NTFS permissions to modify files but not folder structure

I had a request a little while ago where an end-user wanted a set of users to be able to fully manage the folder structure below a certain folder in share, and for another set of users to be able to create/modify/delete files anywhere within that structure, but be unable to change the structure itself. Sounds very straight forward, but there’s slightly more to it than meets the eye [especially if you’re used to applying one ACE (Access Control Entry) per security group/user].