{"version":"2.1.293","anchor":"managed-settings-schema-additions","canonical_anchor":"managed-settings-schema-additions","heading":"Managed settings add a built-in browser group and a desktop sandbox option","tier":"use","area":"Managed Settings","scope":"org","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293\/e\/managed-settings-schema-additions","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293","markdown":"### Managed settings add a built-in browser group and a desktop sandbox option\n\nAdmin-managed settings gain a Built-in browser group, a desktop target for `requireFullVmSandbox`, and the `$schemaVersion` and `$schema` keys\n\n**What**\n\nManaged settings are settings an administrator sets for everyone in an organisation, which users cannot override. The list of what they accept has grown:\n\n- A new group of settings called Built-in browser.\n\n- `requireFullVmSandbox` now accepts `executionTarget: 'desktop'`. A sandbox is a walled-off environment that limits what commands can touch, and a full VM sandbox runs them inside a separate virtual machine.\n\n- Settings documents now recognise two descriptive keys, `$schemaVersion` and `$schema`, which say which version of the settings format a document follows.\n\n**Why**\n\nThese mostly affect administrators who manage the desktop app. They give policy files more to control and a standard way to say which settings format they are written for.\n\n- Area: Managed Settings\n- Tier: Use it now\n- Useful: 3\/5\n- Signal: 4\/5\n- Scope: org\n- Heads-up: no"}