More Information:
I just now Observed the issue when the Primary group for the Mobile Login User on the AD Server is switched to a different Group on the AD Server.
I don't know why MacOS implements it this way, but there seem to be 2 instances of that user in 2 different NODES in DirectoryServices. These instances have the EXACT SAME UniqueID.
One of these NODES is the /Local/Default node, which I assume is for the scenario when the Mobile Login user is not connected.
The other NODE is the /ActiveDirectory/domain node, which might be referred to for the when-connected-to AD scenario.
After switching the Primary group on the AD Server for that user, only one of the above NODE is getting updated.
The above results in the account getting 2 Instances of Primary Group when the Tool is querying via the OpenDirectory/DirectoryServices Framework.
It is unclear to me if this behavior is a Big Sur issue OR occurs on earlier MacOSes OR is by Design this way.
Topic:
App & System Services
SubTopic:
Networking
Tags: