Changing a password in Windows 11 or Windows 10 is straightforward—until the sign-in method on the PC is mistaken for the account type behind it. The right procedure depends on whether the device uses a local account, a personal Microsoft account, or a work or school account managed by an organization. Knowing that distinction prevents the most common failure: resetting a password successfully in one place, only to find that Windows is still asking for a different credential.
A Windows password is also not the same thing as a Windows Hello PIN, fingerprint, facial-recognition profile, browser-saved password, or Credential Manager entry. Each has a different purpose and reset path. This guide explains how to change or reset a Windows password safely, recover access when the password has been forgotten, and avoid security shortcuts that can create bigger problems than the original lockout.

A laptop displays a Windows 11 sign-in screen with account choices, password entry, biometrics, and recovery options.Understand Which Password Windows Is Asking For​

Before changing anything, identify how the account is connected to the computer. The account type determines where the password lives and where it must be changed.

Local account​

A local account exists only on one PC. Its username may be a simple name rather than an email address, and its password is stored on that individual device.
Changing a local-account password affects only that Windows installation. It does not change passwords for Outlook, OneDrive, Xbox, Microsoft 365, or any other online service.

Personal Microsoft account​

A personal Microsoft account usually uses an email address associated with services such as Outlook.com, Hotmail, Xbox, OneDrive, Skype, or the broader Microsoft account dashboard.
If Windows is signed in with this type of account, changing the Microsoft account password changes the password used across Microsoft’s connected consumer services. The PC may continue to accept a Windows Hello PIN after the password is updated, but the underlying account password has still changed.

Work or school account​

A work or school account is issued by an employer, university, or other organization. These accounts are typically managed through Microsoft Entra ID, Active Directory, Microsoft 365, or a hybrid identity system.
The organization may impose password length, history, complexity, expiration, multifactor authentication, and self-service reset requirements. In some environments, users can change passwords themselves; in others, only IT staff can do it.

PIN versus password​

A Windows Hello PIN is separate from the password. It is generally tied to a specific device and backed by the device’s security hardware when supported. It is not a replacement password that can be reused to sign into an online Microsoft account from another computer.
If the Windows sign-in screen accepts a PIN, changing the account password is still important when there is a reason to suspect the password has been exposed. If the PIN itself has been forgotten, use the I forgot my PIN option at the sign-in screen or in Settings > Accounts > Sign-in options rather than resetting the account password unnecessarily.

Change a Windows Password When You Know the Current One​

For most signed-in users, the easiest path begins in the Settings app. This works in both Windows 11 and Windows 10, although small visual differences may exist between versions and updates.
  1. Open Start.
  2. Select Settings.
  3. Open Accounts.
  4. Select Sign-in options.
  5. Expand Password.
  6. Select Change.
  7. Enter the current password.
  8. Create and confirm the new password.
  9. Finish the prompts.
For a local account, this replaces the password stored on the computer. For a Microsoft account, Windows may direct the user through Microsoft account verification before completing the change.

Why Settings is the preferred route​

Settings provides the clearest account-aware experience. It keeps the change process within Windows and helps prevent a user from accidentally editing unrelated credentials, such as a browser password or a saved network sign-in.
The interface also groups related options together, including:
  • Windows Hello PIN
  • Fingerprint recognition
  • Facial recognition
  • Security keys
  • Dynamic Lock
  • Additional sign-in settings
That makes it easier to see whether the device uses a password, a PIN, or biometric authentication for day-to-day access.

Use Ctrl + Alt + Del for a Traditional Password Change​

The familiar Windows security screen remains a practical alternative for changing a password while signed in.
  1. Press Ctrl + Alt + Del.
  2. Select Change a password.
  3. Enter the existing password.
  4. Enter and confirm the new password.
  5. Complete the change.
This route can be particularly useful on business computers, domain-connected devices, remote desktops, and systems where the Settings interface is restricted or managed differently.
However, the option may not appear in every situation. Device policies, sign-in configuration, remote-session behavior, and account type can affect what is available. If Change a password is missing, use Settings for a personal or local account, or the organization’s designated account portal for a managed work or school account.

Change a Personal Microsoft Account Password Online​

A personal Microsoft account can be updated from any web browser, including a phone, tablet, another computer, or the affected Windows PC.
This is the correct route when the Windows sign-in uses an email-based Microsoft account and the existing password is still known.
  1. Sign in to the Microsoft account dashboard.
  2. Open the Security section.
  3. Choose Change password.
  4. Verify the account if prompted.
  5. Enter the existing password.
  6. Create and save the new password.
Because this is an account-wide change, it can affect sign-in requests in services tied to the same account. Expect to sign in again on some devices, applications, browsers, gaming consoles, or Microsoft services after changing the password.

What happens on the Windows PC afterward​

Windows may not immediately demand the new password if the user normally signs in with a PIN, fingerprint, or face recognition. That does not mean the password change failed.
The new password is still required when:
  • Windows needs the account password for verification.
  • The user chooses the password sign-in method.
  • A new PC is set up with the same Microsoft account.
  • Microsoft services request fresh authentication.
  • A security-sensitive account change requires confirmation.
For laptops and tablets, it is wise to connect to the internet after changing a Microsoft account password online. This gives Windows an opportunity to synchronize the updated credential state.

Reset a Forgotten Microsoft Account Password​

When the password is unknown, do not repeatedly guess. Multiple failed attempts can trigger security checks, temporary lockouts, or additional verification requirements.
Instead, use Microsoft’s password reset process from a browser or from the Windows sign-in screen.

Reset from a browser​

  1. Open the Microsoft account sign-in or password reset page.
  2. Select Forgot password or Forgotten your password?
  3. Enter the email address, phone number, or username associated with the account.
  4. Choose an available verification method.
  5. Request a verification code.
  6. Enter the code.
  7. Create a new password.
  8. Complete the reset process.
Verification methods can include an authenticator app, recovery email address, phone number, or another previously registered security method. Availability depends on what was configured before the lockout.

Reset from the Windows sign-in screen​

At the Windows login screen, choose I forgot my password when it appears under a Microsoft account sign-in. Follow the identity-verification prompts and set a new password.
Some Windows configurations also expose a Web sign-in method under Sign-in options. This can be useful when standard authentication is not proceeding normally, although it is typically available only on appropriately configured devices.

Recovery limitations matter​

Microsoft account recovery is deliberately strict. If account ownership cannot be verified, there is no legitimate shortcut that bypasses the process.
Security tools, registry edits, bootable utilities, and social-media “recovery” claims should be treated with extreme skepticism. A password reset mechanism that appears to bypass identity verification may compromise the account, the device, or both.

Reset a Forgotten Local Account Password​

A local account cannot be reset through the Microsoft account website because it is not connected to Microsoft’s online identity service. Recovery depends on which protections were prepared in advance and whether another administrator account exists on the PC.

Use security questions from the sign-in screen​

If security questions were set up when the local account was created, Windows can offer a built-in recovery route.
  1. At the Windows sign-in screen, select the local account.
  2. Enter an incorrect password if necessary to reveal recovery options.
  3. Select OK.
  4. Choose Reset password.
  5. Answer the configured security questions.
  6. Create and confirm a new password.
  7. Sign in with the new password.
This procedure is secure only to the degree that the security-question answers are private and difficult to guess. Answers based on publicly visible social-media details, common family facts, or easily researched information weaken the account’s protection.

Use a password reset disk​

A password reset disk is a USB-based recovery method for a local Windows account. It must be created before the password is forgotten.
To create one:
  1. Sign in to the local account.
  2. Insert a USB flash drive.
  3. Search Windows for Control Panel and open it.
  4. Search within Control Panel for create password reset.
  5. Select Create a password reset disk.
  6. Follow the Forgotten Password Wizard.
  7. Store the USB drive securely.
A useful advantage is that the disk does not need to be recreated every time the local account password changes. The same reset disk remains valid for that account unless it is no longer available or the account is removed.
The obvious risk is physical access. Anyone who obtains both the reset disk and access to the PC may be able to use it to reset that local account’s password. Store it separately from the computer and avoid labeling it in a way that identifies the account or device.

When no recovery option exists​

If a local password has been forgotten and there are no security questions, no password reset disk, and no separate administrator account, the supported recovery options are limited. Resetting or reinstalling Windows may be necessary.
That outcome can affect installed programs, settings, and local data. Before resetting a device, verify whether important files are already backed up to external storage, OneDrive, another user profile, or a managed corporate backup system.

Reset Another Local User’s Password with an Administrator Account​

On a shared family PC or small office workstation, an existing administrator account can reset another local account’s password.
  1. Sign in with an administrator account.
  2. Search for and open Computer Management.
  3. Expand Local Users and Groups.
  4. Select Users.
  5. Right-click the local user account.
  6. Select Set Password.
  7. Confirm the warning.
  8. Enter and confirm the new password.
This is useful when a parent, technician, or designated PC administrator must restore access for another local user.

Important consequences of an administrator reset​

An administrator can set a new password, but this is not identical to a user changing their own password while knowing the old one. Resetting a password can make certain protected data inaccessible, particularly data encrypted with user-specific credentials.
For that reason, do not use this approach casually. It is best suited to situations where the administrator is authorized to manage the account and understands the possibility of losing access to encrypted files, stored credentials, or other protected items.

Windows Home limitations​

The Local Users and Groups console is generally unavailable in Windows Home editions. That is a product limitation, not a sign that the account cannot be managed at all.
Windows Home users may need to use Settings, the local-account recovery screen, another supported administrator-management route, or a device reset depending on the scenario. Avoid downloading unofficial “enablers” or modified system components simply to expose a management console. Such tools can create servicing, security, and support problems.

Change a Work or School Password​

Work and school accounts should be managed through the organization’s approved process. A password might be associated with Microsoft 365, Microsoft Entra ID, an on-premises Active Directory domain, a virtual desktop environment, a VPN, or a combination of systems.
For a password that is still known, a common route is the organization’s My Account portal.
  1. Sign in to the work or school account portal.
  2. Open the password-management area.
  3. Select Change password.
  4. Enter the old password.
  5. Enter and confirm the new password.
  6. Submit the change.
  7. Sign in again where prompted.
Organizations may require a lengthy password, disallow previous passwords, reject predictable phrases, or require multifactor authentication to complete the change.

Reset a forgotten work or school password​

If the password is forgotten, begin at the organization’s sign-in or security-information portal and choose Can’t access your account? or the equivalent recovery option.
Self-service password reset works only when the organization has enabled it and the user previously registered valid recovery methods. Depending on policy, verification may require one or more of the following:
  • Microsoft Authenticator approval or code
  • A registered phone number
  • SMS verification
  • A backup email address
  • Security questions, where permitted
  • A hardware security key
  • Another managed verification method
If the reset option is unavailable, contact the organization’s help desk or IT administrator. That is not a failure of Windows; it often reflects a deliberate company security policy, particularly in regulated or high-risk environments.

Domain and hybrid identity complications​

Some business PCs use passwords synchronized between cloud and on-premises systems. In those environments, password changes may take time to propagate, or the user may need to connect to the company network or VPN before all resources recognize the new credential.
After a corporate password change, update saved credentials carefully in applications that continue to prompt for the old password. Common examples include Outlook, Teams, mapped network drives, VPN clients, remote desktop connections, and Wi-Fi profiles using enterprise authentication.

Do Not Confuse Password Management with Saved Credentials​

Several Windows features store credentials, but they do not change the Windows account password.

Credential Manager​

Credential Manager stores saved usernames and passwords for websites, networks, remote computers, and applications. Removing an entry can resolve repeated sign-in prompts or outdated saved credentials, but it does not reset the Windows login password.

Browser password managers​

Chrome, Edge, Firefox, and third-party password managers save website passwords. Updating a password inside a browser does not update the password for the Windows account unless the same account is being changed through the proper Microsoft or organizational website.

Windows Hello​

Windows Hello lets users sign in with a PIN, face, fingerprint, or security key. It can make day-to-day Windows access faster and more resistant to some password-theft scenarios, but it does not eliminate the need to protect and recover the underlying account properly.
For personal Microsoft accounts, Windows includes an option under Settings > Accounts > Sign-in options to allow only Windows Hello sign-in on that device. In Windows 11, the option is labeled For improved security, only allow Windows Hello sign-in for Microsoft accounts on this device. Windows 10 uses similar wording beginning with Require Windows Hello sign-in.
Turning on this setting removes password sign-in on that device for the Microsoft account. It does not change the Microsoft account password, and it does not mean the password can be forgotten permanently.

Build a Better Password Strategy​

Changing a password only improves security if the replacement is stronger and is not being reused elsewhere.

Use a long, unique passphrase​

A strong password does not need to be a random-looking string that is impossible to type. A long, unique passphrase can be easier to remember and harder to crack than a short password with predictable symbol substitutions.
Good practices include:
  • Use a password that is unique to the account.
  • Prefer length over superficial complexity.
  • Avoid names, birthdays, addresses, sports teams, and public biographical details.
  • Do not reuse an old password with a small variation.
  • Do not store passwords in unprotected text files or sticky notes.
  • Use a reputable password manager for unique credentials where appropriate.
  • Enable multifactor authentication on personal Microsoft and work accounts.

Change passwords for the right reasons​

Routine password changes are not always the strongest security practice if they encourage minor variations such as Summer2026! becoming Summer2027!. A password should be changed promptly when there is a suspected compromise, phishing incident, shared-device concern, unexpected sign-in alert, malware exposure, or data breach affecting a reused password.
For work accounts, follow organizational requirements even when they mandate periodic changes. Those policies may be linked to specific risk, compliance, or technical controls.

A Safer Way to Regain and Keep Access​

The most reliable approach is to prepare before a lockout occurs. A Windows device should have more than one legitimate recovery path.
For a personal Microsoft account, keep recovery contact methods current and protect them with multifactor authentication. For a local account, configure security questions carefully and consider creating a password reset disk. For a work or school account, register approved security methods and know the organization’s support process before an urgent lockout happens.
The central rule remains simple: change the credential that matches the account type actually used by Windows. Use Settings for a known Windows password, Microsoft’s account recovery for personal online accounts, the sign-in screen for eligible local-account recovery, and the organization’s portal or IT team for business-managed identities. That approach protects access without relying on risky shortcuts, unsupported workarounds, or changes that solve the wrong problem.

References​

  1. Primary source: Technobezz
    Published: 2026-07-23T19:24:22.590000+00:00
  2. Official source: support.microsoft.com