{"id":813,"date":"2026-10-11T18:00:00","date_gmt":"2026-10-11T18:00:00","guid":{"rendered":"https:\/\/vpslake.com\/blog\/?p=813"},"modified":"2026-10-11T18:00:00","modified_gmt":"2026-10-11T18:00:00","slug":"change-windows-server-2019-2022-password","status":"publish","type":"post","link":"https:\/\/vpslake.com\/blog\/2026\/10\/11\/change-windows-server-2019-2022-password\/","title":{"rendered":"How to Change the Administrator Password on Windows Server 2019\/2022"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">To change your Windows Server 2019 2022 administrator password, use the RDP secure-attention screen or the Desktop Experience, then test a fresh sign-in. The change takes about five minutes, and this guide also shows how an authorized local administrator can reset a different local account.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prerequisites<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Windows Server 2019 or Windows Server 2022. The Settings and Control Panel paths require the Desktop Experience; Server Core uses the command-line method below.<\/li>\n\n\n<li>An active RDP session or console connection. You need the current password to change your own account; an elevated local administrator account is required to reset another local account.<\/li>\n\n\n<li>The account name and scope: local accounts look like <code>SERVER_NAME\\Administrator<\/code>, while domain accounts use <code>DOMAIN\\USERNAME<\/code>. Domain password rules may be stricter than local policy.<\/li>\n\n\n<li>No special RAM or disk space is needed because changing a password updates account credentials rather than installing software.<\/li>\n\n\n<li>A Windows RDP VPS from <a href=\"https:\/\/vpslake.com\/buy-windows-rdp\">VPSLake<\/a> if you need a remote Windows Server environment for administration.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 1: Confirm the account and open Windows Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Identify the account first so you do not change a similarly named local or domain credential.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In an RDP session, click inside the remote desktop and press <code>Ctrl+Alt+End<\/code>. At the server&#8217;s console, press <code>Ctrl+Alt+Delete<\/code>. Select <strong>Change a password<\/strong> on the Windows Security screen. Microsoft lists <code>Ctrl+Alt+End<\/code> in its <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/termserv\/terminal-services-shortcut-keys\" target=\"_blank\" rel=\"noopener\">Remote Desktop Services shortcut reference<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are unsure which account is signed in, open <strong>Start<\/strong>, search for <strong>Windows PowerShell<\/strong>, and open it without elevation unless you specifically need an administrator prompt. Run:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>whoami<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For a local built-in Administrator account, the result resembles:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SERVER_NAME\\Administrator<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For a domain account, the prefix is normally the domain name. Keep that scope in mind when you reconnect, because <code>DOMAIN\\Administrator<\/code> and <code>SERVER_NAME\\Administrator<\/code> are different accounts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 2: Change the password for the signed-in account<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The secure screen is the most consistent method because it works across Windows Server 2019 and 2022 and asks for the existing credential before accepting a replacement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Select <strong>Change a password<\/strong>, enter the current password, enter the new password twice, and submit the form. Use a long, unique password that is not reused for your email, hosting account, or another server. Do not put the password in a command, password hint, screenshot, or support message.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the server is joined to Active Directory, Windows sends the change to the domain account provider when the domain is reachable. The domain controller can enforce minimum length, complexity, password history, and minimum password age; a local server setting cannot override those rules.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 3: Use Settings or Control Panel from the desktop<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The graphical path is useful when the RDP client captures the secure-attention shortcut or when you are already working at the server desktop.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Start \u2192 Settings \u2192 Accounts \u2192 Sign-in options \u2192 Password \u2192 Change<\/strong>. Enter the current password, provide the new password twice, and select <strong>Next<\/strong> followed by <strong>Finish<\/strong> when Windows presents those buttons.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Windows Server builds can expose a smaller Settings surface than Windows client editions. If <strong>Password \u2192 Change<\/strong> is missing, use <strong>Control Panel \u2192 User Accounts \u2192 Change your password<\/strong> instead. These paths change the account that is currently signed in; they do not reset another user&#8217;s password.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 4: Reset another local account from an elevated prompt<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use this route only when you are authorized to reset a local account and do not know its old password. It also works on Server Core, where Settings is unavailable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Start<\/strong>, search for <strong>Command Prompt<\/strong>, right-click it, and select <strong>Run as administrator<\/strong>. List local accounts if you need to confirm the exact name:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>net user<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Reset the built-in local Administrator account, or replace <code>Administrator<\/code> with the intended local username:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>net user Administrator *<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The asterisk makes Windows prompt for the new password without displaying it. A successful reset looks like this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Type a password for the user:\nRetype the password to confirm:\nThe command completed successfully.<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/administration\/windows-commands\/net-user\" target=\"_blank\" rel=\"noopener\"><code>net user<\/code> command reference<\/a> applies to Windows Server 2019 and 2022. Do not add <code>\/domain<\/code> unless you intentionally administer a domain account through the domain controller; for a normal VPS local account, leave that switch out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Verify the new Windows Server password<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Verify the credential with a new authentication attempt, not only the confirmation message from the password form.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, inspect the local account from the elevated prompt:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>net user Administrator<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The important fields should resemble:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Account active               Yes\nPassword last set            &lt;recent date and time&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The date and time will differ on your server. Save your work, disconnect the RDP session, and start a new connection using the new password. Enter a local account as <code>SERVER_NAME\\Administrator<\/code> or <code>.\\Administrator<\/code>; use <code>DOMAIN\\USERNAME<\/code> for a domain account. Keep the original session open until the new session succeeds so you do not remove your last working path into the server.<\/p>\n\n\n\n<aside class=\"vl-element vl-cta-banner\" aria-label=\"Need a Windows VPS?\">\n\t<div class=\"vl-cta-banner__content\">\n\t\t<p class=\"vl-cta-banner__eyebrow\">Windows server access<\/p>\n\t\t<h3 class=\"vl-cta-banner__title\">Need a Windows VPS?<\/h3>\n\t\t<p class=\"vl-cta-banner__text\">Get a Windows RDP server for remote administration and everyday desktop work.<\/p>\n\t<\/div>\n\t<a class=\"vl-cta-banner__button\" href=\"\/buy-windows-rdp\" aria-label=\"View Windows RDP\">View Windows RDP<\/a>\n<\/aside>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Ctrl+Alt+End affects the local computer<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The RDP window may not have keyboard focus, or the client may be intercepting the shortcut. Click inside the remote desktop, switch the connection to full screen, and try again. A browser-based RDP client may provide a <strong>Send Ctrl+Alt+Delete<\/strong> or secure-attention control; use that control to send the sequence to the server.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u201cThe password does not meet the password policy requirements\u201d<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The new value violates local policy or an Active Directory rule such as length, complexity, history, or minimum password age. Choose a longer unique passphrase that has not been used recently; if the message continues, ask the domain administrator for the effective policy instead of weakening security settings.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u201cAccess is denied\u201d or the account is not found<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The command window may not be elevated, or the name may belong to a domain rather than the local computer. Reopen <strong>Command Prompt \u2192 Run as administrator<\/strong>, run <code>net user<\/code> without a username to list local accounts, and use the secure screen or the domain administrator&#8217;s normal process for domain credentials.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">RDP rejects the new password after the change<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The RDP client may still be sending a saved password, or the username is using the wrong local\/domain prefix. On the connecting computer, open <strong>Control Panel \u2192 Credential Manager \u2192 Windows Credentials<\/strong>, remove the saved entry for this server, and reconnect with the correct username format. Also check that the account is not locked, disabled, or expired.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hardening after the password change<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Store the new credential in a password manager and remove old copies from shared computers.<\/li>\n\n\n<li>Restrict RDP to trusted source IP addresses or a VPN where practical, and avoid exposing an administrator account with a reused password.<\/li>\n\n\n<li>Create a separate named administrator for routine work and reserve the built-in Administrator account for tasks that require it.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Can I change the password without ending my RDP session?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Usually, yes. Windows normally keeps the current session open after a successful change, but the new password is used for later sign-ins. Test a second RDP connection before signing out so a username or policy mistake does not lock you out.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is the difference between changing and resetting a password?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A change verifies the current password before accepting a replacement. An authorized local administrator can reset another local account without knowing its old password, while domain accounts must follow the domain&#8217;s account-management rules.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can <code>net user<\/code> change a domain Administrator password?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Without <code>\/domain<\/code>, <code>net user<\/code> operates on the local computer, so it cannot reset a domain account. Domain credentials should be changed through the secure Windows screen or the domain administrator&#8217;s approved directory-management process.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What should I do if I forgot the current Administrator password?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You cannot complete a normal self-service change without proving the old credential. If another authorized local administrator exists, that account can reset the local Administrator password; otherwise use the provider&#8217;s approved console or recovery process, and avoid untrusted password-bypass tools.<\/p>\n\n\n\n<script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"mainEntity\": [{\"@type\": \"Question\", \"name\": \"Can I change the password without ending my RDP session?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Usually, yes. Windows normally keeps the current session open after a successful change, but the new password is used for later sign-ins. Test a second RDP connection before signing out so a username or policy mistake does not lock you out.\"}}, {\"@type\": \"Question\", \"name\": \"What is the difference between changing and resetting a password?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"A change verifies the current password before accepting a replacement. An authorized local administrator can reset another local account without knowing its old password, while domain accounts must follow the domain's account-management rules.\"}}, {\"@type\": \"Question\", \"name\": \"Can `net user` change a domain Administrator password?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Without `\/domain`, `net user` operates on the local computer, so it cannot reset a domain account. Domain credentials should be changed through the secure Windows screen or the domain administrator's approved directory-management process.\"}}, {\"@type\": \"Question\", \"name\": \"What should I do if I forgot the current Administrator password?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"You cannot complete a normal self-service change without proving the old credential. If another authorized local administrator exists, that account can reset the local Administrator password; otherwise use the provider's approved console or recovery process, and avoid untrusted password-bypass tools.\"}}]}<\/script>\n\n","protected":false},"excerpt":{"rendered":"Change your Windows Server 2019 2022 administrator password from RDP or the desktop, reset a local account safely, and verify the new sign-in.","protected":false},"author":1,"featured_media":814,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","footnotes":""},"categories":[5,11],"tags":[47,32,46,42],"class_list":["post-813","post","type-post","status-publish","format-standard","has-post-thumbnail","category-guides","category-windows-server","tag-administrator-password","tag-rdp","tag-server-security","tag-windows-server","cs-entry"],"_links":{"self":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/813","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/comments?post=813"}],"version-history":[{"count":1,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/813\/revisions"}],"predecessor-version":[{"id":3042,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/813\/revisions\/3042"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media\/814"}],"wp:attachment":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media?parent=813"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/categories?post=813"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/tags?post=813"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}