In this article, we will teach you how to enable or disable built-in administrator account in Windows 11. Windows 11 has a hidden built-in administrator account that serves as the local system administrator with elevated rights without needing to operate as administrator or user account control (UAC) for elevation approval.
The Administrator account permits you to make more broad changes to the computer, for example, adding and removing user accounts or making modifications to install software settings. For those changes, an administrator account is typically necessary.
The built-in administrator account can’t be deleted or locked out, however, it can be enabled, disabled, or renamed.
If you sign in to this built-in administrator account, you are required to have the same full access rights as the administrator. This can be a security issue if you have malware or a virus while signing in to the built-in administrator.
Table of Contents
Enable or Disable Built-in Administrator Account
It is not recommended to use the built-in administrator account as a daily account. It is recommended to only enable the built-in administrator account to be used as necessary and disable it when finished.
Enable or Disable Built-in Administrator in Local Users and Groups
You must sign in as an administrator to use this option.
Local users and groups are only available in the Windows 11 Pro, Enterprise, and Education versions.
Open computer management by right-clicking on the Windows button, or you can directly access local Users and Groups by typing “lusrmgr.msc” in the run box.
Expand local users and groups and click on the user folder. Double click on Administrator in the middle window.
data:image/s3,"s3://crabby-images/72295/72295ef318a6a84de4e4939908ec15b37b946f2d" alt="Computer management"
In the General tab, check (disable) or uncheck (enable) the account that is disabled for what you want, and click OK.
data:image/s3,"s3://crabby-images/24c7d/24c7dea1d766085be9f9bdf2fb3f978c48dc3038" alt="Enable or disable built-in administrator account"
You can now close computer management if you want.
Enable or Disable Built-in Administrator using PowerShell
You must sign in as an administrator to use this option.
Search PowerShell and open it as an administrator.
data:image/s3,"s3://crabby-images/75d9d/75d9d547b60fd385810f115f5601e0d93e83b93a" alt="Search PowerShell command"
Copy and paste the command below you want to use in the elevated PowerShell, and press enter.
To enable a built-in administrator account, type the below PowerShell command.
Enable-LocalUser -Name "Administrator"
To disable the built-in administrator account, type the below PowerShell command.
Disable-LocalUser -Name "Administrator"
If you have previously renamed the “Administrator” account’s name, then you will have to replace Administrator in the command above with the new name instead.
If your Windows uses a different language than English, then you should substitute Administrator in the command above with the translation for your language instead.
When finished, you can close the powershell if you like.
data:image/s3,"s3://crabby-images/05628/056283226664923426013022f4696e1e1f536c3c" alt="Enable or disable built-in administrator account via PowerShell"
Enable or Disable Built-in Administrator via the Command Prompt
You must sign in as an administrator to use this option.
Search command prompt and open it as an administrator.
data:image/s3,"s3://crabby-images/d59ec/d59eca63855411bff1ff7fa226b01273d08360d8" alt="Search command prompt"
Copy and paste the command below you want to enable or disable built-in administrator account into the command prompt, and hit enter.
To enable, type the below command.
net user Administrator /active:yes
To disable it, type the below command:
net user Administrator /active:no
Once finished, you can close the command prompt if you like.
data:image/s3,"s3://crabby-images/c1747/c1747d7d133eb5d20407ea1cd949ffff9a883041" alt="Enable or disable built-in administrator account via command prompt"
Enable or Disable Built-in Administrator using the Local Security Policy
You must sign in as an administrator to use this option.
Local Security Policy is only available in Windows 11 (Pro, Enterprise, and Education versions).
Search for the local security policy and open it.
data:image/s3,"s3://crabby-images/33dd4/33dd4c7a6e5d8250838882eeb0dcdc49c2acd266" alt="Search local security policy"
Expand the Local Policies folder in the left pane, click on the Security Options subfolder in the left pane, and double click on Accounts: Administrator account status in the right pane.
data:image/s3,"s3://crabby-images/1fe3d/1fe3dbeb99bd7210f9fc5697b3ad9b79990dc4a8" alt="Local security policy"
In the administrator account status properties, select Enabled or Disabled for what you wish, and click OK.
data:image/s3,"s3://crabby-images/f7710/f77101cbfff9ee9be27da927dd14a5ed5ec56281" alt="Administrator account status properties"
You can now close the Local Security Policy if you desire.
If you don’t have another administrator account to sign in, or are unable to sign in to Windows 11, this option is ideal.
Boot your system with Windows 11 bootable disk. When the Windows setup screen appears, just press the +FF10 key to open command prompt.
data:image/s3,"s3://crabby-images/9aa64/9aa64de29e9ea8d6f749c5e2956458da10e4fd29" alt="Windows setup"
Type regedit into the command prompt at boot, and then hit enter.
data:image/s3,"s3://crabby-images/fcc18/fcc1832d4bf54908fcb2e074ad08928f6cd1095a" alt="Type regedit into the command prompt"
Click the HKEY_LOCAL_MACHINE key in the left pane of Registry Editor.
data:image/s3,"s3://crabby-images/30c10/30c10e547bdfb3b0af3e48f7c74763223feb4dc1" alt="Registry editor"
Click on the File tab and click on Load Hive.
data:image/s3,"s3://crabby-images/135a4/135a4ba1db8552f1f21d66741e2b3f6a62f94a1b" alt="Registry editor load hive"
In the Load Hive dialogue, open the drive (:C or :D) that Windows 11 is installed on, and navigate to the location below.
The drive letter (:C) will not always be the same at boot as it is in Windows 11.
It will not be the boot (:X).
C:\Windows\System32\config
Select the SAM file inside the config folder, and click on Open.
data:image/s3,"s3://crabby-images/c5826/c5826a9179de14285f01f4b6b5bb4c34c822e523" alt="Open SAM file"
In the Load Hive dialog, enter REM_SAM as a key name and click OK.
data:image/s3,"s3://crabby-images/465bf/465bf005fa8474aa7126adaa5ffdf0ff3c14e8cc" alt="Load hive"
Navigate to and enter the key below the left pane of Registry Editor.
HKEY_LOCAL_MACHINE\REM_SAM\SAM\Domains\Account\Users\000001F4
In the right pane of the “000001F4” key, double click on the F binary value to modify it.
data:image/s3,"s3://crabby-images/ab268/ab268fbd5c96e4907dad4254b97296d7ddc09e2d" alt="Windows registry users"
In the first column of row line 00000038, change 11 to 10, and click OK.
In the first column of row line 00000038, change 10 to 11, and click OK.
You could do this by clicking to the left of 11 to locate the cursor, pressing the Delete button, then typing 10.
data:image/s3,"s3://crabby-images/6b84d/6b84d207272c744c15a7b8a692f2c0dd9322c915" alt="Edit binary value"
Please visit Microsoft to learn more about the built-in administrator account.