RE: Create a Read Only User
Hi!
The AccessMode has 3 options: Read/Write, Administrative and Non-Interactive. The Read/Delegated administrator/Support access mode are related to specific roles (From Microsoft Support, Partners or API Access).
Your approach is quite good. But I would add a new layer:
you have a root Business unit, and a Team associated with this by default. If you assign a security role to this team/BU, everyone that is added to the enviroment will inherit such Security role. What you should aim, is that EVERYONE added by default, have this new&customized security role. Therefore, if users are added by "mistake", then the impact is reduced as they have only read access.
Then, you create a new Business Unit as a child, and move required users to this particular BU, and assign the appropriate security roles (Basic User, Sales person, Customer Service representative) that provides Create/Update/Delete permissions.
Regards