{"version":"2.1.293","anchor":"managed-mcp-policy-only-transport-plus-egress-helper-chang","canonical_anchor":"managed-mcp-policy-only-transport-plus-egress-helper-chang","heading":"Managed MCP policy fails closed and gains a policy-only server entry","tier":"notice","area":"MCP","scope":"org","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293\/e\/managed-mcp-policy-only-transport-plus-egress-helper-chang","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293","markdown":"### Managed MCP policy fails closed and gains a policy-only server entry\n\nIf the managed MCP server list cannot be read, every MCP server is now blocked; entries can also be policy-only\n\n**Unclear.** What Claude Code does when the managed MCP server list fails to be read is not shown.\n\n**What**\n\nOrganisations can supply MCP servers to every user through `managedMcpServers` in managed settings. MCP servers are outside programs that give Claude extra tools. This release changes how that list is read and enforced.\n\n- If the list cannot be parsed, the fallback is now `MANAGED_MCP_SERVERS_PARSE_FAILED` instead of an empty list, and the tool policy becomes `{'*':'blocked'}`, which blocks every server.\n\n- Policy is now matched to a server by its identity, its url or name, and merges in settings from organisation plugins.\n\n- An entry can use the transport `MCP_TRANSPORT_POLICY_ONLY`. Such entries only carry policy. They are left out when Claude Code collects the network hosts it must reach, and an exported helper filters them out.\n\n- The helper that works out those hosts was replaced. Custom web search URLs now use `singleHostEgress` and GitHub hosts use `egressAddress`.\n\n**Why**\n\nA broken managed server list now locks MCP servers down instead of leaving them unrestricted. If MCP tools suddenly stop working in a managed setup, check that the managed settings file is valid.\n\n- Area: MCP\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 2\/5\n- Scope: org\n- Heads-up: yes"}