This is slightly alarming. Our lab Macs are set up with AD authentication (thru NoMAD) ; network users get a local home created at first login on any given computer. Network user accounts get standard permissions.
Today I noticed that user homes are created with wrong permissions on some (but not all!) of the lab Macs.
I would expect user homes to be owned by [some_user]:staff with default permissions 700. On some machines this is the case; on others I'm seeing 750 or 755.
Especially weird because I just nuked & paved the whole lab, so configs should be identical.
Am I overlooking something obvious? Where does the umask get set? I don't see anywhere in NoMAD to control it; is it coming from the AD server?
[Intel iMacs running 13.6.7, highest os version they support]