To change your Windows Server 2019 2022 administrator password, use the RDP secure-attention screen or the Desktop Experience, then test a fresh sign-in. The change takes about five minutes, and this guide also shows how an authorized local administrator can reset a different local account.
Prerequisites
- Windows Server 2019 or Windows Server 2022. The Settings and Control Panel paths require the Desktop Experience; Server Core uses the command-line method below.
- An active RDP session or console connection. You need the current password to change your own account; an elevated local administrator account is required to reset another local account.
- The account name and scope: local accounts look like
SERVER_NAME\Administrator, while domain accounts useDOMAIN\USERNAME. Domain password rules may be stricter than local policy. - No special RAM or disk space is needed because changing a password updates account credentials rather than installing software.
- A Windows RDP VPS from VPSLake if you need a remote Windows Server environment for administration.
Step 1: Confirm the account and open Windows Security
Identify the account first so you do not change a similarly named local or domain credential.
In an RDP session, click inside the remote desktop and press Ctrl+Alt+End. At the server’s console, press Ctrl+Alt+Delete. Select Change a password on the Windows Security screen. Microsoft lists Ctrl+Alt+End in its Remote Desktop Services shortcut reference.
If you are unsure which account is signed in, open Start, search for Windows PowerShell, and open it without elevation unless you specifically need an administrator prompt. Run:
whoami
For a local built-in Administrator account, the result resembles:
SERVER_NAME\Administrator
For a domain account, the prefix is normally the domain name. Keep that scope in mind when you reconnect, because DOMAIN\Administrator and SERVER_NAME\Administrator are different accounts.
Step 2: Change the password for the signed-in account
The secure screen is the most consistent method because it works across Windows Server 2019 and 2022 and asks for the existing credential before accepting a replacement.
Select Change a password, enter the current password, enter the new password twice, and submit the form. Use a long, unique password that is not reused for your email, hosting account, or another server. Do not put the password in a command, password hint, screenshot, or support message.
If the server is joined to Active Directory, Windows sends the change to the domain account provider when the domain is reachable. The domain controller can enforce minimum length, complexity, password history, and minimum password age; a local server setting cannot override those rules.
Step 3: Use Settings or Control Panel from the desktop
The graphical path is useful when the RDP client captures the secure-attention shortcut or when you are already working at the server desktop.
Open Start → Settings → Accounts → Sign-in options → Password → Change. Enter the current password, provide the new password twice, and select Next followed by Finish when Windows presents those buttons.
Windows Server builds can expose a smaller Settings surface than Windows client editions. If Password → Change is missing, use Control Panel → User Accounts → Change your password instead. These paths change the account that is currently signed in; they do not reset another user’s password.
Step 4: Reset another local account from an elevated prompt
Use this route only when you are authorized to reset a local account and do not know its old password. It also works on Server Core, where Settings is unavailable.
Open Start, search for Command Prompt, right-click it, and select Run as administrator. List local accounts if you need to confirm the exact name:
net user
Reset the built-in local Administrator account, or replace Administrator with the intended local username:
net user Administrator *
The asterisk makes Windows prompt for the new password without displaying it. A successful reset looks like this:
Type a password for the user:
Retype the password to confirm:
The command completed successfully.
The net user command reference applies to Windows Server 2019 and 2022. Do not add /domain unless you intentionally administer a domain account through the domain controller; for a normal VPS local account, leave that switch out.
Verify the new Windows Server password
Verify the credential with a new authentication attempt, not only the confirmation message from the password form.
First, inspect the local account from the elevated prompt:
net user Administrator
The important fields should resemble:
Account active Yes
Password last set <recent date and time>
The date and time will differ on your server. Save your work, disconnect the RDP session, and start a new connection using the new password. Enter a local account as SERVER_NAME\Administrator or .\Administrator; use DOMAIN\USERNAME for a domain account. Keep the original session open until the new session succeeds so you do not remove your last working path into the server.
Troubleshooting
Ctrl+Alt+End affects the local computer
The RDP window may not have keyboard focus, or the client may be intercepting the shortcut. Click inside the remote desktop, switch the connection to full screen, and try again. A browser-based RDP client may provide a Send Ctrl+Alt+Delete or secure-attention control; use that control to send the sequence to the server.
“The password does not meet the password policy requirements”
The new value violates local policy or an Active Directory rule such as length, complexity, history, or minimum password age. Choose a longer unique passphrase that has not been used recently; if the message continues, ask the domain administrator for the effective policy instead of weakening security settings.
“Access is denied” or the account is not found
The command window may not be elevated, or the name may belong to a domain rather than the local computer. Reopen Command Prompt → Run as administrator, run net user without a username to list local accounts, and use the secure screen or the domain administrator’s normal process for domain credentials.
RDP rejects the new password after the change
The RDP client may still be sending a saved password, or the username is using the wrong local/domain prefix. On the connecting computer, open Control Panel → Credential Manager → Windows Credentials, remove the saved entry for this server, and reconnect with the correct username format. Also check that the account is not locked, disabled, or expired.
Hardening after the password change
- Store the new credential in a password manager and remove old copies from shared computers.
- Restrict RDP to trusted source IP addresses or a VPN where practical, and avoid exposing an administrator account with a reused password.
- Create a separate named administrator for routine work and reserve the built-in Administrator account for tasks that require it.
FAQ
Can I change the password without ending my RDP session?
Usually, yes. Windows normally keeps the current session open after a successful change, but the new password is used for later sign-ins. Test a second RDP connection before signing out so a username or policy mistake does not lock you out.
What is the difference between changing and resetting a password?
A change verifies the current password before accepting a replacement. An authorized local administrator can reset another local account without knowing its old password, while domain accounts must follow the domain’s account-management rules.
Can net user change a domain Administrator password?
Without /domain, net user operates on the local computer, so it cannot reset a domain account. Domain credentials should be changed through the secure Windows screen or the domain administrator’s approved directory-management process.
What should I do if I forgot the current Administrator password?
You cannot complete a normal self-service change without proving the old credential. If another authorized local administrator exists, that account can reset the local Administrator password; otherwise use the provider’s approved console or recovery process, and avoid untrusted password-bypass tools.