Add the PUBLIC and/or SASUSERS groups to a new or existing AMO role that you want to restrict, and then set the AMO capabilities how you want them restricted. In this way, you'll have one group of users in the AMO:Advanced role, who are allowed to use AMO, and then all the other users (PUBLIC and SASUSERS) in the restricted role.
It is also important to note that the role metadata capabilities are version specific. In other words, you have to make sure that one of the versions of the AMO role metadata capabilities in metadata matches the version of AMO your end users are using. For example, if they are using AMO 7.1x, then you should have the AMO 7.1 role capabilities in metadata.
Casey
... View more