Hi,
In general, we use local user group to manage user account permission. For users within administrator group means they have full permissions. I am afraid that we are unable to restrict the permission for administrator.
You may consider adding a general local account to Network Configuration Operators group. Or we may consider domain user with domain policy configuration to restrict the account permission.