Server-managed settings are in public beta and available for Claude for Teams and Claude for Enterprise customers. Features may evolve before general availability.
Requirements
To use server-managed settings, you need:- Claude for Teams or Claude for Enterprise plan
- Claude Code version 2.1.38 or later for Claude for Teams, or version 2.1.30 or later for Claude for Enterprise
- Network access to
api.anthropic.com
Choose between server-managed and endpoint-managed settings
Claude Code supports two approaches for centralized configuration. Server-managed settings deliver configuration from Anthropic’s servers. Endpoint-managed settings are deployed directly to devices through native OS policies (macOS managed preferences, Windows registry) or managed settings files.| Approach | Best for | Security model |
|---|---|---|
| Server-managed settings | Organizations without MDM, or users on unmanaged devices | Settings delivered from Anthropic’s servers at authentication time |
| Endpoint-managed settings | Organizations with MDM or endpoint management | Settings deployed to devices via MDM configuration profiles, registry policies, or managed settings files |
Configure server-managed settings
Open the admin console
In Claude.ai, navigate to Admin Settings > Claude Code > Managed settings.
Define your settings
Add your configuration as JSON. All settings available in Hooks use the same format as in To configure the auto mode classifier so it knows which repos, buckets, and domains your organization trusts:Because hooks execute shell commands, users see a security approval dialog before they’re applied. See Configure the auto mode classifier for how the
settings.json are supported, including hooks, environment variables, and managed-only settings like allowManagedPermissionRulesOnly.This example enforces a permission deny list, prevents users from bypassing permissions, and restricts permission rules to those defined in managed settings:settings.json.This example runs an audit script after every file edit across the organization:autoMode entries affect what the classifier blocks and important warnings about the allow and soft_deny fields.Verify settings delivery
To confirm that settings are being applied, ask a user to restart Claude Code. If the configuration includes settings that trigger the security approval dialog, the user sees a prompt describing the managed settings on startup. You can also verify that managed permission rules are active by having a user run/permissions to view their effective permission rules.
Access control
The following roles can manage server-managed settings:- Primary Owner
- Owner
Managed-only settings
Most settings keys work in any scope. A handful of keys are only read from managed settings and have no effect when placed in user or project settings files. See managed-only settings for the full list. Any setting not on that list can still be placed in managed settings and takes the highest precedence.Current limitations
Server-managed settings have the following limitations during the beta period:- Settings apply uniformly to all users in the organization. Per-group configurations are not yet supported.
- MCP server configurations cannot be distributed through server-managed settings.
Settings delivery
Settings precedence
Server-managed settings and endpoint-managed settings both occupy the highest tier in the Claude Code settings hierarchy. No other settings level can override them, including command line arguments. Within the managed tier, the first source that delivers a non-empty configuration wins. Server-managed settings are checked first, then endpoint-managed settings. Sources do not merge: if server-managed settings deliver any keys at all, endpoint-managed settings are ignored entirely. If server-managed settings deliver nothing, endpoint-managed settings apply. If you clear your server-managed configuration in the admin console with the intent of falling back to an endpoint-managed plist or registry policy, be aware that cached settings persist on client machines until the next successful fetch. Run/status to see which managed source is active.
Fetch and caching behavior
Claude Code fetches settings from Anthropic’s servers at startup and polls for updates hourly during active sessions. First launch without cached settings:- Claude Code fetches settings asynchronously
- If the fetch fails, Claude Code continues without managed settings
- There is a brief window before settings load where restrictions are not yet enforced
- Cached settings apply immediately at startup
- Claude Code fetches fresh settings in the background
- Cached settings persist through network failures
Security approval dialogs
Certain settings that could pose security risks require explicit user approval before being applied:- Shell command settings: settings that execute shell commands
- Custom environment variables: variables not in the known safe allowlist
- Hook configurations: any hook definition
In non-interactive mode with the
-p flag, Claude Code skips security dialogs and applies settings without user approval.Platform availability
Server-managed settings require a direct connection toapi.anthropic.com and are not available when using third-party model providers:
- Amazon Bedrock
- Google Vertex AI
- Microsoft Foundry
- Custom API endpoints via
ANTHROPIC_BASE_URLor LLM gateways
Audit logging
Audit log events for settings changes are available through the compliance API or audit log export. Contact your Anthropic account team for access. Audit events include the type of action performed, the account and device that performed the action, and references to the previous and new values.Security considerations
Server-managed settings provide centralized policy enforcement, but they operate as a client-side control. On unmanaged devices, users with admin or sudo access can modify the Claude Code binary, filesystem, or network configuration.| Scenario | Behavior |
|---|---|
| User edits the cached settings file | Tampered file applies at startup, but correct settings restore on the next server fetch |
| User deletes the cached settings file | First-launch behavior occurs: settings fetch asynchronously with a brief unenforced window |
| API is unavailable | Cached settings apply if available, otherwise managed settings are not enforced until the next successful fetch |
| User authenticates with a different organization | Settings are not delivered for accounts outside the managed organization |
User sets a non-default ANTHROPIC_BASE_URL | Server-managed settings are bypassed when using third-party API providers |
ConfigChange hooks to log modifications or block unauthorized changes before they take effect.
For stronger enforcement guarantees, use endpoint-managed settings on devices enrolled in an MDM solution.
See also
Related pages for managing Claude Code configuration:- Settings: complete configuration reference including all available settings
- Endpoint-managed settings: managed settings deployed to devices by IT
- Authentication: set up user access to Claude Code
- Security: security safeguards and best practices