Ah yeah. Sorry. We definitely only support the ACL mirror model - in fact we go even further and support local user and groups (with their new SIDs) so that we don't lose access to data or expose it by mistake, something robocopy cannot handle. I think robocopy is going to be your best option, perhaps combined with the ancient-but-still-useable built in 'server migration tool' you'll see listed as a feature. That tool can be run in a "recreate the shares only" mode where you wouldn't have to manually do all the shares over yourself.
Then you're just left with dealing with cutover manually. We did document what it does so you have kind of a checklist though: How cutover works in Storage Migration Service | Microsoft Docs
Sorry for my bummer answer. I've never had anyone ask for this functionality before. I guess one other thing would be to just run the migration, let it do all the security, and then just blow it away yourself with ICACLs afterwards? Meh...