Adding an internal user to the Extra rights/ Technical features group causes some security issues, even the lower level users can access the settings page.
Is there any specific reason, why the odoo by default has been adding new users to this group?
base/security/base_groups.xml (odoo16)
Here adding the technical feature group the internal user group