{"version":"2.1.282","anchor":"managed-settings-malformed-strictpluginonlycustomization","canonical_anchor":"managed-settings-malformed-strictpluginonlycustomization","heading":"A malformed strictPluginOnlyCustomization policy now locks down instead of being ignored","tier":"notice","area":"Managed Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/managed-settings-malformed-strictpluginonlycustomization","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### A malformed strictPluginOnlyCustomization policy now locks down instead of being ignored\n\nAn invalid strictPluginOnlyCustomization value in managed settings is now treated as true, and bad payloads are rejected with an error\n\n**What**\n\nClaude Code now checks the managed setting `strictPluginOnlyCustomization` more strictly. Managed settings are settings an organization's administrator deploys to control Claude Code on its computers.\n\n- A value that is present but invalid is treated as `true` until it is fixed, so skills, agents, hooks and MCP servers load only from managed settings and plugins.\n\n- Entries in the list that Claude Code does not recognise produce a warning in the status output.\n\n- A managed-settings payload whose value is not `true`, `false`, a list or empty is rejected with an error saying the value must be true, false, or a list of surface names.\n\n- The settings validator reports the same problem with a message naming the key and asking you to fix the value.\n\n**Why**\n\nA typo in an organization's lockdown policy now either tightens the restrictions or gets flagged, instead of quietly leaving skills, agents, hooks and MCP servers open to user and project sources.\n\n- Area: Managed Settings\n- Names: `strictPluginOnlyCustomization`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}