How configuration propagates
When the app starts a Code session, it translates your Claude Desktop on 3P configuration keys into the equivalent Claude Code settings and passes them to the session. You configure one profile, and both tabs honor it. Each key reaches Claude Code through one of two mechanisms, and the distinction matters if you also deploy Claude Code’s own managed settings (see the next section).Always applied
These keys are passed directly to the Claude Code process as environment variables or launch options. They take effect on every Code session and cannot be overridden by user-level Claude Code settings or by a separately deployedmanaged-settings.json.
Applied as managed policy
These keys are translated into Claude Code managed settings and supplied to the session as policy. They take precedence over user and project settings, but they participate in Claude Code’s managed-settings precedence if you have also deployed a separate Claude Code policy.Interaction with Claude Code’s own managed settings
Claude Code can also be configured directly by deploying amanaged-settings.json file, an OS configuration profile for Claude Code, or (with Anthropic authentication) server-managed settings. If a device has any of these, Claude Code treats it as the administrator policy and, by default, ignores the policy values Claude Desktop supplies from the Applied as managed policy table. The Always applied keys are unaffected.
To have Claude Desktop’s restrictions apply on top of your Claude Code policy, set parentSettingsBehavior to "merge" in the Claude Code managed settings you deploy:
managed-settings.json
"merge", Claude Desktop’s policy values are layered under your Claude Code policy. Your values win any conflict, deny and allow lists are unioned, and Claude Desktop’s values are filtered so they can only tighten policy, never loosen it. See parentSettingsBehavior in the Claude Code settings reference. Requires Claude Code v2.1.133 or later, which ships with Claude Desktop on 3P.
In a third-party deployment there is no Anthropic authentication, so Claude Code’s server-managed settings tier is never present. If you have not separately deployed a Claude Code
managed-settings.json or OS profile, Claude Desktop’s policy applies automatically and you do not need to set parentSettingsBehavior.Further reading
Disabling the Code tab
To remove the Code tab entirely, setisClaudeCodeForDesktopEnabled to false in your Claude Desktop on 3P configuration. Users see only the Cowork tab.