Configuring your Windows 7, Vista, or XP Professional computer to connect to IU's ADS domain
To connect your Windows 7, Vista, or XP Professional computer to the ADS domain, first set the local administrator password if you have not done so already, and then join your computer to the ADS domain. If you are unsure whether you should join your computer to the ADS domain, see the "Important information" section below.
Notes:
- The directions below allow you to connect to the Active Directory Services (ADS) domain at Indiana University by creating a new user profile on your workstation. When you log into ADS using this new profile, none of the settings from your previous user profile will apply (e.g., Task Manager icons, desktop files, Outlook configuration). To restore these settings, you must copy your old user profile over to the new one; see In Windows, what is a user profile, and how do I copy one user profile to another?
- The instructions below work for the Business, Ultimate, and Enterprise editions of Windows 7 and Vista.
On this page:
- Setting the local administrator password
- Joining your computer to the ADS domain
- Important information
Setting the local administrator password
To join your computer to IU's ADS domain, you need a local administrator password. For more, see In Windows 7, Vista, or XP, how do I set the administrator password?
Joining your computer to the ADS domain
- In Windows 7 or Vista, from the
Startmenu, right-clickComputer; in XP, right-clickMy Computer. Then, from the menu that appears, selectProperties.
- In Windows 7 or Vista, select
Advanced System Settings. In theSystem Propertieswindow, select theComputer Nametab and clickChange.In XP, in the
Systems Propertieswindow, select theComputer Nametab and clickChange. - Under "Member of", the selected radio button will show
whether your computer is a member of a domain or a
workgroup. If your computer is a member of a domain, follow the
instructions in this step. If your computer is a member of a
workgroup, skip to step 8.
- In the
Computer Name Changeswindow, under "Member of", selectWorkgroup. - In the "Workgroup:" field, type a temporary name and click
OK. - A
Network Identificationdialog box will appear. ClickOK. - You will then see another dialog box reminding you to reboot your
computer. Click
OK. The computer will restart.
- In the
- Navigate back to the
Computer Name/Domain Changesdialog box. Then, in the "Computer name:" field, type a new computer name that complies with the ADS domain naming convention. The naming convention requires names with the following components:
- A two-character campus code followed by a dash:
- BL for Bloomington
- EA for East
- FW for Fort Wayne
- IN for Indianapolis
- KO for Kokomo
- NW for Northwest
- SB for South Bend
- SE for Southeast
- A four-character department code followed by a dash
- A unique computer name up to seven characters in length
Note: Do not insert any spaces in the computer name.
- A two-character campus code followed by a dash:
- Reboot your computer.
- After the computer restarts, log in again. You will most likely
have to log in as Administrator, or as a user with
administrative rights. From the
Startmenu, right-clickComputer(7 and Vista) orMy Computer(XP) and, from the menu that appears, selectProperties.
- In the
Systems Propertieswindow, select theComputer Nametab and clickChange.
- In the
Identification Changeswindow, under "Member of", selectDomain. In the "Domain:" field, typeads.iu.edu.
- Click
More....
- In the "Primary DNS suffix of this computer:" field, enter
ads.iu.edu. - Check
Change primary DNS suffix when domain membership changes. - Click
OK.
- In the "Primary DNS suffix of this computer:" field, enter
- You will then be prompted with the
Domain Username And Passwordwindow for authentication. In the "Name:" field, typeADS\username, replacingusernamewith your Network ID username. In the "Password:" field, type your IU Network ID passphrase. ClickOK.
- A
Network Identificationdialog box will appear. ClickOK. You will see another dialog box reminding you to reboot your computer. ClickOK.
- Click
OKto close theIdentification Changeswindow. You may see a warning icon in the bottom portion of theSystems Propertieswindow reminding you to reboot the computer. ClickOK.
- You will see a
System Settings Changedialog box. ClickYesto automatically reboot your computer.
Note: When you log into your computer after it
reboots, in the "Domain:" field of the login prompt, select
ADS to log into the Active Directory domain. In Windows 7 or Vista, you may be automatically prompted to log into ADS.
By default, ADS accounts will have user-level rights. For more, see At IU, in Windows, how do I give myself or other users login privileges on my computer?
Important information
UITS recommends that all computers directly on the IU network (i.e., physically present and on the IU network, not wireless or off campus) should be joined to the Active Directory if possible, whether or not it is a department requirement.
In general, the following guidelines apply:
- If you want or need to take advantage of once-per-session domain
authentication (i.e., if you use Outlook to access your IU Exchange
account, or if you regularly map drives or print to networked
printers), the computer should be on the ADS domain. If it is not, you
will have to enter a password for each service or resource you
access.
- If the local support provider (LSP) or local
departmental administrator controls computer and network security
through Group Policy Objects, the computer must be on the ADS domain.
- If many different IU users use the computer, it should be on the ADS domain. Otherwise, you will have to create a local account for each individual user, or one "general" local account accessible by everyone. This option is not secure, as it allows all users to access all other users' files.
However, in some instances, you may not want your computer on the ADS domain. Consider the following:
- If you use a portable computer or otherwise access the network wirelessly, joining the ADS domain will not give you the benefits listed above.
- An Active Directory-joined computer will normally need to
communicate with the network to log you in, with the following exceptions:
- Cached credentials will let you log in without a connection.
- You can log into a local rather than an ADS account.
At IU, that means a wireless computer needs a VPN connection first. Windows is able to log into a domain through a VPN connection, and has no problem doing it, but relying on such a connection when logging in adds complexity as well as a potential point for problems to arise.

