Being locked out of your own laptop is a bad afternoon. You know the machine is yours, the files on it are yours, and none of that helps at a sign-in screen that will not accept anything you type.
This guide covers the routes back into a Windows laptop you own. Which one applies depends on two things people rarely check first: whether you sign in with a Microsoft account or a local account, and whether the drive is encrypted. On laptops sold in the last couple of years, the second answer is usually yes, and it rules out most of the tricks older guides still recommend.
This is for a machine you own. Everything here assumes you can prove the laptop is yours — you set up the Microsoft account on it, or you have the purchase receipt. Using these methods on someone else’s laptop, a work-issued machine, or a device you bought secondhand while still locked is unauthorized access, and on a managed or Entra-joined laptop your IT administrator is the only person who can help. Microsoft states plainly that support cannot retrieve or circumvent a lost or forgotten password for you.
What’s Inside
- 1 – First, Work Out Which Account You Are Locked Out Of
- 2 – Reset a Microsoft Account Password From Another Device
- 3 – Security Questions for a Local Account
- 4 – Why BitLocker Defeats Most Password Reset Tricks
- 5 – The Command Prompt and net user Route
- 6 – The Recovery Media Method and Its Hard Limit
- 7 – Windows Hello Fingerprint and Face Sign-In
- 8 – Resetting the Laptop When Nothing Else Works
- 9 – Third-Party Password Recovery Tools
- 10 – How to Avoid Being Locked Out Next Time
- 11 – Final Thoughts on Getting Back Into a Locked Laptop
First, Work Out Which Account You Are Locked Out Of
Look at the sign-in screen. If it shows an email address under your name, that is a Microsoft account and the fix is an online reset that takes about five minutes. If it shows only a name with no email, it is a local account, and your options are narrower.
Also check what the box is actually asking for. Windows Hello PINs are per-device and separate from the account password, so “I forgot my PIN” is a different and much easier problem — there is an I forgot my PIN link directly under the field.
- Microsoft account: reset online from any other device. Nothing on the laptop needs to change.
- Local account: security questions if you set them, otherwise a reset of the machine.
- Work or school account: your organization’s IT desk. Consumer methods do not apply and may be blocked outright.
Reset a Microsoft Account Password From Another Device
This is the route that works most often, because most Windows 11 laptops are set up with a Microsoft account during the out-of-box experience. The password lives on Microsoft’s servers, not on the laptop, so you reset it elsewhere and then sign in normally.
- On a phone or another computer, open Microsoft’s account password reset page.
- Enter the email address, phone number or Skype name you sign in with.
- Choose where to receive the security code — the recovery email or phone number attached to the account.
- Enter the code, then set a new password.
- Go back to the laptop and sign in with the new password. It needs an internet connection to check the new credentials the first time, so connect to Wi-Fi at the sign-in screen using the network icon in the corner.

Microsoft also documents two ways to start this from the laptop itself: the I forgot my password link on the sign-in screen, and Sign-in options > Web sign-in, which opens a browser window at the sign-in screen so you can complete the reset without a second device. Both need the laptop online.
If you cannot receive the security code because the recovery phone or email is long gone, Microsoft’s account recovery form is the only remaining path, and it can take days. That is the point at which a Microsoft account stops being the easy option.
Security Questions for a Local Account
Local accounts created on Windows 10 version 1803 and later prompt you to set three security questions. If you answered them at setup, they are your way back in and no tools are needed.
- Enter a wrong password once so the Reset password link appears.
- Select the arrow next to the password field, choose OK, then Reset password.
- Answer the three questions you set when the account was created.
- Type a new password and sign in.
Those are Microsoft’s documented steps for resetting a Windows local account password. The catch is that the questions are optional on accounts created by other routes, and an account upgraded from an older Windows version may have none. If the Reset password link never appears, there are none set.
Why BitLocker Defeats Most Password Reset Tricks
This is the part that has changed most since 2022, and it is the part most competing guides still leave out. Every offline password reset method works the same way underneath: boot something other than Windows, reach the Windows files on the drive, and edit them. If the drive is encrypted, none of that is possible without the recovery key.
Windows 11 turns device encryption on by default, and version 24H2 widened which laptops qualify. Microsoft’s documentation states that device encryption is enabled automatically once the out-of-box experience is finished, and that starting in version 24H2 the previous DMA and HSTI/Modern Standby prerequisites were removed, making far more devices eligible.
The practical consequence: boot a laptop with an encrypted drive from a USB stick and the Windows partition either does not mount at all or prompts for a 48-digit recovery key. The Command Prompt tricks below cannot touch files they cannot read.
Check Whether Your Drive Is Encrypted
You can only check this from inside Windows, so do it now on machines you can still sign in to rather than after a lockout. Run msinfo32 and look at the Device Encryption Support line, or open Settings and look for Privacy & security > Device encryption. On Pro editions the same feature appears as BitLocker in Control Panel.
Where Your Recovery Key Is
Where the key was escrowed depends on how you signed in when encryption switched on. Microsoft’s BitLocker documentation sets out the destinations: a Microsoft account user’s key is uploaded to their online Microsoft account, an Entra-joined device backs up to Microsoft Entra ID, and a domain-joined device to Active Directory.
Sign in to your Microsoft account’s recovery keys page from a phone and the keys for your devices are listed there. Note the exception in the same Microsoft documentation: a device set up with a local account only gets no key backup at all. If that describes your laptop and you did not print or save the key yourself, the encrypted data is not recoverable, and reinstalling Windows is the only route back to a usable machine.
The Command Prompt and net user Route
This is what most search results describe, so it is worth being precise about what it does and does not require. The command itself is genuine: net user username newpassword from an administrator Command Prompt sets a local account’s password without knowing the old one.
The difficulty is getting an administrator Command Prompt while locked out. The old advice was to restart, press F8 and choose Safe Mode with Command Prompt, then sign in to the hidden built-in Administrator account.

Two things break that today. F8 has not opened a boot menu by default since Windows 8, which is covered in our walkthrough of the routes into Safe Mode that still work. And the built-in Administrator account is disabled by default on consumer installs, so even reaching Safe Mode does not present it as a sign-in option.

If someone deliberately enabled that Administrator account earlier — many small IT shops do — then this route still works exactly as written. Otherwise it is a dead end, and the guides that present it as the standard fix are describing a configuration most laptops do not have.
The Recovery Media Method and Its Hard Limit
The other technique that fills search results replaces an accessibility binary on the sign-in screen with a copy of Command Prompt. Boot from Windows installation media, open a Command Prompt from the repair options, swap sethc.exe (Sticky Keys) or utilman.exe (the Ease of Access button) for cmd.exe, reboot, and trigger it at the sign-in screen to get a SYSTEM-level prompt. It has been documented and discussed by Windows administrators for years, usually in the context of defending against it.
The original version of this article walked through that swap, and the screenshots below are from it. They are kept as a record of what the procedure looked like, not as a current recommendation.








On an encrypted drive this method simply does not work. Every step depends on reading and writing files in WindowsSystem32 from outside Windows. With device encryption on, that partition will not open without the 48-digit recovery key — and if you have the recovery key you also have access to the Microsoft account that stores it, which means the online password reset is available to you anyway. It also leaves a modified system binary behind, which security software may quarantine later.
Windows Hello Fingerprint and Face Sign-In
If the laptop has a fingerprint reader or an infrared camera and you enrolled either one, use it. Windows Hello signs you in without the password, and once you are at the desktop you can change the password through Settings > Accounts > Sign-in options at your leisure.
One caveat: Windows requires the account password rather than a biometric after certain events, including some restarts following an update, so a fingerprint is a convenience rather than a guaranteed way past a forgotten password. Enroll it before you need it, not after.
Resetting the Laptop When Nothing Else Works
A reset gets you a working laptop. It does not get you your files. Treat it as the end of the line, and only after the account routes above have genuinely failed.
The current route is built into Windows and does not need vendor software. From the sign-in screen, hold Shift while clicking Restart, then choose Troubleshoot > Reset this PC > Remove everything. Because you are locked out, keeping files is not an option the reset will offer in a useful form — a reset that preserves user data still requires signing in afterwards.
The original guide pointed HP owners at HP Recovery Manager, reached with F11 at startup. That tool shipped with Windows 7 and Windows 8-era machines and is absent from HP laptops sold in recent years; HP’s own support material for current notebooks points to the Windows recovery options and to HP Cloud Recovery for rebuilding media. The screenshots below are kept as a record of what that older tool looked like.


Dell, Lenovo and Acer are in the same position — the Windows recovery environment is the supported path, with vendor tools now mostly limited to downloading fresh installation media. If the reset fails or the recovery partition is gone, a Windows installation USB built with Microsoft’s Media Creation Tool does the same job.
Third-Party Password Recovery Tools
The paid tools that dominate these search results are automating the same offline registry edit described above. They are subject to the same limit: an encrypted drive stops them, whatever the product page implies.
They also occupy a category with a poor track record on marketing honesty. The FTC’s action against the operators of two widely advertised PC repair products ended in a $26 million settlement over deceptive claims, which is worth remembering when a tool promises to recover any Windows password. Before paying for one, check whether your drive is encrypted; if it is, no amount of software changes the answer.
How to Avoid Being Locked Out Next Time
Everything that makes a lockout survivable has to be set up while you can still sign in.
- Save the BitLocker recovery key somewhere off the laptop — printed, or in a password manager. Check it is actually listed in your Microsoft account.
- Keep the recovery phone number and email on your Microsoft account current. This is the single most common reason an online reset fails.
- Set the three security questions if you use a local account.
- Enroll a fingerprint or face, and add a PIN.
- Keep a backup. A reset stops being a disaster when the files already exist somewhere else.
Can I get into my laptop without losing my files?
Yes, if the account routes work. A Microsoft account reset, a local account security-question reset, or Windows Hello all sign you in with everything intact. Resetting the PC is the only method here that erases data, which is why it comes last.
Does the net user command still work in Windows 11?
The command works exactly as before. Getting an administrator Command Prompt while locked out is the hard part — F8 no longer opens a boot menu by default, the built-in Administrator account is disabled on consumer installs, and an encrypted drive blocks the offline routes entirely.
Why do password reset tricks fail on my new laptop?
Almost certainly device encryption. Microsoft enables it automatically after setup on qualifying hardware, and Windows 11 version 24H2 removed prerequisites so that more laptops qualify. Offline methods need to read and modify files on the Windows partition, and encryption prevents that without the recovery key.
Where do I find my BitLocker recovery key?
Sign in to your Microsoft account on another device and open the recovery keys page under Devices. Work laptops store the key in Microsoft Entra ID or Active Directory, so your IT desk holds it. A laptop set up with a local account only has no key backed up anywhere.
I forgot my PIN, not my password. Is that different?
Much easier. A Windows Hello PIN is specific to that device and separate from the account password. Select “I forgot my PIN” under the field, verify with your account password or another sign-in method, and set a new one.
Can I reset the password on a laptop I bought secondhand?
Not if it is still signed in to the previous owner’s Microsoft account, and you should not try. Ask the seller to remove the device from their account and reset it. A locked machine that a seller will not unlock may be stolen.
Does a factory reset remove BitLocker encryption?
It reinstalls Windows and discards the previous encrypted volume, so you get a working laptop and lose the old data. On a device that qualifies, encryption is then enabled again on the fresh installation.
Is it legal to reset the password on my own laptop?
Yes. Recovering access to a device you own using the manufacturer’s and Microsoft’s documented routes is ordinary maintenance. The line is ownership — the same steps applied to someone else’s machine or a work laptop you do not administer are unauthorized access.
Final Thoughts on Getting Back Into a Locked Laptop
Start with the account, not the machine. A Microsoft account reset or a security-question reset solves this cleanly and leaves your files where they are, and both take minutes.
The offline tricks that dominate older guides are increasingly beside the point, because encrypted drives stop them before they start. Check where your recovery key is stored while you can still sign in — that one habit is what decides whether a future lockout is an inconvenience or a reinstall.



