Every new user group is automatically added to the default VDC, which grants access to all resources. To enforce custom resource restrictions through a new VDC, the user group must first be removed from the default VDC, otherwise the default permissions will override the custom VDC settings.