The issue for us came up because we used to have a user forced into a certain directory for backup retrieval, but changed in the transition to OPNsense to the backup script pushing the config via SFTP. We like to give minimal access to service accounts if possible.
Btw, I really appreciate your responsiveness to issues here instead of wiking off with "by design"...
With that or on top we could add a "remote" group and give that group SSH rights so no users without a proper shell will be able to login through SFTP and SSH?