Good Morning Vern,
I feel like I've experienced this earlier than those two OS releases too as the permissions get messed with.
Might I recommend the use of JAMF's composer to package up apps as pkg files?
Its a paid for program but it simplifies making packages and is just a really helpful tool.
You need not have to pay for JAMF Pro to get it as its available separately.
I am quite partial to using composer 😊
Otherwise, there are free alternatives that may take some learning to make the packages with.
eg Munki has Munkipkg and theres autopkg.
From memory these are command line based.
I tend to use it to make an installer for Filemaker that slaps the Kamar license file into the correct location.
Also removes old versions while its at it, assuming its a major version upgrade.
As for windows, Intune and MSI's perhaps look into visual studio + wix installers.
You can use it to wrap up exe files into an MSI which Intune will happily install.
This is expected and required in shared and multi-user setups such as schools, offices, and managed environments. ~ also personal devices! 😉
We'll have to wait for Apple to release a fix for the behavior, unless they are thinking of 1 to 1 devices are the future!
Thanks,
Dion McGovern-Allen.