claude Desktop will fail and the key should be removed. Dictation no longer turns itself off when `allowOptionalClientAuth` is true.\n\n- `sshClientPath`: from 1.46388.1, behind the `sshRemoteSessions` beta key. It fails closed if the program is missing.\n\n- `continuousAccessEvaluation`: an option for the built-in Microsoft 365 connector, from 1.49585.0, either enabled or disabled, with enabled as the default. It requests Continuous Access Evaluation Graph tokens that last about 28 hours but can be revoked within minutes.\n\n- `disableMultiAccount`: \"Single account only\", marked public-undocumented and first-party only.\n\nChanged keys:\n\n- `forceLoginOrgUUID` is now validated. It must be a UUID or a JSON array of UUIDs, and an invalid value fails closed to `[]`. Before, it was a plain optional string.\n\n- `microsoftAuthBroker` gains a `required` value alongside `auto` and `disabled`. Desktop builds older than 1.49585.0 treat `required` as `disabled`.\n\n- `allowOptionalClientAuth` is deprecated in a new batch, `BATCH_2026_11`. Warnings start on 2026-11-03 and support ends on 2026-11-17. The replacement advice is to run Claude Desktop 1.49585.0 or later on every device, then remove the key.\n\n- The OTLP protocol hint (OTLP is the format for sending OpenTelemetry monitoring data) gets a long description.\n\n**Why**\n\nIf you administer Claude Desktop, check for `allowOptionalClientAuth` before the November dates, and check that `forceLoginOrgUUID` holds a valid UUID or array, because an invalid value now fails closed. Gateway admins get an explicit warning about a dictation setting that cannot work, instead of a silent failure.\n\n- Area: Gateway\n- Names: `dictationEnabled`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 3\/5"}