the question is:
• I'm using AzureAD. And I want to restrict the default group from having access to execute shell. What bugs me was some cluster were prevented (disconnected when exec), and the other cluster didn't. What exactly defines this behavior?