Solved

Prevent users from changing time zone settings

Posted on 2007-03-20
2
379 Views
Last Modified: 2008-05-30
We are currently running Windows server 2003, with all XP clients. I need to lockout the users from being able to change their time zone settings and want to use group policy to do so. The only problem I'm having is that  all our users domain accounts are in the local machine admin group (we can't change this, as it is a requirement that users of one of our specific applications be administrators in order to use this app). Is there any way to lock them out of Time Zone properties (or grey it out) at the computer level and not the user level?
0
Comment
Question by:Kzwijacz
2 Comments
 
LVL 13

Accepted Solution

by:
strongline earned 250 total points
ID: 18757713
it is in computer level already.

it's a user rights assignment
computer config\windows settings\security settings\local policies\user rights assigment
0
 

Author Comment

by:Kzwijacz
ID: 18757847
I did make the change in the user rights assignment area under computer config, and modified the 'change system time properties'. However, on the workstations users were still able to modify the properties. We have all users locally on their machines in the admin group (becuase of a specific application we use, we cannot change this) so I'm thinking this is the problem.
Any suggestions, or is there a different policy I need to change? Someone had suggested there may be a script I could use for this.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolve DNS query failed errors for Exchange
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question