What
Claude Code now checks the managed setting strictPluginOnlyCustomization more strictly. Managed settings are settings an organization's administrator deploys to control Claude Code on its computers.
- A value that is present but invalid is treated as
trueuntil it is fixed, so skills, agents, hooks and MCP servers load only from managed settings and plugins. - Entries in the list that Claude Code does not recognise produce a warning in the status output.
- A managed-settings payload whose value is not
true,false, a list or empty is rejected with an error saying the value must be true, false, or a list of surface names. - The settings validator reports the same problem with a message naming the key and asking you to fix the value.
Why
A typo in an organization's lockdown policy now either tightens the restrictions or gets flagged, instead of quietly leaving skills, agents, hooks and MCP servers open to user and project sources.
Names in the bundlestrictPluginOnlyCustomization
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed since
Anthropic's documentation has since written up strictPluginOnlyCustomization, on Set up Claude Code for your organization.
| [Customization lockdown](/docs/en/settings-reference#strictpluginonlycustomization) | Block skills, agents, hooks, and MCP servers from user and project sources, so they can only come from plugins or managed settings. Locking skills also…admin-setup see the edit
Added since
A small documentation edit on Code in Claude Desktop on 3P touched a line naming strictPluginOnlyCustomization after this was published.
| `allowedPluginMcpServers` | `strictPluginOnlyCustomization` set to `["mcp"]` together with an `allowedMcpServers` list holding your entries and `allowManagedMcpServersOnly`, whether or not `managedMcpServers` is set. MCP servers bundled …third-party/claude-desktop/code see the edit
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agrees
A small documentation edit on Code in Claude Desktop on 3P touched a line naming strictPluginOnlyCustomization after this was published.