Hi All,
I currently have a business request to revoke access to exp manager ui where an user that currently has only authors and workflow-users permissions allowed, because though this UI this same user is allowed to see and access some links that they should not, such as "Penetration Tests, Universal Editor, tools, permissions and others:
A user can currently access this page just by hitting "Experience Manager", on AEM navigation (witch i'm also not able to hide and revoke access to).

I've tried to use several ACLs to control it, but could not achieve my goal.
Any toughts on how can i customize it?