Who this is for: IT administrators who install Claude Desktop on agency devices and connect it to Claude for Government.A fresh install of Claude Desktop connects to claude.ai. To connect it to Claude for Government instead, each device needs one managed setting that tells the app where to reach Claude for Government. Once that setting is in place, everything else that governs the app (which products and features are available, model access, connectors, usage limits, the Claude Desktop banner) is controlled through the tenant and organization configuration pages in this portal and delivered to each user when they sign in.
Choose how to deploy
There are two ways to get Claude Desktop installed and connected to Claude for Government. They differ in who runs the installer, what rights that requires, and how the setting reaches the app.Before you begin
Confirm each of the following before you start either path.- User accounts exist. Claude Desktop signs users in to the same accounts as this portal. For each user, including your own test account, check with your tenant administrators that the user can sign in (a routing rule covers them) and has a seat tier with at least one model enabled.
- Devices can reach Claude for Government. Claude Desktop on every device must reach the Claude for Government host over HTTPS on port 443. That one host carries the app’s configuration and chat traffic.
- Browsers can reach sign-in. Sign-in happens in the user’s default web browser, not in the app. Browsers on each device must reach the Claude for Government host, its sign-in service (a separate host that your Anthropic representative provides), and your agency’s identity provider.
- The device meets Claude Desktop’s requirements. See the Claude Desktop system requirements for macOS and Windows device requirements. For a Windows fleet, work through the Windows fleet checklist, which covers the Virtual Machine Platform feature that Cowork needs along with the installer, policy, and network prerequisites.
- Windows devices used for Code have Git for Windows. On Windows, only the Code part of Claude Desktop needs Git for Windows. Chat and Cowork work without it. Install Git on the devices whose users will work in Code, or turn Code in Claude Desktop off under Product availability so that users are not prompted to install Git.
- Devices used for Code have the software your users’ work needs. Code runs its commands with the software installed on the device. Cowork and Advanced file analysis in Chat run theirs in the app’s own virtual machine, which includes Python.
- You can install the app. Installing by hand needs administrator rights on each device; see Configure a single machine for what that means on each platform. Installing through your device management system does not, because the management system installs with elevated rights. The macOS deployment guide and the Windows deployment guide cover where to download the installer and how to distribute it.
- The app is current. Deploy Claude Desktop 1.46388.1 or later.
The managed setting
The setting is calledbootstrapUrl, and its value is the Claude for Government host followed by the fixed path /gateway-api/user/bootstrap.
bootstrapUrl, and Claude for Government answers sign-in only on the host provided to your agency, so the app cannot sign in through such an alias.
With any alias of this kind, the app still offers Sign in with your organization, but sign-in fails as soon as the user chooses it; see Troubleshooting. The app supports routing its traffic through your network’s proxy server, as the Security and data handling page describes.
How the app uses the bootstrap address
The address is the same for every device and user in your agency and carries no credentials or user information, so the same profile is safe to push to your whole fleet. A request to the address without a signed-in session is refused. When a user chooses Sign in with your organization, the app asks the Claude for Government host to start a sign-in, shows the pairing code it receives, and opens the host’s sign-in page in the user’s default browser. That page asks for the user’s agency email address, then sends the browser to the sign-in service and on to your agency’s identity provider. After signing in, the user acknowledges the system-use notification, confirms that the code shown in the browser matches the one in the app, and approves. Claude for Government then issues the app a session for that user, which the app stores encrypted on the device. The app presents that session, and nothing from the profile, when it downloads the user’s configuration from this address and when it sends chat traffic to the same host. It re-checks the configuration about every 10 minutes (about every 30 minutes on Claude Desktop versions earlier than 1.46388.1) and at each launch. A session lasts until the user has gone without using Claude for longer than the Session idle timeout your tenant administrators set, which is 24 hours unless they change it, or until it reaches the Maximum session length if one is set. Using Claude extends the session, but leaving the app open on an idle, locked, or sleeping device does not. When a session has ended, the app keeps the user’s configuration and asks them to sign in again, with a message and a Sign in again button while the app is open, or with the sign-in screen the next time it starts, and it reloads the configuration once they sign in. Claude Desktop 1.34493.0 or later shows these prompts. Earlier versions can report an ended session as a Configuration sync issue, so update them. The configuration that the app downloads for a user includes the following settings, all of which you manage in this portal.Configure a single machine
Video: Pilot Claude Desktop on one machine (1 min 34 s). Narrated with an AI-generated voice, with on-screen captions.
Transcript
Transcript
Launch the app without signing in
Enable developer mode
Open the configuration window
Enter the bootstrap address
Apply and sign in
Allow the gateway address
Run the verification checklist
.mobileconfig profile for macOS, a .reg file for Windows, an ADMX template for Intune or Group Policy, and a Profile Manifest for Jamf. Before exporting, turn on Disable Claude.ai sign-in in the window’s Workspace section so the exported profile hides the claude.ai option on managed devices, and make sure Trust bootstrap-delivered settings in the Source section is off so the exported files do not carry it.
Deploy to your fleet
Video: Deploy to your fleet (1 min 31 s). Narrated with an AI-generated voice, with on-screen captions.
Transcript
Transcript
"true" or "false"; the Linux file uses native JSON types, as shown.
forceLoginOrgUUID or loginSsoOrgDomain, apply only to claude.ai workspaces and are not used here. Keys for a separate sign-in provider, such as bootstrapOidc and inferenceGatewayOidc in the Claude Desktop configuration reference, do not work with Claude for Government either. Leave them unset, because you cannot connect the app directly to your identity provider.
With Claude for Government, the name the app shows for the connection in the lower-left corner of its window and at the top of its account menu is not controlled through device management. Leave the deploymentDisplayName and deploymentDisplaySubtitle keys unset, because the app discards them once it downloads the user’s configuration after sign-in.
macOS
Claude Desktop reads managed preferences in thecom.anthropic.claudefordesktop domain. Deploy a configuration profile that sets the two keys in that domain as strings.
.mobileconfig ready to upload, use the Export menu described in the single-machine path.
Windows
Claude Desktop reads string (REG_SZ) values by name under HKLM\SOFTWARE\Policies\Claude. Deliver them with Intune, Group Policy, or any tool that writes machine policy. The ADMX template from the Export menu makes both keys available in the policy editor. As a .reg file:
.reg file from the Export menu targets HKEY_CURRENT_USER, which is correct for single-machine testing. For fleet deployment, deliver the values under HKEY_LOCAL_MACHINE as shown here.
After a user signs in, Claude for Government sends the app the address to use for chat traffic, which the app shows as Gateway base URL. When the registry values are under HKEY_LOCAL_MACHINE, the app accepts that address without asking the user. When they are under HKEY_CURRENT_USER, the app asks each user once to allow it, as described under Keys that require user consent. Have each user confirm that the address is on your Claude for Government host before they click Allow.
To approve the address in advance on a test device configured under HKEY_CURRENT_USER, first confirm that the bootstrapUrl value is on your Claude for Government host, then add "trustBootstrapDelivery"="true" next to it under the same key. That value tells the app to trust everything your Claude for Government host delivers without asking, including connectors and helper scripts that run on the device, which is the same trust the app extends when bootstrapUrl is under HKEY_LOCAL_MACHINE.
If you later move a test device’s values to HKEY_LOCAL_MACHINE, move all of them, because once any value exists under HKLM\SOFTWARE\Policies\Claude the app ignores HKEY_CURRENT_USER entirely.
Linux
Place a JSON file at/etc/claude-desktop/managed-settings.json containing the same keys at the top level.
main.log, and treats the device as managed but unreadable, so local settings are also disabled until the permissions are corrected and the app is relaunched.
Order of deployment
Deploy the configuration before the app wherever you can. A user whose device already has the profile opens Claude Desktop for the first time and lands directly on the Claude for Government sign-in screen, with no opportunity to sign in to claude.ai by mistake.bootstrapUrl, disableDeploymentModeChooser, or any other recognized key except the automatic update settings is present in the profile, the device is managed. The in-app configuration window becomes read-only, and locally authored settings, including a single-machine test configuration, are ignored in favor of the profile. A managed device uses only the connection in the profile: users cannot add, import, or switch to other configurations in that window. Users on a managed device can still turn on developer mode from the Help menu by choosing Troubleshooting, then Enable Developer Mode. The configuration window it reveals stays read-only, so they can view the connection there but not change it. If a group of users needs a different connection, scope a different profile to their devices or users in your management system, or leave those devices without a profile and set them up as described under Configure a single machine. Removing the profile returns the device to local control.Automatic updates
On macOS and Windows, Claude Desktop downloads and installs its own updates by default. If your agency distributes Claude Desktop updates itself, turn automatic updates off in both of the following places so that devices never update themselves.- On the Config page. Have a tenant administrator or organization owner turn on Block automatic updates and lock it, so that no level below theirs can turn updates back on. Claude Desktop applies this setting once a user has signed in and the app has loaded their configuration from Claude for Government. With that configuration loaded, the app follows this setting alone, whether it is on or off, and ignores the profile value.
- In the profile. Add
disableAutoUpdateswith the value"true"to the macOS and Windows profiles above. The app applies the profile value only when it starts without a signed-in user, for example on a newly deployed device or when a user opens the app and has to sign in again because their session expired. Without the Config page setting, the profile value does not stop signed-in devices from updating.
claude-desktop package adds Anthropic’s apt repository, so apt upgrade installs new versions from downloads.claude.ai, and so do unattended upgrades on devices that have them turned on. The Block automatic updates setting and the disableAutoUpdates key do not change these updates.
To keep Linux devices on the versions your agency distributes, add the line CLAUDE_DESKTOP_ADD_REPO=false to /etc/default/claude-desktop, and create that file if it does not exist. The package then does not add the repository when it installs or upgrades. On a device that already has the package, also delete /etc/apt/sources.list.d/claude-desktop.list.
Confirm it worked
Video: Verify a managed device and spot common failures (1 min 40 s). Narrated with an AI-generated voice, with on-screen captions.
Transcript
Transcript
Check the sign-in screen
disableDeploymentModeChooser set, it is the only option. If only the claude.ai sign-in appears, the configuration did not reach the app.Check that the device is managed
Generate a diagnostic report
Sign in and send a message
Confirm per-user settings arrived
Troubleshooting
~/Library/Logs/Claude-3p/main.log on macOS, %LOCALAPPDATA%\Claude-3p\logs\main.log on Windows, and ~/.config/Claude-3p/logs/main.log on Linux. The log records which configuration keys were read or dropped and why. The diagnostic report from the verification checklist produces a bundle, without conversation content, that you can send to your Anthropic representative.
Things to know
- Configuration changes made in this portal do not need to be pushed to devices. The app re-checks Claude for Government for changes about every 10 minutes (about every 30 minutes on Claude Desktop versions earlier than 1.46388.1) and at each launch, and prompts users to relaunch when a change needs a restart.
- New and retired models appear in the model picker without any profile change; model access is controlled through seat tiers. Models in Claude Desktop covers a model that needs a newer version of Claude Desktop.
- The sign-in flow and what a user sees on the Sessions page after pairing a device are covered on that page.