In Windows, how do I disable ADS network settings after I leave the IU network?
To disable your ADS network settings in Windows after you leave the Indiana University network, follow the appropriate instructions below.
On this page:
Windows 8, 7, and Vista
Reset the password to the Administrator account if you are not sure you already know it:
- In Windows 8, press Win-
xto open the Power User menu, and then clickComputer Management.Note: For help navigating in Windows 8, see About views in Windows (Start screen/menu, Control Panel) and Microsoft's Windows 8 FAQ.
In Windows 7 and Vista, from the
Startmenu, right-clickComputerand selectManage. - In the left pane of the window, click the arrow next to "Local
Users and Groups", and select the
Userssubfolder.
- At the right, find the account with the description "Built-in
account for administering the computer/domain". By default, the
account is named Administrator. Right-click it and choose
Set Password....
- Enter a new password for the account and confirm it. Click
OK.
To unjoin from the ADS Domain:
- In Windows 8, press Win-
eto open theComputerwindow. In the list of locations on the left, right-clickComputer, and then selectProperties.Note: For help navigating in Windows 8, see About views in Windows (Start screen/menu, Control Panel) and Microsoft's Windows 8 FAQ.
In Windows 7 and Vista, from the
Startmenu, right-clickComputerand selectProperties. - In the left pane of the window, click
Advanced System Settings.
- In the
System Propertieswindow, select theComputer Nametab, and then clickChange.
- Under "Member of", select
Workgroup:. In the field provided, type any name you would like, and then clickOK.
- You will then be prompted with the
Local Username And Passwordwindow for authentication. In the "Name:" field, type your computer name and local account name (e.g.,bl-rh-username\LocalAccount). In the "Password:" field, type your local account password. ClickOK.
- In the
System Settings Changedialog box that appears, clickYesto automatically reboot your computer.
Windows XP
When leaving the IU network, you should do three things:
-
Before leaving campus, reset the password for the local
administrator account if you are not sure you already know
it:
- Click
Start, and thenControl Panel.Note: If this doesn't match what you see, refer to About navigation settings in Windows.
- Double-click
User Accounts.
- Highlight the administrator account (make sure the "Domain:"
listed is the name of your computer and not "ADS") and click
Set Password....
- In the two boxes, enter the password you'd like to use, and then
click
OK.
- Click
-
Disable the ADS network settings:
Note: This step only applies to Windows XP Professional. Windows XP Home and Media Center editions are unable to join a domain or Active Directory; if you use either of those operating systems, skip to the next section.
- Right-click
My Computerand chooseProperties.
- Click the
Computer Nametab, and then clickChange.
- Select
Workgroup:, and then enter anything you like in the field provided.
- Click
OK, and then clickApplyto save your changes and close the open windows.
Note that this step can be done either on or off campus, so it doesn't matter if you do it before or after you leave.
- Right-click
-
If necessary, reconfigure the LAN Manager authentication
settings:
When set to its highest setting, the LAN Manager Authentication level should still work off campus in most situations. The only times it won't work will be when you bring your computer to a new domain that isn't set to handle the NTLMv2 protocol. Note that this combination of factors is rare; most domains can handle NTLMv2. For most people, this setting should be fine, especially if you are returning to campus at some point.
Some users may experience issues with this control at its current setting. For example, in a home networking situation, a Windows computer not configured to use NTLMv2 will not be able to map a drive or folder until it is reconfigured to do so. In those cases, UITS recommends that you reconfigure the other computer, rather than decrease the security of your own.
UITS does not recommend that you change this setting proactively. However, if you have no choice, go no lower in settings than you must in order to guarantee functionality.
Follow the instructions below to change the setting, but do not do this until you have left campus, since the IU ADS is configured to have its computers run at the highest level for this setting:
- Determine whether you ran the IUWindowsAuthUpdate program. If you configured your computer
with Get Connected or downloaded the tool
from IUware, you did; otherwise, you did not.
- Undo the settings:
- If you ran IUWindowsAuthUpdate from IUware, uninstall it.
- If you changed the settings manually, see How can I use the local security settings to force NTLMv2?
Note: Do not choose
Send NTLMv2 response only/refuse LM & NTLM. Instead, select one of the first four choices. UITS recommends choosingSend NTLMv2 response only, but for some networks, you may need to drop that toSend NTLM response onlyor lower. Protocols lower than NTLMv2 are considered insecure, so it is best to stay at the highest setting possible for your situation.
- If you ran IUWindowsAuthUpdate from IUware, uninstall it.
- Determine whether you ran the IUWindowsAuthUpdate program. If you configured your computer
with Get Connected or downloaded the tool
from IUware, you did; otherwise, you did not.
Note: At Indiana University, the University Information Security Office (UISO) recommends that you normally refrain from running your Windows computer as an administrator. For more, see What is the principle of least privilege?
Last modified on June 06, 2013.







