How to Enable or Disable Administrator Account Lockout in Windows 11

This post shows students and new users steps to change turn On or Off built-in administrator account lockout in Windows 11.

Windows 11 now has a new account lockout policy to protect users against brute-force password attack.

The Allow Administrator account lockout policy determines whether the built-in administrator account is subject to account lockout policy.

When you subject the built-in admin user to account lockout policy, it will apply Account lockout threshold policy setting, which determines the number of failed sign-in attempts that will cause a user account to be locked.

Account lockout duration policy setting which also determines the number of minutes that a locked-out account remains locked out before automatically becoming unlocked will be applied to the built-in administrator account.

Starting with Windows 11 build 22528 and higher, a new default policy are as follows:

  • Account lockout threshold is now set to 10 failed sign-in attempts by default
  • Account lockout duration is now set to 10 minutes by default.
  • Allow Administrator account lockout is now enabled by default.
  • Reset account lockout counter after is now set to 10 minutes by default.

Below is how to enable or disable account lockout policy for the built-in administrator account in Windows 11.

How to turn on or off account lockout policy for the built-in administrator account in Windows 11

As mentioned above, there are certain account lockout policies that can be applied to normal users in Windows 11. If you also want to apply these policies to the built-in administrator account, you must enable Allow Administrator account lockout.

Below is how to turn on or off Allow Administrator account lockout policy in Windows 11.

To turn on or off this policy, open Local Group Policy Editor by clicking on the Start menu and searching for Edit group policy as highlighted below.

Under Best match, select Edit group policy to launch Local Group Policy Editor.

In the left pane of Local Group Policy Editor, expand the tree: 

 Computer Configuration > Windows Settings > Security Settings > Account Lockout Policy

In the Account Lockout Policy details pane on the right, locate and double-click the setting Allow Administrator account lockout.

On the Allow Administrator account lockout Properties window, set to Enabled or Disabled to turn on or off the policy.

Select OK.

Close Local Group Policy Editor.

That should do it!


This post showed you how the enable or disable administrator account lockout policy in Windows 11. If you find any error above or have something to share, please use the comment form below.