{"version":"2.1.283","anchor":"managed-drop-in-directory-detection-for-permission-writes","canonical_anchor":"managed-drop-in-directory-detection-for-permission-writes","heading":"Writes into managed settings drop-in folders are harder to slip past","tier":"notice","area":"Managed Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/managed-drop-in-directory-detection-for-permission-writes","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Writes into managed settings drop-in folders are harder to slip past\n\nClaude Code now locates managed settings drop-in folders when deciding whether a file write is protected, and assumes the worst when it cannot\n\n**What**\n\nManaged settings are settings an organisation's administrator enforces on Claude Code. A drop-in folder is a folder where extra managed settings files can be placed. When Claude Code checks whether a file write touches a protected location, it now also works out where these drop-in folders are.\n\n- If a drop-in folder cannot be located, any write to a `.json` file is treated as a possible drop-in file.\n\n- If a drop-in folder exists but cannot be opened, because access is denied or the path is not a folder, Claude Code compares paths by name instead.\n\nIn both cases Claude Code writes a line to its debug log.\n\n**Why**\n\nThis makes it harder for Claude to write into your organisation's managed policy folders without first asking you for permission.\n\n- Area: Managed Settings\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}