It is possible to hide all Temporal Group functionality by settings a server-side configuration option and then exposing that configuration option to Users who need to have the Temporal Group functionality blocked.
First, it is necessary to set the edsva-TemporalGroupMemberships-Disable boolean to a true value. This boolean is not editable in the Active Roles Console by any User and needs to be set via a script. The following script will set it to a true value:
Second, in order to allow Users to read the setting edsva-TemporalGroupMemberships-Disable boolean, create an Access Template that allows Read access to edsva-TemporalGroupMemberships-Disable attribute performing the following steps:
If this new Access Template is used to delegate access to the Active Roles Server Configuration node, any delegated users will find all Temporal Group options removed in the Active Roles Console and the Active Roles Web Interface.
NOTE: Since Active Roles Administrators ignore all Access Templates, they will still be able to see and use Temporal Group options in Active Roles clients.