802.1x instead of switch ACLs
SSSD (Linux) or Active Directory (Windows) or other more custom solutions for dynamic DNS
Firewalls rules that use those dynamic DNS names
Dynamic DNS, DHCP, and static assignment are all still part of IPv6. Putting single IPs in switch ACLs is an anti pattern. Consider zero trust or working with whole subnets(they're plentiful in v6) instead.
I'm convinced half the ipv6 subreddit is made of people who don't actually like ipv6 and are trying to subvert it. The advice they give sometimes is just insane. "Just get a new ISP bro..."
I think a lot of people assume privacy addresses are required. You can just not mess with them. Privacy is dead anyway.