Active Directory User Permissions

Hello, I have a MS Active Directory integration and i choose “Allow members of Clusters, Projects, plus Authorized Users and Organizations” option.

I can login with only this option. So i don’t give any permission to ad user but this user can see cluster management section and cluster configs including vcenter passwords. After loggining i changed users global permission to user-base from standart-user but nothing changed. Is there any way to block ad users from seeing cluster management?

A local user-base user doesn’t see anything in the Rancher. not the cluster and cluster management.

Thanks