I'm attempting to follow the CIS macOS 10.12 security benchmark. One of the recommendations (5.1.1) is to remove read and execute from group and global. Easy enough to document , but for a live environment we'd want something to run when a new home folder is created.
Testing has revealed that sudo is required so I'm thinking a script to loop through home folders and run:
sudo chmod -R og-rwx /Users/<username>
Issue I have, being a macOS admin n00b, is what should the daemon/plist be configured to monitor to ensure I'm running the script at the correct time. Or perhaps there is a master "home folder" permission template I can modify to ensure new home folders adhere to the CIS recommendation.
