After choosing “Add”, you will see the deny rule settings window. In this window there are the following fields:
By default all fields are empty and suggests that it's set to “all”, meaning that if you create a default deny rule and apply it to a user or a group, the firewall will allow all user's or group's communication that go through ICS CUBE. You can check what values are acceptible when you place the cursor on the field, or you can choose a value from the drop-down list containing the objects that are already known to ICS CUBE.
The “Allow traffic even if the user is disabled” checkbox means that even if user has been disabled or his quota has been exceeded, he will still has access to the resources that are set in the rule.