Disable Or Re-Enable Local Windows Account Without Deleting Its Profile

Xploit Machine

私の人生の中で孤独な旅人
Administrator
Joined
Nov 29, 2022
Messages
1,386
Reaction score
123
You can disable an unused local Windows account without deleting its profile or files by using Computer Management: open Local Users and Groups > Users, open the account’s Properties, select Account is disabled, then choose Apply and OK. The account can be enabled later by clearing the same check box. This graphical method applies to Windows 11 Pro, Enterprise, and Education, plus equivalent Windows 10 editions that include the Local Users and Groups snap-in. Windows 10 Home and Pro reached end of support on October 14, 2025; the procedure may still work on existing installations, but unsupported PCs should be moved to a supported Windows release. Windows Home editions do not include the Local Users and Groups console, so use the supported net user command instead.
​
146403-871af27e1a0fa2a0b0ee271f9a8a8b7d.jpg

Disabling is safer than deleting when you are unsure whether an account will be needed again. A disabled local account cannot sign in or use resources on the PC, but its user profile remains in place until you deliberately remove it.
​

Check the account before disabling it​

Before changing an account, make sure it is genuinely an unused local account and not the account you are currently using.​
  • Sign in using a different administrator account. You need administrative rights to change another account’s status.​
  • Keep at least one known, working administrator account enabled. If you disable every administrator account, you may be unable to make future administrative changes.​
  • Make sure you know the account name exactly. An account’s display name and sign-in name can differ.​
  • Do not disable an account merely because it looks unfamiliar. Some accounts are built into Windows or are created for specific features. In particular, leave system-created accounts alone unless you know why they exist and what depends on them.​
  • If the PC belongs to an employer, school, or other organization, do not use this method to manage a domain or Microsoft Entra account. Contact the organization’s IT administrator instead.​
Warning: Do not disable the account you are signed in with. Also avoid disabling the only remaining local administrator account. Create or verify another administrator account first if there is any doubt.​

For a quick command-line review of the local accounts on the computer, open Windows Terminal or Command Prompt and run:

net user

This lists local user accounts. To inspect one account in more detail, run:

net user "AccountName"

Replace AccountName with the exact local account name. Review the result before making any change, particularly if you are deciding whether an account has been used recently or is active.
​
 

Xploit Machine

私の人生の中で孤独な旅人
Administrator
Joined
Nov 29, 2022
Messages
1,386
Reaction score
123

Disable a local account in Computer Management​

Use this method when your edition of Windows includes Local Users and Groups.​
  1. Save work and ensure that you are signed in with an administrator account that is not the account you intend to disable.​
  2. Open Computer Management:
    • Right-click the Start button and select Computer Management; or​
    • Open Start, search for Computer Management, and select the desktop app.​
  3. In the left navigation pane, expand:
    System Tools > Local Users and Groups > Users
    ​
  4. Review the entries in the central pane. Each entry is a local user account on this PC.​
  5. Right-click the account you no longer need and select Properties.​
  6. On the General tab, select the Account is disabled check box.
    Do not change password, group membership, or other settings unless that is part of a separate, planned task.
    ​
  7. Select Apply, then select OK.​
  8. Close Computer Management.​
The change takes effect without a restart step. However, do not treat disabling an account as a way to manage an active session in progress. If the account is currently in use, sign out of that account before relying on the change as an access control.​
 

Xploit Machine

私の人生の中で孤独な旅人
Administrator
Joined
Nov 29, 2022
Messages
1,386
Reaction score
123

Confirm that the account is disabled​

There are two straightforward ways to verify the result.
​

Check in Computer Management​

  1. Return to Computer Management.​
  2. Browse to System Tools > Local Users and Groups > Users.​
  3. Locate the account you changed.​
A disabled account is marked with a down-arrow overlay on its user icon. You can also double-click the account and confirm that Account is disabled remains selected.​

Check with the net user command​

  1. Open Windows Terminal (Admin) or Command Prompt (Admin).​
  2. Run:
    net user "AccountName"
    ​
  3. Review the account details and confirm that its active status is set to No.​
Use the exact local account name, including spaces when present. Quotation marks prevent names with spaces from being interpreted as separate words.
​
 

Xploit Machine

私の人生の中で孤独な旅人
Administrator
Joined
Nov 29, 2022
Messages
1,386
Reaction score
123

Re-enable the account later​

Re-enabling a disabled local account does not restore a forgotten password or undo changes made to its group membership. It simply allows the account to sign in again, provided it still has valid sign-in credentials.​
  1. Sign in with a different administrator account.​
  2. Open Computer Management.​
  3. Go to:
    System Tools > Local Users and Groups > Users
    ​
  4. Double-click the disabled account.​
  5. Clear the Account is disabled check box.​
  6. Select Apply, then OK.​
  7. Sign out or switch users and test the restored account’s sign-in normally.​
The account’s down-arrow overlay should disappear once it is enabled.​
 

Xploit Machine

私の人生の中で孤独な旅人
Administrator
Joined
Nov 29, 2022
Messages
1,386
Reaction score
123

Windows Home - disable the account with net user​

Windows Home editions do not provide the Local Users and Groups node in Computer Management. Do not download unofficial tools or attempt to add unsupported management consoles just to disable an account. Use the built-in command instead.
​

Disable an account​

  1. Sign in with an administrator account other than the account you plan to disable.​
  2. Right-click Start and select Terminal (Admin). On some Windows 10 installations, select Windows PowerShell (Admin) or Command Prompt (Admin) instead.​
  3. List local accounts if you need to confirm the exact name:
    net user
    ​
  4. Disable the chosen local account:
    net user "AccountName" /active:no
    For example:
    net user "OldUser" /active:no
    ​
  5. Windows should report that the command completed successfully.​
  6. Verify the change:
    net user "AccountName"
    Confirm that the account’s active status is no longer enabled.
    ​

​

Re-enable an account on Windows Home​

Open an elevated Terminal or Command Prompt and run:

net user "AccountName" /active:yes

Then verify it:

net user "AccountName"

This command changes only whether the account is active. It does not reset the password, add the account to an administrator group, or repair a damaged profile.
​
 

Xploit Machine

私の人生の中で孤独な旅人
Administrator
Joined
Nov 29, 2022
Messages
1,386
Reaction score
123

Troubleshoot common problems​

“Local Users and Groups” is missing from Computer Management​

This is expected on Windows Home. Use the net user method described above.

If you use Windows Pro, Enterprise, or Education and the node is missing, first confirm the Windows edition at Settings > System > About > Windows specifications. If the device is managed by an organization, administrative tools or account settings may also be controlled by policy.
​

The “Account is disabled” option is unavailable or changes do not save​

You are probably not using an administrator account, or Computer Management was not opened with sufficient administrative permission.
​
  • Sign out and use a known local administrator account.​
  • When Windows asks for permission through User Account Control, select Yes.​
  • If the PC is organization-managed, ask IT whether a policy manages local accounts.​

“System error 5 has occurred. Access is denied.”​

The Terminal or Command Prompt was not opened with administrative rights.
​
  1. Close the current window.​
  2. Right-click Start.​
  3. Select Terminal (Admin), Windows PowerShell (Admin), or Command Prompt (Admin).​
  4. Approve the User Account Control prompt.​
  5. Run the command again.​

The command says the user name cannot be found​

Confirm that you are using the local account name rather than the person’s full name, Microsoft account email address, or profile-folder name.

Run:

net user

Then copy the account name from the list. If it contains spaces, retain the quotation marks around it:

net user "Example User" /active:no
​

The account still appears on the sign-in screen​

An account tile may remain visible even after the account is disabled. The important test is whether Windows permits that account to sign in. Confirm the account status with:

net user "AccountName"

If the active status is disabled, do not delete the profile just because the account is still displayed. Deleting a user account or profile is a separate, permanent cleanup task and should only be done after you have confirmed that its files are no longer needed.
​

You disabled the wrong account​

Sign in with another administrator account and reverse the change immediately:

net user "AccountName" /active:yes

Or, in Computer Management, clear Account is disabled in that user’s Properties window.

If you accidentally disabled the only account with administrator access and cannot sign in with another administrator, do not attempt password-bypass tools or registry edits. Use your organization’s recovery process on managed devices. For a personal device, use Microsoft’s supported Windows account recovery or device reset options, understanding that a reset can affect installed applications and local data.
​
 
Top