1. Home
  2. Artificial Intelligence
  3. Claude Code Managed Settings

Claude Code Managed Settings

Early Release Content

This is an early release of this KB article and content is subject to change. Please refer back to this article occasionally for updated guidance. Managed settings have not been deployed yet, but will be in the coming weeks.

By default, Claude Code does not have file restrictions or permissions configured. This means that anything you have access to on your device or in network shares, Claude Code can also access. This can include sensitive data, including protected University Data accessible from your computer, or authentication keys and other credentials. To prevent accidental/unintentional data exposure or system access, ETS has configured default settings for Claude Code on managed UVM devices.

Disclaimer

These settings do not guarantee that Claude Code cannot gain access to sensitive data or files, they simply provide safeguards for well-known directories and files. To ensure Claude Code does not access unnecessary data, agents permissions should be configured to only provide access to required data sources and locations with a deny-by-default, allow-by-exception approach.

UVM Managed Settings

Across all managed devices with Claude Code installed, settings are configured to restrict access to certain behavior and file locations. This includes restricting permissions modes and the ability for Claude Code to automatically approve new permissions for itself. They also prevent overriding these settings with certain flags. These settings are deployed automatically through centralized device management tools on all UVM-managed devices.

Unmanaged Devices

If you run Claude Code on an unmanaged device, you can download the UVM managed settings from the UVM Software Portal under Claude Code Settings File. Instructions on where to place those files are also located in the portal.

Windows Settings

Windows devices receive specific settings to either deny access to select locations and files as well as denying certain commands, or to ask each time a certain file is read or command is run. This includes ClaudeCode installation and configuration directories and common credential and authentication key locations.

macOS Settings

macOS devices receive specific settings to either deny access to select locations and files as well as denying certain commands, or to ask each time a certain file is read or command is run. This includes Claude Code installation and configuration directories and common credential and authentication key locations.

macOS devices also receive settings that configure Claude Code to run in sandbox mode which prevents unintentional behavior and access further. More information about this sandbox mode can be found in the Claude Code Permissions & Sandboxing KB article.

Overriding Settings

Certain settings deployed to UVM devices can be overridden by exception. To request overriding settings, please submit a Footprint to the Tech Team detailing the setting you need to override and the behavior or access you’re looking for.

Important Note

Overriding settings should only be done when absolutely necessary. The overrides need to be configured in a certain way as well or Claude Code may fail to run, or the permissions may not persist.

Updated on August 31, 2026

Related Articles

Not the solution you were looking for?
Don’t worry we’re here to help!
Submit a Help Ticket