First, whenever you make a change to the permissions, be sure you flush permissions *and* sessions and test from a browser where you're not logged in to the Manager (even in another window).
One way to protect the resources in a context, is to add them to a resource group *and* connect that resource group to a user group that the (anonymous) user is not a member of with a Resource Group Access ACL entry.
Another way is to create a Context Access ACL entry for the Administrator user group with a Context of 'auth'. That protects the whole context as long as the (anonymous) user group does not have a Context Access ACL entry with that context.
An even simpler way to protect the resources in the front end is to add a tag for a snippet with this code to all templates:
if (! $modx->user->get('userame') === '(anonymous)') {
return '';
}
$modx->sendUnauthorizedPage();
Unlike the first two methods, this won't prevent the pages from showing up in menus or getResources displays. It will just forward the users to the page designated in the unauthorized_page System Setting.