When a user exists in our system, and they have membership to level/group where policies are set - and that user logs into the mac policies / apps etc should be applied to that user.
When the next user logs in, policies assigned to them should be applied, the previous user policies / apps etc should be removed