Locking down Windows 11 Pro, still allows users who are not assigned Administrator rights to install programs??

I recently started running into this one after replacing dozens of Win10 workstations wtih new fancy schmancy ones with Win11. M365 (Azure/Entra) accounts simply ignore the fact that they do not have administrator rights and continue on as though they have local admin rights.

If a user downloads some bullshit (or even something simple like Chrome), and then proceeds to try install it, they don't face failure. All you have to do is close the authentication popup requesting the admin log-in and Windows just merrily continues on installing the app. It didn't do this in Windows 10, what in the world?