Updated: October 2026
The admin on a PC is often whoever set it up, and that person rarely stays with the machine. It might be a former employee, a family member who unboxed it, or a technician's account from three projects ago. Here's how to change administrator on Windows 11, from the Settings switch on one PC to handing machines over cleanly and keeping admin rights scarce across a fleet.
Change the Administrator in Settings
The fastest way to change administrator on Windows 11 is the account type switch. You need to be signed in as an administrator already.
- Open Settings, then Accounts, then Other users.
- Expand the account you want to change.
- Next to Account options, select Change account type.
- Pick Administrator or Standard User, then select OK.
The account has to exist on the PC first. If it doesn't, add it from the same page with Add account, then change its type. The change applies at the user's next sign-in, so ask them to sign out and back in.
Two older tools do the same job. Control Panel has it under User Accounts, then Change account type. netplwiz opens the classic User Accounts dialog: select the user, choose Properties, then the Group Membership tab. Microsoft's help page for this adds one line of advice: limit the number of administrators on a device, because they have complete control over it.
Change It From the Command Line
The GUI is fine at a desk. On a remote session, or across twenty PCs, use a command. Both of these run from an elevated prompt.
powershell# Classic, works in cmd or PowerShell net localgroup Administrators "jsmith" /add # PowerShell, including Microsoft and Entra accounts Add-LocalGroupMember -Group "Administrators" -Member "AzureAD\jsmith@contoso.com" Remove-LocalGroupMember -Group "Administrators" -Member "olduser" Get-LocalGroupMember -Group "Administrators"
Microsoft's documentation for Add-LocalGroupMember shows the prefixes: MicrosoftAccount\ for a personal Microsoft account, AzureAD\ for an Entra account, and DOMAIN\ for a domain user or group. Two gotchas from the same page. The LocalAccounts module isn't available in 32-bit PowerShell on a 64-bit system. And on a domain-joined PC, if a local user and a domain user share a name, the cmdlet adds the domain one.
Run Get-LocalGroupMember before and after any change. It's the audit, and it's the line that shows you the forgotten accounts. Our PowerShell commands guide has more of these sorted by ticket type.
Local, Microsoft and Entra Accounts Behave Differently
"Administrator" means membership in the local Administrators group. How an account lands in that group depends on what kind of account it is.
| Account type | How it becomes admin | How to change it |
|---|---|---|
| Local account | Created by setup or added by an admin | Settings, netplwiz or net localgroup |
| Microsoft account | First account on a home PC is admin | Same tools, with the MicrosoftAccount\ prefix |
| Domain account | Domain groups added to the local group, often by Group Policy | Group Policy or DOMAIN\ prefix |
| Microsoft Entra account | The user who joins the device, plus two Entra roles | Entra device settings, Intune policy or the AzureAD\ prefix |
Entra-joined PCs are the ones that surprise people. According to Microsoft Learn, the Entra join adds three principals to the local Administrators group: the Global Administrator role, the Microsoft Entra Joined Device Local Administrator role, and the user who performed the join. So the employee who unboxed the laptop is an admin unless someone turned that off.
Changes to the Entra role are slow on purpose. Microsoft documents up to 4 hours for a new Primary Refresh Token, and the user must sign out and back in, not just lock and unlock. Removing someone works the same way: they keep admin rights while signed in, until that token refreshes.
To stop joining users from becoming admins, use the device registration setting in Entra or an Autopilot profile. To manage the group per device set, Intune's Account protection policy can set local group membership from Entra groups.
Hand the PC Over When Someone Leaves
The order matters more than the tool. Remove the old admin first and you can lock yourself out of the machine.
- Add the new admin. Use any method above.
- Sign in as the new admin. Confirm it works, elevated, before touching anything else.
- Demote or remove the old account. Change it to Standard User if their data still needs copying. Remove it once the data is safe.
- Remove the work or school account if the PC is going to someone outside the company.
- Re-check the group with
Get-LocalGroupMember.
On Entra-joined devices, step 3 has an extra catch. If the departed employee joined the laptop, their account is in the local group directly. Disabling them in Entra stops the sign-in, but the local group still lists them until someone cleans it up or the device is reset.
The Built-in Administrator Account
Every Windows 11 PC has a built-in account called Administrator. It's disabled by default. Setup creates your first admin account instead.
You can turn it on with net user Administrator /active:yes. Don't use it as a daily account. Its security identifier ends in 500 and is the same on every machine, so attackers know it exists before they look.
Renaming it is an option, through the Group Policy setting "Accounts: Rename administrator account" under Computer Configuration, Windows Settings, Security Settings, Local Policies, Security Options. Microsoft's own reference is modest about the benefit. It says renaming makes the account "slightly more difficult" to guess, and tools that authenticate by SID ignore the name anyway. The query "how to change administrator name on Windows 11" usually means this rename, or the display name on a Microsoft account, which you change on the Microsoft account website.
Keep Admin Rights Scarce
Changing the administrator is a good moment to ask who needs to be one. In this r/sysadmin thread from April 2025, the most upvoted answer is three words: "Administrators. No one else." The replies below it split between separate admin accounts for IT and time-limited elevation for everyone else.
Three habits cover most of it. Techs use a standard account day to day and a second account to elevate. Users who need admin for one installer get it for that installer, which is what endpoint privilege management tools do. And every PC gets its own local admin password, which is what Windows LAPS is for.
Windows LAPS has been built into Windows since the April 11, 2023 update. It rotates the password of one local admin account on each device and backs it up to Active Directory or Microsoft Entra ID, where authorized admins can read it. The Entra version has been generally available since October 23, 2023. On Windows 11 24H2 and later, its automatic account management can create and manage the account for you. The legacy Microsoft LAPS installer is deprecated and blocked on Windows 11 23H2 and later.
Andy Malone, a Microsoft MVP, walks through Windows LAPS from policy to password retrieval here.
The usual worry is what happens if LAPS breaks and nobody can get in. This June 2026 thread asks exactly that. The replies point out that the password only changes once the directory confirms it has the new one, so a sync problem doesn't strand you.
Locked Out of Every Admin Account
If no working account on the PC is an administrator, go through the options in this order:
- Another admin account on the same PC, including a separate IT account.
- The LAPS password, read from Active Directory, Entra ID or Intune.
- Directory admins. On a domain PC, a domain admin. On an Entra-joined PC, a user with the Entra Joined Device Local Administrator role.
- Reset or reinstall. For an unmanaged PC with none of the above, Reset this PC or a clean install is the supported route. Have the BitLocker recovery key ready first.
Microsoft doesn't offer a supported way to promote an account from outside Windows. That's why steps 1 to 3 are worth setting up before anyone needs them. OpenFrame can run the Get-LocalGroupMember check as a script across a client's devices and collect the output, which turns "who is admin where" into one report instead of a remote session per PC.
The Short Version
To change administrator on Windows 11, go to Settings, Accounts, Other users, and use Change account type. From a prompt, net localgroup Administrators or Add-LocalGroupMember does the same, with AzureAD\ for Entra accounts. Add the new admin before removing the old one. On Entra-joined PCs, check who joined the device, and expect role changes to take up to 4 hours. Then keep the list short with separate admin accounts and Windows LAPS.
For how roles and permissions scale beyond one PC, read our guide to RBAC.
Conrad Lunderstedt
Solution Architect
I'm Conrad, Solution Architect at Flamingo. I've spent about 26 years in IT, roughly half of it inside MSPs and the rest in enterprise environments, so I've watched vendor decisions get made on both sides of that line. Now I spend my days talking with MSPs about the stack they already run, and helping them work through the requests and issues that come with it.
