Forum Discussion
OMA-URI Settings to Allow users to change time fails!
Hi SamSONACA,
Yeah, the "Policy CSP - UserRights" isn't really well documented.
This is how I've used it in my test environment:
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/UserRights/ChangeSystemTime
Data Type: String
Value: *S-1-5-19*S-1-5-32-544*S-1-5-32-545
As mentioned in https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-userrights, it is better to use SIDs, because strings are localized for different languages. For reference, see https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dtyp/81d92bba-d22b-4a8c-908a-554ab29148ab?redirectedfrom=MSDN.
Now, you have to be careful with the special character . Johan Arwidmark has already well explained in https://deploymentresearch.com/configuring-user-rights-policies-in-intune-via-custom-profile/ how to handle this.
The real delimiter is: 
It has to be converted to:
In MEM, it will be displayed like this:
Im my case, the end user with standard user rights can only change the time through the "timedate.cpl". The shield of UAC is still displayed, but the end user is nevertheless able to change the time: