Description of problem:
Please cover this in the release notes for EAP 6.2.0 GA.
When Red Hat JBoss EAP 6 is run with the Java Security Manager (JSM) enabled, the Role Based Access Control (RBAC) system is effectively disabled because in this situation all authenticated users are treated as SuperUsers. The only way to use RBAC currently is without the JSM enabled.
*** Bug 1035231 has been marked as a duplicate of this bug. ***