@Ismaele Giallombardo, Thanks for posting in Q&A.
Based on my research, I find that autopilot is the only enrollment option to restrict user to become a local admin, that choose a standard user when assigning profile. To make devices as 'Corporate', you can try to enroll device using Windows automatic enrollment, but it will still let user to join local admin automatically.
If you would like to restrict user as local admin, as a workaround, there's feature under Endpoint security > Account protection>Local user group membership to manage local user group membership. We can choose Remove (Update) if we want to remove specific user from local administrators group. Here is a link with more details for your reference.
As a note, removing the built-in Administrator account from the built-in Administrators group is blocked at SAM/OS level for security reasons. Attempting to do so will result in failure.
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.