SMB Share / ACL Permissions issue

I have a dataset “shared” with a “user#” dataset structure underneath i.e. /shared/user1, etc

“shared” dataset preset nfs4_restricted and root:root Full/Modify, everyone@ traverse
”user” dataset is presetn nfs_restricted and;
user1 Full (no group)
admin Full
user1 deny delete children / delete - inherit file / directory

user can create files but can’t delete - as desired

problem: user cannot create subdirectories - should be able to create but not delete