Here are the steps to leave and rejoin the domain:
- Remove affected rules and policies.
- Delete realms.
- Leave the domain.
- Ensure the Edge SWG (ProxySG) appliance has left the domain.
- Rejoin the domain and recreate the IWA_Direct realm.
- Reapply policies.
Remove Affected Rules and Policies
To manually remove all Visual Policy Manager (VPM) rules and policies that apply to the realm you want to remove:
Note: When following 1.b for removing affected rules and policies, you must respect the format of the XML file. If you do not respect the format then when re-importing the backup and opening the VPM it will not open up with the policies. In notepad++, for example, is how to save correctly the policy files. Set the encoding as xml extension

Once completed you can now open the XML document with the normal notepad and now it respects the format of the XML
- Back up your policy files:
- Log into the Management Console and select Configuration > Policy > Policy Files.
- Save the Local, Forward, and Central policy files by copying and pasting their content from Text Editor to a text editor, such as Notepad.
- Remove the content from the Local, Forward, and Central policy files.
- Back up the VPM files:
- Select Configuration > Policy > Policy Files > Visual Policy Files.
- Save the VPM-CPL and VPM-XML policy files by copying and pasting their content from Text Editor to a text editor, such as Notepad.
- Remove the content from the VPM-CPL and VPM-XML policy files.
- Open the VPM by selecting Configuration > Policy > Visual Policy Manager > Launch.
- You should see a blank VPM dialog.
- Click Install policy to apply changes, and close the dialog.
Delete Realms
To delete the realms:
- Log in to the Management Console and click Configuration > Authentication > IWA.
- Select the IWA_Direct realm you want to delete.
- Click Delete.
- Click OK.
NOTE: Proxy may need to be rebooted to clear any association to realm in question in the memory.
Leave The Domain
To leave the domain:
- Log in to the Management Console and click Configuration > Authentication > Windows Domain.
- Select the Windows domain you want to leave.
- Click Leave.
- Click OK.
Note: If the Leave button is grayed out, refer to the following Knowledge Base article: Cannot leave Windows domain in the Management Console
Ensure the Edge SWG (ProxySG) Appliance has Left the Domain
To refresh the Management Console, press the F5 key.
Rejoin the Domain and Recreate the IWA_Direct Realm
To rejoin the domain, refer to the Knowledge Base article: How do I configure the Edge SWG (ProxySG) appliance to connect directly to Active Directory for IWA authentication?
Reapply Policies
To reapply the policies:
- Restore all the rules and policies that you backed up. To reapply the policies, refer to the following Knowledge Base article: Restoring VPM-CPL and VPM-XML to ProxySG
- Apply your changes by launching VPM and clicking Install policy.