The user socket directory needs to be SGID so that they inherit the group ownnership. Then xrdp can write to them.