Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.283 ·

Models denied in the catch-all managed policy now apply to every policy

deniedModels in the catch-all managed.policies entry is now combined with each specific policy's list instead of being replaced by it

Use it now Improvements
JSON All of v2.1.283
Use it nowTier: how much it should matter to you
3Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
ImprovementsKind: in v2.1.283,
What probably matters to youSection of the release
What

In managed.policies, an entry with match: {} is the catch-all base that other entries are merged with. deniedModels, the list of models that are not allowed, is now combined when that merge happens: the base list and an entry's own list are joined and duplicates removed. Before, an entry that set its own deniedModels replaced the base list entirely.

This is how disabledMcpjsonServers, deniedMcpServers and blockedMarketplaces were already merged.

Why

An admin who denies a model in the catch-all policy can no longer have that silently undone by a more specific policy that sets its own deniedModels.

Read from
Names in the bundlemanaged.policiesdeniedModels
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhich program or command runs this policy merge is not confirmed.
Anthropic's release notes agreeAdded deniedModels managed setting to block specific models, even when availableModels allows them
The name it cites is new in this buildNew in this build: deniedModels

See this entry in the whole of v2.1.283 →

Feedback