Solved

Disable access to change date and time

Posted on 2008-10-09
12
5,109 Views
Last Modified: 2010-08-05
I'm a sys. admin and want throgh some policy or something disable the user from being able to change the time/date settings of a computer. I have found a way to make it disappear from the system tray but it is not the ideal solution. any ideas?
0
Comment
Question by:borgb002
  • 5
  • 4
  • 2
  • +1
12 Comments
 
LVL 6

Expert Comment

by:MrNiss99
ID: 22682163
As long as the user is not in the local administrators group then they shouldn't be able to change date/ time.
0
 

Author Comment

by:borgb002
ID: 22682210
in fact they are....... any work arounds please?
0
 
LVL 8

Expert Comment

by:Point-In-Cyberspace
ID: 22682222
Normal users cannot change date/time on the machine. If users are power users or administrators you can use a local policy that you can apply to local computers or, if there is a domain, a group policy to do this.

Open policy editor and look for:
  Computer config/Windows settings/User rights/Change system time

Here you can set who will be able to change date and time.

0
 

Author Comment

by:borgb002
ID: 22682299
can't find it.... under "Windows Settings" there are only two options:
Scripts
Security settings
0
 
LVL 8

Expert Comment

by:Point-In-Cyberspace
ID: 22682468
My mistake. I'm using nonenglish windows now.

You have to go to:
Computer config/windows settings/Security settings/Local .../User rights/Change system time


0
 

Author Comment

by:borgb002
ID: 22682565
ok found. But it is asking for a user/group in my domain. I was hoping to find:
Allow change date/time [ENABLE or DISABLE]  but unfortunately wasn't like that.

If I add a user or group, what does that mean that I'm restricting or allowing access?
0
How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

 
LVL 5

Expert Comment

by:micalkin
ID: 22686795
Only the Groups/Users listed in the policy are allowed to change the time.
0
 
LVL 6

Expert Comment

by:MrNiss99
ID: 22686885
If there are too many user/ group entries to add to the policy, then just force a time sync with your DC on logon. Then at least it would be in sync upon logon.

Just a thought.

add this to your logon script:

net time \\ntpserver

0
 

Author Comment

by:borgb002
ID: 22687072
micalkin:
I'm doing this from the server ACTIVE DIRECTORY USERS AND COMPUTERS
in the GROUP POLICY OBJECT EDITOR I'm selecting the feature you've mentioned and added a user that obvious is not my user name. I assumed that I was giving access to this user only and automatically inheritince deny permissions to mine; but unfortunately it didnt work that way.

MrNiss99:
I am already doing that... It works but the user still can change the date and time later on.
0
 
LVL 8

Expert Comment

by:Point-In-Cyberspace
ID: 22694450
Let's talk about group policy:

A policy is applied to an object. You have to apply this policy to the object where is contained the COMPUTERS which are used by the users you need to block, because this policy is a computer settings one.
If, for example, computers are in the OU called machines, then you have to apply this policy to that OU.
If they are in a folder you can't apply the policy so you have to create an OU or you may apply the policy to the entire domain. This will apply the policy to the domain controllers too.

In the policy you have to specify which users or users group WILL BE ABLE to cange the date and time, so, in your config, you have to set it to none because all of your users are administrators.


Hope this helps

0
 
LVL 8

Accepted Solution

by:
Point-In-Cyberspace earned 500 total points
ID: 22694456
One more thing: to apply a policy you have to go to the compter that you are using for test and in a command prompt write:
   gpupdate /force

to apply group policy. You have to do this after every policy change, because by default policied are refreshed every hour.

Another way is to restart the test computer.

0
 

Author Comment

by:borgb002
ID: 22694478
Thanks Point-In-Cyberspace

your comment has shed some further light. I'll try it out on computers rather than login names. I had created an OU and applied the policy to that OU, then placed login names under it. Obviously it didnt work out.

I'll try your suggestion ..
0

Featured Post

Are your corporate email signatures appalling?

Is it scary how unprofessional your email signatures look? Do users create their own terrible designs and give themselves stupid job titles? You can make this a lot easier for yourself by choosing an email signature management solution from Exclaimer today.

Join & Write a Comment

Storage devices are generally used to save the data or sometime transfer the data from one computer system to another system. However, sometimes user accidentally erased their important data from the Storage devices. Users have to know how data reco…
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
The goal of the tutorial is to teach the user how to use functions in C++. The video will cover how to define functions, how to call functions and how to create functions prototypes. Microsoft Visual C++ 2010 Express will be used as a text editor an…
The viewer will learn how to clear a vector as well as how to detect empty vectors in C++.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now