Couple options. You could change local security permissions and then remove his gateway, thus preventing him from changing network settings.
You could possibly also NAT him back to himself if you have a basic NAT turned on in your gateway. The only problem with this is that if they change to automatically detect i addresses, it will be fixed.
Another option, if you have a small network would be to set everyone up with static IP addresses and not give him the gateway. You may need to change it. Then regardless of whether or not he uses DHCP, he will not have the gateway.
Changing DNS will probably not work. It is pretty easy to find an open DNS... Also removing DNS would fail in keeping the workstation active in the local network if DNS is used.