Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

The admin on a PC is often whoever set it up, and that person rarely stays with the machine. It might be a former employee, a family member who unboxed it, or a technician's account from three projects ago. Here's how to change administrator on Windows 11, from the Settings switch on one PC to handing machines over cleanly and keeping admin rights scarce across a fleet.

Change the Administrator in Settings

The fastest way to change administrator on Windows 11 is the account type switch. You need to be signed in as an administrator already.

  1. Open Settings, then Accounts, then Other users.
  2. Expand the account you want to change.
  3. Next to Account options, select Change account type.
  4. Pick Administrator or Standard User, then select OK.

The account has to exist on the PC first. If it doesn't, add it from the same page with Add account, then change its type. The change applies at the user's next sign-in, so ask them to sign out and back in.

Two older tools do the same job. Control Panel has it under User Accounts, then Change account type. netplwiz opens the classic User Accounts dialog: select the user, choose Properties, then the Group Membership tab. Microsoft's help page for this adds one line of advice: limit the number of administrators on a device, because they have complete control over it.

Change It From the Command Line

The GUI is fine at a desk. On a remote session, or across twenty PCs, use a command. Both of these run from an elevated prompt.

powershell
# Classic, works in cmd or PowerShell
net localgroup Administrators "jsmith" /add

# PowerShell, including Microsoft and Entra accounts
Add-LocalGroupMember -Group "Administrators" -Member "AzureAD\jsmith@contoso.com"
Remove-LocalGroupMember -Group "Administrators" -Member "olduser"
Get-LocalGroupMember -Group "Administrators"

Microsoft's documentation for Add-LocalGroupMember shows the prefixes: MicrosoftAccount\ for a personal Microsoft account, AzureAD\ for an Entra account, and DOMAIN\ for a domain user or group. Two gotchas from the same page. The LocalAccounts module isn't available in 32-bit PowerShell on a 64-bit system. And on a domain-joined PC, if a local user and a domain user share a name, the cmdlet adds the domain one.

Run Get-LocalGroupMember before and after any change. It's the audit, and it's the line that shows you the forgotten accounts. Our PowerShell commands guide has more of these sorted by ticket type.

Local, Microsoft and Entra Accounts Behave Differently

"Administrator" means membership in the local Administrators group. How an account lands in that group depends on what kind of account it is.

Account typeHow it becomes adminHow to change it
Local accountCreated by setup or added by an adminSettings, netplwiz or net localgroup
Microsoft accountFirst account on a home PC is adminSame tools, with the MicrosoftAccount\ prefix
Domain accountDomain groups added to the local group, often by Group PolicyGroup Policy or DOMAIN\ prefix
Microsoft Entra accountThe user who joins the device, plus two Entra rolesEntra device settings, Intune policy or the AzureAD\ prefix

Entra-joined PCs are the ones that surprise people. According to Microsoft Learn, the Entra join adds three principals to the local Administrators group: the Global Administrator role, the Microsoft Entra Joined Device Local Administrator role, and the user who performed the join. So the employee who unboxed the laptop is an admin unless someone turned that off.

Changes to the Entra role are slow on purpose. Microsoft documents up to 4 hours for a new Primary Refresh Token, and the user must sign out and back in, not just lock and unlock. Removing someone works the same way: they keep admin rights while signed in, until that token refreshes.

To stop joining users from becoming admins, use the device registration setting in Entra or an Autopilot profile. To manage the group per device set, Intune's Account protection policy can set local group membership from Entra groups.

Hand the PC Over When Someone Leaves

The order matters more than the tool. Remove the old admin first and you can lock yourself out of the machine.

  1. Add the new admin. Use any method above.
  2. Sign in as the new admin. Confirm it works, elevated, before touching anything else.
  3. Demote or remove the old account. Change it to Standard User if their data still needs copying. Remove it once the data is safe.
  4. Remove the work or school account if the PC is going to someone outside the company.
  5. Re-check the group with Get-LocalGroupMember.

On Entra-joined devices, step 3 has an extra catch. If the departed employee joined the laptop, their account is in the local group directly. Disabling them in Entra stops the sign-in, but the local group still lists them until someone cleans it up or the device is reset.

The Built-in Administrator Account

Every Windows 11 PC has a built-in account called Administrator. It's disabled by default. Setup creates your first admin account instead.

You can turn it on with net user Administrator /active:yes. Don't use it as a daily account. Its security identifier ends in 500 and is the same on every machine, so attackers know it exists before they look.

Renaming it is an option, through the Group Policy setting "Accounts: Rename administrator account" under Computer Configuration, Windows Settings, Security Settings, Local Policies, Security Options. Microsoft's own reference is modest about the benefit. It says renaming makes the account "slightly more difficult" to guess, and tools that authenticate by SID ignore the name anyway. The query "how to change administrator name on Windows 11" usually means this rename, or the display name on a Microsoft account, which you change on the Microsoft account website.

Keep Admin Rights Scarce

Changing the administrator is a good moment to ask who needs to be one. In this r/sysadmin thread from April 2025, the most upvoted answer is three words: "Administrators. No one else." The replies below it split between separate admin accounts for IT and time-limited elevation for everyone else.

Three habits cover most of it. Techs use a standard account day to day and a second account to elevate. Users who need admin for one installer get it for that installer, which is what endpoint privilege management tools do. And every PC gets its own local admin password, which is what Windows LAPS is for.

Windows LAPS has been built into Windows since the April 11, 2023 update. It rotates the password of one local admin account on each device and backs it up to Active Directory or Microsoft Entra ID, where authorized admins can read it. The Entra version has been generally available since October 23, 2023. On Windows 11 24H2 and later, its automatic account management can create and manage the account for you. The legacy Microsoft LAPS installer is deprecated and blocked on Windows 11 23H2 and later.

Andy Malone, a Microsoft MVP, walks through Windows LAPS from policy to password retrieval here.

The usual worry is what happens if LAPS breaks and nobody can get in. This June 2026 thread asks exactly that. The replies point out that the password only changes once the directory confirms it has the new one, so a sync problem doesn't strand you.

Locked Out of Every Admin Account

If no working account on the PC is an administrator, go through the options in this order:

  1. Another admin account on the same PC, including a separate IT account.
  2. The LAPS password, read from Active Directory, Entra ID or Intune.
  3. Directory admins. On a domain PC, a domain admin. On an Entra-joined PC, a user with the Entra Joined Device Local Administrator role.
  4. Reset or reinstall. For an unmanaged PC with none of the above, Reset this PC or a clean install is the supported route. Have the BitLocker recovery key ready first.

Microsoft doesn't offer a supported way to promote an account from outside Windows. That's why steps 1 to 3 are worth setting up before anyone needs them. OpenFrame can run the Get-LocalGroupMember check as a script across a client's devices and collect the output, which turns "who is admin where" into one report instead of a remote session per PC.

The Short Version

To change administrator on Windows 11, go to Settings, Accounts, Other users, and use Change account type. From a prompt, net localgroup Administrators or Add-LocalGroupMember does the same, with AzureAD\ for Entra accounts. Add the new admin before removing the old one. On Entra-joined PCs, check who joined the device, and expect role changes to take up to 4 hours. Then keep the list short with separate admin accounts and Windows LAPS.

For how roles and permissions scale beyond one PC, read our guide to RBAC.

Conrad Lunderstedt

Conrad Lunderstedt

Solution Architect

I'm Conrad, Solution Architect at Flamingo. I've spent about 26 years in IT, roughly half of it inside MSPs and the rest in enterprise environments, so I've watched vendor decisions get made on both sides of that line. Now I spend my days talking with MSPs about the stack they already run, and helping them work through the requests and issues that come with it.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

How to Change Administrator on Windows 11

Sign in as an administrator, open Settings, go to Accounts, then Other users, expand the account and select Change account type. Pick Administrator and select OK. The change applies at the user's next sign-in. From an elevated prompt, net localgroup Administrators "username" /add does the same.
From an elevated PowerShell prompt, run Add-LocalGroupMember -Group "Administrators" -Member "AzureAD\user@yourdomain.com". For all Entra-joined devices at once, use the Microsoft Entra Joined Device Local Administrator role, which can take up to 4 hours plus a sign-out to apply.
The PC is left with no working administrator, and you can't change account types or install software. Recover with another admin account, the Windows LAPS password, or a domain or Entra admin. On an unmanaged PC with none of those, Reset this PC or a clean install is the supported route.
Not as a daily account. It's disabled by default and its security identifier ends in 500 on every machine, so attackers know it exists. If you need a local admin fallback, manage its password with Windows LAPS so every PC has a different, rotated password.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.