Skip to main content
  • Fixed members not being reactivated after they are re-enabled in your identity provider.
  • Changed SCIM provisioning to reject requests to deactivate an organization’s primary owner or a tenant’s last admin until ownership is transferred or another admin is added.
  • Changed SCIM provisioning to return an error that says what to do first when an identity provider deactivates or changes the email address of a member who is not yet linked to their directory entry.
  • Changed sign-in for accounts outside any organization that still held a Primary Owner role without being a tenant admin: they now sign in like any other member.
  • Changed sign-in: a network that starts sign-ins unusually fast is briefly told to try again.
  • Added a check of the Issuer against what your identity provider publishes when you save OIDC single sign-on.
  • Added a Test sign-in button to the Single sign-on settings on the tenant portal’s Identity and access page, so a tenant admin can check their own sign-in through their identity provider.
  • Added Sign out everywhere to each member’s row menu on the Users page, which ends all of that member’s sessions; the Compliance API records it as user.sessions_revoked.
  • Added the option to enforce settings whose values are hidden after saving, such as Telemetry headers, from the Admin Console.
  • Added the Claude Desktop home setting on the Config page, which sets Chat, Advanced file analysis, and Cowork in Claude Desktop together. It needs Claude Desktop 1.52386.0 or later.
  • Fixed directory provisioning (SCIM) rejecting some of the user updates that Microsoft Entra ID sends by default.
  • Changed what removing a tenant admin does for someone who is not yet in an organization: they can no longer request an emailed sign-in link and are placed by the sign-in routing rules at their next single sign-on, like any other member.
  • Changed where Claude Desktop looks for Anthropic’s published model catalog (model names, descriptions and effort options): starting with the first Claude Desktop release that supports the setting, the app asks your Claude for Government host for it instead of downloads.claude.ai, and keeps using the catalog it already has when the host has no copy.
  • Improved how service updates are applied so that answers still being generated when an update begins have longer to finish.
  • Added more checks of your identity provider’s signing certificate when you save SAML single sign-on.
  • Added the “Let members create skills” setting under Config > Integrations, on by default: turning it off stops members from creating or uploading skills of their own in Claude Desktop.
  • (breaking) Changed the Telemetry endpoint setting on the Config page to check its host name more strictly when you save; an address that is already saved stays until the setting is next changed.
  • Changed plugin uploads to ask for the Runs code confirmation when a plugin’s settings.json sets anything other than its default agent or a $schema reference, such as a status line.
  • Added tenant-level Compliance API keys: tenant administrators can create, list, and revoke them on the tenant portal’s Compliance API keys page under Settings, and a tenant-level key returns the events of every organization in the tenant together with tenant-level activity.
  • Improved accessibility in the Admin Console for people who use the operating system’s reduce motion setting or a screen reader.
  • Fixed importing Claude for Government Web chats into Claude Desktop failing with “This account doesn’t match your organization” for members of tenants that use directory provisioning (SCIM) now but did not on Claude for Government Web.
  • Added the “Let members add plugin marketplaces” and “Let members add their own plugins” settings under Config > Integrations at the tenant, organization, and group levels, both off by default: members on Claude Desktop 1.37937.0 or later can no longer add plugin marketplaces or their own plugins unless an admin turns these on, while marketplaces and plugins they already added keep working.
  • Changed the “Claude Code” and “Claude for Microsoft 365” switches under Config > Product availability so that turning a product off takes effect at once for members already signed in to it, instead of waiting for the product to re-read its settings; a member who signs in to Claude for Microsoft 365 while it is off is now told so on the sign-in page.
  • Added the “IPv6 in the sandbox” setting under Config > Access and models at the tenant, organization, and group levels, off by default: when it is on, Claude Desktop on macOS and Windows lets tools in its sandbox reach IPv6-only hosts during Cowork tasks, which takes effect once a Claude Desktop release that supports the setting is available.
  • Changed how the “Telemetry headers” setting and your connectors are delivered to Claude Desktop, ahead of Claude Desktop retiring the older formats: nothing changes in your settings or for members, and the notice about deprecated configuration fields that Claude Desktop 1.40609.0 or later can show no longer lists them.
  • Fixed web fetch failing in Claude Desktop’s Code sessions on networks that block api.anthropic.com: sessions no longer contact that host before fetching a page, which takes effect on Claude Desktop 1.37937.0 or later after a restart.
  • Fixed the sign-in page Claude Desktop opens in the browser showing an error instead of a field to enter the code when it is opened without a code or with an expired one.
  • Changed the limit on a member’s active app sign-ins from 3 shared across the Claude apps to 6 in each app: a new sign-in over the limit now signs out the one closest to expiring instead of the oldest.
  • Fixed Admin Console pages sometimes loading part light and part dark when your computer is set to dark mode, which made some text hard to read.
  • Improved the Admin Console for tenant admins who manage several organizations: every page shows which organization or tenant your changes apply to.
  • Fixed the Sessions page under Account showing every app sign-in as “Desktop app”: each sign-in now names its app, or reads “Claude app” when the app is not known.
  • (breaking) Changed the “Telemetry endpoint” setting under Config > Compliance and telemetry to refuse an address products can’t use, such as one with a password or a ? query; an address you already saved is checked only when you next change the setting.
  • (breaking) Changed the “Telemetry resource attributes” setting under Config > Compliance and telemetry to refuse a value longer than 255 bytes, where a space or an accented letter counts as three or more bytes; values you already saved are checked only when you next change the setting.
  • (breaking) Changed the “Advanced file analysis in Chat” setting under Config > Product availability to apply only on Claude Desktop 1.14271.0 or later; on 1.13576.0, the only earlier version with this feature, it is off until the app is updated.
  • Improved screen reader and keyboard support in the Admin Console: actions such as revoking a key or saving seats now announce their result, and keyboard focus returns to the control you used instead of being lost.
  • Changed the main button on the sign-in pages to a dark button with a white label so it is easier to read; the page an emailed sign-in link opens now announces its result to screen readers.
  • Added the “Restart deadline for configuration changes” setting under Config > Compliance and telemetry: it sets how long members can keep working after a settings change before Claude Desktop requires the restart that applies it, and takes effect on Claude Desktop 1.40609.0 or later.
  • Added a search box to the Config page that finds a setting by its name or description and takes you to it.
  • Fixed members on the default 24-hour “Session idle timeout” being signed out a day after signing in even when they had kept using Claude; the timeout now counts from a member’s last activity.
  • Improved screen reader support in the Admin Console: dialog options, repeated buttons, and usage meters are announced with distinct names, every page has its own browser title, and the setup wizards move keyboard focus to the new step’s heading when you change steps.
  • Changed the “Session idle timeout” setting so a tenant admin can set it as high as 96 hours (5,760 minutes), with larger values refused; a value above 24 hours saved earlier, which was ignored until this release, now applies, and the 24-hour default is unchanged.
  • Added connector management to the Group configuration pages: tenant admins and organization owners can add, override, or remove connectors for one directory group instead of only for the whole tenant or organization, and these changes appear as new activity types in the Compliance API feed.
  • Fixed adding a plugin or marketplace under Config > Integrations > Plugins failing with “Something went wrong” for all but the smallest zip files.
  • Added text alternatives to the charts on the Admin Console’s Analytics page: screen readers announce each chart by name and can read its plotted values as a table.
  • Fixed the “By product” table on the Analytics page counting Claude for Microsoft 365 activity as “Unknown”.
  • Fixed Admin Console pages cutting off setting names, values, and buttons at high browser zoom or in narrow windows; content now wraps instead of scrolling sideways.
  • Added two settings under Config > Compliance and telemetry: “Application event level (Claude Desktop)” chooses how much of Claude Desktop’s application event log goes to your telemetry collector, and “Telemetry resource attributes (Claude Desktop)” adds your own labels to every record.