Hello,
By default localhost\Users group is added to OMEUsers. For Windows it means every Domain User has access to your OME server with users rights. It's known issue en.community.dell.com/.../19613576
You can delete them from OMEUsers but they still have access to the OME REST API and can view almost all the environment. Try this uri for checking it OMEServer:2607/.../CurrentUser
I deleted localhost\Users from the ACL of file OME.svc but I'm not sure is it correct solution?