Many of the settings have a default value of 'true', while the settings UI has a default value of 'false', meaning you need to toggle the setting on and then off again for it to actually be disabled.
I believe the correct setting should be disabled by default, given that it requires explicit action in the Tailscale admin UI to enable, and it isn't enabled by default in the stock client configuration.