You give the user Modify AND remove authenticated users and builtin/users, so that only one user has access to each profile container. Admins continue to have access if that was given correctly. https://docs.microsoft.com/en-us/azure/storage/files/storage-files-identity-ad-ds-configure-permissions#azure-rbac-permissions