You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release
What
allowManagedPermissionRulesOnly is a managed setting. Managed settings are pushed by an organisation's administrators, and this one makes them the only place permission rules can come from. When it is set, the settings now describe an extra condition for plugin marketplaces. A marketplace is a catalogue that plugins are installed from.
Marketplace source: a marketplace defined in settings keeps its plugins' allowed-tools only when every npm entry pins a registry on a bare package name. Allowed-tools is the list of tools a plugin may use without asking.
Registry field: an npm marketplace keeps plugin allowed-tools only when the policy entry and the marketplace registration both pin the same registry.
While the setting is on, marketplace sync also downloads the marketplace again every time. It no longer skips the download when the server reports that nothing has changed.
Why
Administrators who rely on npm-sourced plugin marketplaces can lose those plugins' tool grants unless they pin a registry. Check your managed configuration if plugins stop getting the tools they had before.