Guillaume, I just found a solution to the issue. In my case, I set the user to be read only at the datacenter level but did not propagate it down. Then I had to set up individual "no access permissions for all of the resource pools that don't belong to him. That seemed to fix my issue.
↧