[Samba] using Windows AD unwanted Group rights get applied to new Files


we have some Samba shares joined a existing Windows AD.
Everything works well with complex user rights.
But the problem ist that when a user creates a new file the standard windows group (domain-user) is also applied as a permission to the file. This breaks all the security because all users have now full acess to this file. (because all users are in the domain-user group)
All parent directories do not have this permission set. Where does it come from?

Thank you
