Win11: weaknesses of domain policy and vulnerabilities

Job ID: 40183729

Budget: €30 – €250 EUR

For this project I'm looking for a VERY competent consultant on Windows systems and (maybe) on ethical hacking.
Standard approach is not useful and doesn't solve the task.

I want to clarify that the request is made for purely educational and exercise purposes.
The goal is to make a client accessible/usable again (ethical hacking techniques).

The target client is really closed/blocked.
The client is Windows 11 Enterprise 23H2 - Experience Pack 1000 - 64bit (OS build 22631.5908)

Actual landscape:
- Windows user is not local machine Administrator.
- The local disk is encrypted via BitLocker (booting from the outside therefore does not allow reading the data);
- BIOS has a password, not known;
- Unauthorized applications are not allowed (no possible to install nothing more).
- If you try to run CMD with administrator rights you get the message: "This app has been blocked by your system administrator"
- It is not possible to create administrator users nor insert the local user in the administrators group
- Command “netplwiz” is locked by Administrator.
- Access to the registry has been disabled (every time you edit you get the error "Cannot edit....")
- Local Administator user is disabled.
- Resource sharing via local network is disabled;
- USB ports are disabled: no external media can be read/connected;
- Bluetooth connections are not enabled
- No changes on "User Account Control Setting", getting the error "Your system administrator has blocked this program"
- No changes on "Group Policy", getting the error "You don't have permission to perform this operation - Access denied"
- No changes on "Local Group Policy", getting the error "You don't have permission to perform this operation - Access denied";
- The contents of the path C:\Windows\System32\GroupPolicy cannot be changed;
- No remote access allowed.

I am looking for a consultant who can evaluate current policies and allow the user to modify existing policies to allow the full workstations management.

Most likely the client has a log system of user activities (I don't know if it's possible)