How to keep /api/users endpoint off limits, but still allow filtering content by user?

You could extend the users-permission plugin (docs: Plugins extension | Strapi Documentation) and add the policy to the one route you want to change.