Hi Dom,
Just a small suggestion to check as i had the same situation and worked through the below to get this fixed.
Can you check if you have added the correct users in the group ?
Also are the Users who you added are using the correct login credentials i.e Domain\Username ? As the SCOM server is located in another domain and the Desk where you are trying to access the web console is in another domain and they are using the credentials
of the desktop's domain to access the webconsole and not the SCOM servers domain.
Also can you check if the other role users are able to access the Web console or are they as well getting the same error ?