How to Change Password on Windows Server 2016-2022

Change password on Windows Server 2016, 2019, or 2022 using RDP, Settings, Control Panel, or CMD, then verify access and fix common policy errors.
A glowing key and shield protect a Windows Server rack during a remote password change.

To change password on Windows Server, use the secure Windows Security screen or the Settings app while connected through RDP. This guide covers Windows Server 2016, 2019, and 2022, and you can finish the change and test the new credential in about five minutes.

Prerequisites

  • Windows Server 2016, Windows Server 2019, or Windows Server 2022 with the Desktop Experience installed.
  • An active RDP session or console session. You need the current password to change your own account; a local administrator is required to reset another local account.
  • A local or domain username, plus the domain name if the server is joined to Active Directory. Domain password rules can override local settings.
  • No special RAM or disk space is needed because this changes account metadata, not server files.
  • A Windows RDP VPS from VPSLake if you need a Windows Server environment for this procedure.

Step 1: Identify the account and open Windows Security

Use the secure-attention shortcut that matches the connection type so the password form opens on the server, not on your own computer.

Inside an RDP session, press Ctrl+Alt+End. Select Change a password. At the physical console, press Ctrl+Alt+Delete and choose the same option. Ctrl+Alt+End is the RDP equivalent of the local secure-attention sequence; Microsoft lists it in its Remote Desktop shortcut reference.

If you are unsure which identity is signed in, open Start, search for Command Prompt, and select Run as administrator only when your account has that permission. Run:

whoami

The result identifies the account and authority that will receive the new password:

SERVER_NAME\YOUR_USERNAME

The prefix before the backslash normally identifies the computer for a local account or the domain for a domain account. Record it before changing credentials, because the prefix helps you select the right account when you reconnect.

Step 2: Change your password from the RDP security screen

The secure screen is the best first choice because it works consistently across the three server releases and respects the account provider’s policy.

Select Change a password, enter the current password, and type the new password twice. Submit the form, then select OK or Finish when Windows confirms the change. Do not put the password in a note, command, or screenshot while you work.

Use a long, unique passphrase that is not reused for your email, VPSLake account, or another server. If the server belongs to a domain, the domain controller may enforce minimum length, complexity, password history, or minimum password age; a local administrator cannot bypass those domain rules from this screen.

Step 3: Change a local password in Settings or Control Panel

The graphical account page is useful when keyboard shortcuts are intercepted by the RDP client or when you are already working at the desktop.

Open Start → Settings → Accounts → Sign-in options. Expand Password, select Change, enter the current password, and provide the new password twice. Leave the hint blank or make it generic; a hint should never reveal part of the credential.

Some Windows Server builds expose fewer consumer-facing Settings pages. If Password → Change is absent, open Control Panel → User Accounts → Change your password and complete the same current-password and new-password fields. Microsoft describes the Settings workflow in its local account password guidance.

This route changes the signed-in account. It does not reset a different user and it does not change a domain account outside the policies and services that manage that domain.

Step 4: Reset another local account from an elevated prompt

Use this method only when you are an administrator resetting a local account and do not need to know that user’s old password.

Open Start, search for Command Prompt, select Run as administrator, and first list the local names if necessary:

net user

Then replace YOUR_USERNAME with the exact local account name and run:

net user YOUR_USERNAME *

Windows asks for the new password twice without displaying either entry. A successful reset returns:

Type a password for the user:
Retype the password to confirm:
The command completed successfully.

The asterisk is important: it prevents the password from appearing in the command line or shell history. This is a local-account reset; do not use it as a substitute for a domain administrator’s account-management procedure. Microsoft documents the command and its Server 2016, 2019, and 2022 support in the net user reference.

Verify the new Windows Server password

A confirmation dialog is not enough; prove that the new credential works in a fresh authentication attempt.

  1. Save any work, press Windows key + L, and sign in to the same account with the new password.
  2. If you manage the server over RDP, disconnect the session and start a new connection. Enter the account as SERVER_NAME\YOUR_USERNAME for a local account or DOMAIN\YOUR_USERNAME for a domain account.
  3. For a local account, check the recorded password-change time from an elevated Command Prompt:
net user YOUR_USERNAME

Look for Password last set with a recent time and Account active set to Yes. A successful lock-screen or RDP sign-in is the actual proof that the new password is accepted.

Troubleshooting

Ctrl+Alt+End opens a menu on your computer

The keystroke was captured by the local operating system or the RDP client is not in focus. Click inside the RDP window, use Ctrl+Alt+End again, and make the session full screen if needed. In a browser-based remote client, use its keyboard or secure-attention control to send Ctrl+Alt+Delete to the remote session.

“The password does not meet the password policy requirements”

The new value violates local policy or an Active Directory rule such as length, complexity, history, or minimum age. Use a longer passphrase that has not been used recently; if the message remains, ask the domain administrator for the effective policy instead of weakening server security.

“Access is denied” when using net user

The prompt is not elevated, or YOUR_USERNAME is a domain account rather than a local account. Reopen Command Prompt → Run as administrator, run net user to confirm the local names, and use the secure screen or domain administrator process for domain credentials.

RDP rejects the new password after it was accepted

The client may be sending an old saved credential, or the account is being identified with the wrong local/domain prefix. Close the connection, open Control Panel → Credential Manager → Windows Credentials on the client, remove the saved entry for the server, and reconnect with the correct username format.

Hardening after the password change

  • Store the new credential in a password manager and remove old copies from shared computers.
  • Keep RDP limited to trusted source IP addresses or a VPN where practical; never expose a management account with a weak or reused password.
  • Create a separate named administrator for routine work and use the built-in Administrator account only when the task requires it.

FAQ

Can I change a Windows Server password without ending my RDP session?

Usually, yes. The password change takes effect for the next authentication, while the current session normally remains open. Keep it open until you have confirmed a new RDP connection, so you retain a recovery path if a username or policy issue appears.

What is the difference between changing and resetting a password?

A normal change verifies the current password before accepting a replacement. A local administrator reset, such as net user YOUR_USERNAME *, can set a different local user’s password without knowing the old one; domain accounts follow domain administration rules.

Does this work on Windows Server 2016 as well as 2019 and 2022?

Yes. The RDP secure-attention shortcut and net user approach apply to all three versions. The Settings layout can vary, so Control Panel is the fallback when a Server 2016 or customized installation does not show the Password option.

What should I do if I forgot the current password?

You cannot complete a normal self-service change without proving the old credential. Ask another authorized local administrator to reset a local account, or contact the domain administrator for a domain account; do not try to bypass the sign-in system with untrusted recovery tools.

Samrat Ghosh
Written by

Samrat Ghosh

Founder & Infrastructure Engineer

Samrat Ghosh is the founder of VPSLake, where he builds and runs the remote desktop and VPS hosting infrastructure the company is built on. He writes hands-on guides about RDP, Windows Server, VPS management and secure remote access - the practical documentation he wishes had…

Previous Article

Block All Websites, Allow Specific Sites in Windows Server

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter

Subscribe to our email newsletter to get the latest posts delivered right to your email.
Pure inspiration, zero spam ✨