

Is he doing this with his entra account? Are there any local accounts? Could he just be providing a local admins credentials any time he needs the permission (UAC pop up) but still logged into the Entra ID account? Either way, jump onto (or backstage into) his device and use lusrmgr.msc to check if he’s in the admin group if your sure he’s not an admin in entra. If he is in the admins group (or there’s a dummy account in there he may be using) remove it with the relevant net localgroup command.
To add to your comment, IM, uncensored and file sharing just screams CSAM network to me; either by intention or by who it’ll attract. This place has a TOS and had to wrestle with that shit in the early days on the main comms.