{"id":809,"date":"2026-10-11T09:00:00","date_gmt":"2026-10-11T09:00:00","guid":{"rendered":"https:\/\/vpslake.com\/blog\/?p=809"},"modified":"2026-10-11T09:00:00","modified_gmt":"2026-10-11T09:00:00","slug":"change-password-windows-server-2016-2022","status":"publish","type":"post","link":"https:\/\/vpslake.com\/blog\/2026\/10\/11\/change-password-windows-server-2016-2022\/","title":{"rendered":"How to Change Password on Windows Server 2016-2022"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">To change password on Windows Server, use the secure Windows Security screen or the Settings app while connected through RDP. This guide covers Windows Server 2016, 2019, and 2022, and you can finish the change and test the new credential in about five minutes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prerequisites<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Windows Server 2016, Windows Server 2019, or Windows Server 2022 with the Desktop Experience installed.<\/li>\n\n\n<li>An active RDP session or console session. You need the current password to change your own account; a local administrator is required to reset another local account.<\/li>\n\n\n<li>A local or domain username, plus the domain name if the server is joined to Active Directory. Domain password rules can override local settings.<\/li>\n\n\n<li>No special RAM or disk space is needed because this changes account metadata, not server files.<\/li>\n\n\n<li>A Windows RDP VPS from <a href=\"https:\/\/vpslake.com\/buy-windows-rdp\">VPSLake<\/a> if you need a Windows Server environment for this procedure.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 1: Identify the account and open Windows Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use the secure-attention shortcut that matches the connection type so the password form opens on the server, not on your own computer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Inside an RDP session, press <code>Ctrl+Alt+End<\/code>. Select <strong>Change a password<\/strong>. At the physical console, press <code>Ctrl+Alt+Delete<\/code> and choose the same option. <code>Ctrl+Alt+End<\/code> is the RDP equivalent of the local secure-attention sequence; Microsoft lists it in its <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/termserv\/terminal-services-shortcut-keys\" target=\"_blank\" rel=\"noopener\">Remote Desktop shortcut reference<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are unsure which identity is signed in, open <strong>Start<\/strong>, search for <strong>Command Prompt<\/strong>, and select <strong>Run as administrator<\/strong> only when your account has that permission. Run:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>whoami<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The result identifies the account and authority that will receive the new password:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SERVER_NAME\\YOUR_USERNAME<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The prefix before the backslash normally identifies the computer for a local account or the domain for a domain account. Record it before changing credentials, because the prefix helps you select the right account when you reconnect.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 2: Change your password from the RDP security screen<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The secure screen is the best first choice because it works consistently across the three server releases and respects the account provider&#8217;s policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Select <strong>Change a password<\/strong>, enter the current password, and type the new password twice. Submit the form, then select <strong>OK<\/strong> or <strong>Finish<\/strong> when Windows confirms the change. Do not put the password in a note, command, or screenshot while you work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use a long, unique passphrase that is not reused for your email, VPSLake account, or another server. If the server belongs to a domain, the domain controller may enforce minimum length, complexity, password history, or minimum password age; a local administrator cannot bypass those domain rules from this screen.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 3: Change a local password in Settings or Control Panel<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The graphical account page is useful when keyboard shortcuts are intercepted by the RDP client or when you are already working at the desktop.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Start \u2192 Settings \u2192 Accounts \u2192 Sign-in options<\/strong>. Expand <strong>Password<\/strong>, select <strong>Change<\/strong>, enter the current password, and provide the new password twice. Leave the hint blank or make it generic; a hint should never reveal part of the credential.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some Windows Server builds expose fewer consumer-facing Settings pages. If <strong>Password \u2192 Change<\/strong> is absent, open <strong>Control Panel \u2192 User Accounts \u2192 Change your password<\/strong> and complete the same current-password and new-password fields. Microsoft describes the Settings workflow in its <a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/security\/change-or-reset-your-local-account-password-in-windows\" target=\"_blank\" rel=\"noopener\">local account password guidance<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This route changes the signed-in account. It does not reset a different user and it does not change a domain account outside the policies and services that manage that domain.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 4: Reset another local account from an elevated prompt<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use this method only when you are an administrator resetting a local account and do not need to know that user&#8217;s old password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Start<\/strong>, search for <strong>Command Prompt<\/strong>, select <strong>Run as administrator<\/strong>, and first list the local names if necessary:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>net user<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Then replace <code>YOUR_USERNAME<\/code> with the exact local account name and run:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>net user YOUR_USERNAME *<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Windows asks for the new password twice without displaying either entry. A successful reset returns:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Type a password for the user:\nRetype the password to confirm:\nThe command completed successfully.<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The asterisk is important: it prevents the password from appearing in the command line or shell history. This is a local-account reset; do not use it as a substitute for a domain administrator&#8217;s account-management procedure. Microsoft documents the command and its Server 2016, 2019, and 2022 support in the <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/administration\/windows-commands\/net-user\" target=\"_blank\" rel=\"noopener\"><code>net user<\/code> reference<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Verify the new Windows Server password<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A confirmation dialog is not enough; prove that the new credential works in a fresh authentication attempt.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Save any work, press <code>Windows key + L<\/code>, and sign in to the same account with the new password.<\/li>\n\n\n<li>If you manage the server over RDP, disconnect the session and start a new connection. Enter the account as <code>SERVER_NAME\\YOUR_USERNAME<\/code> for a local account or <code>DOMAIN\\YOUR_USERNAME<\/code> for a domain account.<\/li>\n\n\n<li>For a local account, check the recorded password-change time from an elevated Command Prompt:<\/li>\n\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>net user YOUR_USERNAME<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Look for <code>Password last set<\/code> with a recent time and <code>Account active<\/code> set to <code>Yes<\/code>. A successful lock-screen or RDP sign-in is the actual proof that the new password is accepted.<\/p>\n\n\n\n<aside class=\"vl-element vl-cta-banner\" aria-label=\"Need a Windows VPS?\">\n\t<div class=\"vl-cta-banner__content\">\n\t\t<p class=\"vl-cta-banner__eyebrow\">Windows server access<\/p>\n\t\t<h3 class=\"vl-cta-banner__title\">Need a Windows VPS?<\/h3>\n\t\t<p class=\"vl-cta-banner__text\">Get a Windows RDP server for remote administration and everyday desktop work.<\/p>\n\t<\/div>\n\t<a class=\"vl-cta-banner__button\" href=\"\/buy-windows-rdp\" aria-label=\"View Windows RDP\">View Windows RDP<\/a>\n<\/aside>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Ctrl+Alt+End opens a menu on your computer<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The keystroke was captured by the local operating system or the RDP client is not in focus. Click inside the RDP window, use <code>Ctrl+Alt+End<\/code> again, and make the session full screen if needed. In a browser-based remote client, use its keyboard or secure-attention control to send <code>Ctrl+Alt+Delete<\/code> to the remote session.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u201cThe password does not meet the password policy requirements\u201d<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The new value violates local policy or an Active Directory rule such as length, complexity, history, or minimum age. Use a longer passphrase that has not been used recently; if the message remains, ask the domain administrator for the effective policy instead of weakening server security.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u201cAccess is denied\u201d when using <code>net user<\/code><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The prompt is not elevated, or <code>YOUR_USERNAME<\/code> is a domain account rather than a local account. Reopen <strong>Command Prompt \u2192 Run as administrator<\/strong>, run <code>net user<\/code> to confirm the local names, and use the secure screen or domain administrator process for domain credentials.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">RDP rejects the new password after it was accepted<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The client may be sending an old saved credential, or the account is being identified with the wrong local\/domain prefix. Close the connection, open <strong>Control Panel \u2192 Credential Manager \u2192 Windows Credentials<\/strong> on the client, remove the saved entry for the server, and reconnect with the correct username format.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hardening after the password change<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Store the new credential in a password manager and remove old copies from shared computers.<\/li>\n\n\n<li>Keep RDP limited to trusted source IP addresses or a VPN where practical; never expose a management account with a weak or reused password.<\/li>\n\n\n<li>Create a separate named administrator for routine work and use the built-in Administrator account only when the task requires it.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Can I change a Windows Server password without ending my RDP session?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Usually, yes. The password change takes effect for the next authentication, while the current session normally remains open. Keep it open until you have confirmed a new RDP connection, so you retain a recovery path if a username or policy issue appears.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is the difference between changing and resetting a password?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A normal change verifies the current password before accepting a replacement. A local administrator reset, such as <code>net user YOUR_USERNAME *<\/code>, can set a different local user&#8217;s password without knowing the old one; domain accounts follow domain administration rules.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Does this work on Windows Server 2016 as well as 2019 and 2022?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes. The RDP secure-attention shortcut and <code>net user<\/code> approach apply to all three versions. The Settings layout can vary, so Control Panel is the fallback when a Server 2016 or customized installation does not show the Password option.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What should I do if I forgot the current password?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You cannot complete a normal self-service change without proving the old credential. Ask another authorized local administrator to reset a local account, or contact the domain administrator for a domain account; do not try to bypass the sign-in system with untrusted recovery tools.<\/p>\n\n\n\n<script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"mainEntity\": [{\"@type\": \"Question\", \"name\": \"Can I change a Windows Server password without ending my RDP session?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Usually, yes. The password change takes effect for the next authentication, while the current session normally remains open. Keep it open until you have confirmed a new RDP connection, so you retain a recovery path if a username or policy issue appears.\"}}, {\"@type\": \"Question\", \"name\": \"What is the difference between changing and resetting a password?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"A normal change verifies the current password before accepting a replacement. A local administrator reset, such as `net user YOUR_USERNAME *`, can set a different local user's password without knowing the old one; domain accounts follow domain administration rules.\"}}, {\"@type\": \"Question\", \"name\": \"Does this work on Windows Server 2016 as well as 2019 and 2022?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Yes. The RDP secure-attention shortcut and `net user` approach apply to all three versions. The Settings layout can vary, so Control Panel is the fallback when a Server 2016 or customized installation does not show the Password option.\"}}, {\"@type\": \"Question\", \"name\": \"What should I do if I forgot the current password?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"You cannot complete a normal self-service change without proving the old credential. Ask another authorized local administrator to reset a local account, or contact the domain administrator for a domain account; do not try to bypass the sign-in system with untrusted recovery tools.\"}}]}<\/script>\n\n","protected":false},"excerpt":{"rendered":"Change password on Windows Server 2016, 2019, or 2022 using RDP, Settings, Control Panel, or CMD, then verify access and fix common policy errors.","protected":false},"author":1,"featured_media":810,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","footnotes":""},"categories":[5,11],"tags":[32,46,34,42],"class_list":["post-809","post","type-post","status-publish","format-standard","has-post-thumbnail","category-guides","category-windows-server","tag-rdp","tag-server-security","tag-windows-password","tag-windows-server","cs-entry"],"_links":{"self":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/809","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/comments?post=809"}],"version-history":[{"count":1,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/809\/revisions"}],"predecessor-version":[{"id":3040,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/809\/revisions\/3040"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media\/810"}],"wp:attachment":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media?parent=809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/categories?post=809"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/tags?post=809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}