only one idea which I have to restrict access to storage is to use credential passthrough so your user will have access (full or read only etc.) only to what is defined by IAM in azure https://docs.microsoft.com/en-us/azure/databricks/security/credential-passthrough/adls-passthrough

so every database will be on separate mount pointing to separate container in adls with separate access rights


My blog: https://databrickster.medium.com/