If you're rolling out Claude Desktop across your organization, you don't have to leave settings up to individual users. Claude Desktop now supports enterprise-grade configuration for Team and Enterprise plan admins, letting IT teams manage the app centrally through familiar tools like Microsoft Intune, Jamf Pro, and Group Policy.
Manage Claude Desktop Through Your MDM
On macOS, Claude Desktop reads its settings from the com.anthropic.claudefordesktop preference domain, which means you can deploy configuration profiles using any standard MDM tool — Jamf Pro, Kandji, Intune, or third-party profile editors like ProfileCreator and iMazing Profile Editor. This lets admins push settings to specific machines or user groups without needing anyone to touch a settings menu.
On Windows, configuration happens through Group Policy or Intune, with settings applied at either the machine level (HKLM) or user level (HKCU). If you set policies at both levels, machine-wide settings take priority, giving admins a reliable way to enforce standards across the fleet.
What You Can Control
Enterprise policies cover a practical range of controls, including:
- Auto-updates: Disable them if your MDM manages app versioning, or set how many hours (up to 72) before an update is force-applied.
- Organization login restrictions: Require users to log in under specific organization UUIDs, blocking unauthorized accounts from accessing Claude Desktop.
- Extensions and MCP servers: Enable or disable desktop extensions, the extension directory, and local MCP servers depending on your security posture.
- Cowork and Claude Code access: Turn these features on or off, and restrict which workspace folders can be mounted.
These settings are managed through registry keys on Windows (under HKLM:\SOFTWARE\Policies\Claude) or configuration profiles on macOS, giving IT teams a consistent way to enforce policy regardless of platform.
One Thing to Watch: The Allowlist Override
There's an important interaction worth knowing before you deploy: enterprise policy controls set at the machine level will override the in-app desktop extension allowlist. If your organization relies on that allowlist, make sure isDesktopExtensionEnabled and isDesktopExtensionDirectoryEnabled aren't set to "false," or the allowlist won't be able to populate its registry properly.
Why This Matters for IT Teams
Centralized configuration means fewer support tickets, more consistent security policies, and less risk of shadow IT creeping in through unmanaged extensions or MCP servers. For organizations already using MDM to manage other desktop apps, adding Claude Desktop to that workflow should feel familiar rather than like learning a new system.
If you're planning a broader rollout, it's worth pairing this configuration guide with Anthropic's platform-specific deployment articles for macOS and Windows to make sure installation and policy management are aligned from day one.
Source: Enterprise configuration for Claude Desktop – Claude Help Center