Two admin-managed settings now come only from the top policy tier, so lower tiers can't sneak values in.
What's wrong with this entry?
Two admin-controlled keys are now read only from the highest-precedence tier, so a lower tier can no longer supply them when the top tier omits them.
forceLoginOrgUUIDandallowedMcpServersnow follow the ruleavailableModelsalready used, reading from tier index 0 only- previously each was taken from the first tier that happened to define it
- the merge result gained a
presentfield withremote,mdmandfilebooleans reporting which tiers were found
forceLoginOrgUUID: u[0]?.forceLoginOrgUUID
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.221
New MCP policy-predicate telemetry for allowedMcpServers matching
Both mention allowed server