Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To make Windows 11 lock the built-in local Administrator account after repeated failed network sign-ins, enable Allow Administrator account lockout and set the three supporting Account Lockout Policy values. Microsoft’s example is 10 failed attempts, a 10-minute lockout, and a 10-minute counter reset period. The policy mainly protects network logons such as Remote Desktop; a console sign-in may still be allowed during lockout.
Quick settings
In Local Group Policy Editor, open Computer Configuration > Windows Settings > Security Settings > Account Policies > Account Lockout Policy. Enable Allow Administrator account lockout, then configure the other three policies:
| Policy | Microsoft example | What it controls |
|---|---|---|
| Allow Administrator account lockout | Enabled | Whether the built-in local Administrator account is subject to lockout. |
| Account lockout threshold | 10 invalid attempts | How many failed attempts trigger a lockout. |
| Account lockout duration | 10 minutes | How long the account remains locked. |
| Reset account lockout counter after | 10 minutes | How long without another failure before the failed-attempt count resets. |
Microsoft presents these values as a 10/10/10 baseline example, not a universal requirement. Choose values that fit your environment and recovery plan.
Recommended Free Tools
What this policy does—and which account it affects
The setting applies to the built-in local Administrator account, a specific Windows account. It does not automatically apply to every account in the local Administrators group, a domain Administrator account, or a Microsoft Entra ID or Microsoft account identity. Windows setup commonly disables the built-in account and creates a different local account that belongs to the Administrators group. Those are separate accounts and settings. See Microsoft’s local accounts guidance.
#1 Best Overall
- [INTEL POWERED CONTENT] - Built with a 8th Generation Hexa-Core Intel i5 and 32GB of DDR4 RAM; Modern, Windows 11 ready, with 4K support, Executive multitasking, media streaming and smooth, multi-tab web browsing; Perfect as an all-purpose multimedia computer; built for content creators; Plenty of RAM and Mass storage for photo and video editing powered by Intel HD 630
- [LATEST WIRELESS TECH] - This Dell Desktop Computer easily connects to the internet through the Built In WiFi / Bluetooth
- [SOLID STATE STORAGE] - This Dell Computer setup comes with an ultra-fast 1TB Solid State Drive (SSD); Setup as the primary boot device; Boot and load programs with lightning speed ; Additional expansion available
- [BUY & OWN WITH CONFIDENCE] - From the world's largest Microsoft Authorized Refurbisher; Quality Guarantee and Free Tech Support; Award-winning Customer Service; | Support Sustainable Business
- [MODERN HI-SPEED PORTS] - USB 3.0 (x4) | USB 2.0 (x4) | DisplayPort (x1) | HDMI Port (x1) | Audio Combo Jack (x1) | Audio Out (x1) | RJ-45 Ethernet (x1) | Internal SATA (x3)
Account status is also separate from lockout policy. Enabling lockout does not enable a disabled account. The built-in account’s status is controlled separately at Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options > Accounts: Administrator account status.
Check availability before configuring
Microsoft introduced the policy in cumulative updates beginning October 11, 2022, including for Windows 11 version 22H2. Microsoft’s current Policy CSP documentation lists Windows 11 Pro, Enterprise, Education, and IoT Enterprise editions. Group Policy management tools are not available in every Windows edition; do not assume a Home device has Local Group Policy Editor.
Check the device’s edition and Windows version/build, and install current cumulative updates. For a domain-managed device, also check that the administrative templates and management tools used to edit the GPO are current enough to expose the setting.
Rank #2
- Model: Dell OptiPlex 7050 Small Form Factor (SFF)
- Processor: Intel Core i7-7700 3.60 GHz
- Memory: 32GB DDR4 Ram
- Storage: 1TB Solid State Drive (SSD) Fast Boot + Storage
- Operating System: Windows 11 Pro (64-bit)
Enable it with Local Group Policy
- Sign in using an account with administrative rights.
- Press Windows+R, enter
gpedit.msc, and press Enter. - Go to Computer Configuration > Windows Settings > Security Settings > Account Policies > Account Lockout Policy.
- Open Allow Administrator account lockout, select Enabled, then select Apply and OK.
- Open Account lockout threshold, Account lockout duration, and Reset account lockout counter after in turn. Set the values appropriate to your environment; 10, 10 minutes, and 10 minutes are Microsoft’s example.
- Refresh policy from an elevated Command Prompt or terminal:
gpupdate /force
You can inspect the account-lockout settings in Local Security Policy by opening secpol.msc and going to Account Policies > Account Lockout Policy.
Configure a domain Group Policy
For domain-managed computers, use Group Policy Management to create or edit a GPO scoped to the target computer accounts. Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy. Enable the Administrator-account setting and configure the threshold, duration, and reset interval. Link the GPO to the appropriate domain, site, or computer OU, and check its precedence and scope.
On a pilot client, refresh policy with gpupdate /force. To see which policies applied, run:
Rank #3
- This Certified Refurbished product is tested and certified to look and work like new. The refurbishing process includes functionality testing, basic cleaning, inspection, and repackaging. The product ships with all relevant accessories, a minimum 90-day warranty, and may arrive in a generic box. Only select sellers who maintain a high-performance bar may offer Certified Refurbished products on Amazon.com.
- Dell Optiplex 3050 SFF Desktop computer PC, Intel Quad Core i5-6500 up to 3.6GHz, 16GB DDR4, 256GB SSD
- Includes: USB Keyboard & Mouse, USB WiFi adapter, Microsoft office 30 days free trail.
- Port: Front: USB 3.0(2), USB 2.0(2); Rear: DP, HDMI, USB 3.0(2), USB 2.0(2), RJ-45.
- Support 4K (3840x2160) Dual display, makes it easy to connect two monitors at the same time, and you can expand working Windows, mirror content, or expand a single window across multiple monitors.
gpresult /r
For a more detailed report, run:
gpresult /h "%USERPROFILE%Desktopgpresult.html"
These commands refresh and report Group Policy; they do not configure the setting by themselves. A policy you edited is not necessarily the effective policy: a higher-precedence GPO or another management configuration may supply a different value.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhat 10/10/10 means—and its trade-offs
With the example values, ten failed attempts can trigger a 10-minute lockout. If another failed attempt occurs before the counter-reset interval has elapsed, the failure count has not yet reset. The policy’s threshold can range from 0 to 999; a threshold of 0 disables lockout. The documented duration range is 0 to 99,999 minutes, and a duration of 0 means an administrator must unlock the account. The reset interval range is 1 to 99,999 minutes.
A lower threshold limits password-guessing opportunities sooner, but also makes accidental or deliberate lockouts more likely. A lockout can be abused to deny access: someone may repeatedly submit bad credentials to create an outage or support burden. Consider stale credentials in services and scheduled tasks, automated retry behavior, exposure of Remote Desktop, failed-logon monitoring, and how administrators will recover access. Microsoft discusses operational consequences in its guidance on account-lockout thresholds.
Rank #4
- 【AN INDUSTRY LEADER】- As a Microsoft Authorized Refurbisher, we pride ourselves on producing quality remanufactured PCs. Every machine is handled with care, and our experts are dedicated to giving them a new life. We are committed to reducing e-waste, and it is our goal to ensure each machine we process can satisfy our customers needs.
- 【PROCESSOR】- Intel Core i5 7500 (6MB Cache, 3.4GHz up to 3.8GHz Turbo Boost). TPM 2.0 is recommended for Windows 11, yet this PC only has TPM 1.2. This PC may not support all security features and newest updates.
- 【RAM & STORAGE】- 16GB DDR4 RAM, 512GB SSD, Preloaded with Windows 11 Pro 64-bit.
- 【CONNECTIVITY】- 2x Display Port 1.2; 1x HDMI 1.4; 1x USB 3.0 Type C; 5x USB-A 3.0; 4x USB-A 2.0
- 【BUILT IN WIFI & BLUETOOTH】- Built-in Intel 7260 featuring the latest 802.11ac Wi-Fi for enhanced wireless performance and integrated Bluetooth for seamless device connectivity.
Network logons, RDP, and the console exception
The feature is intended to protect the built-in account against repeated failed network logons, including Remote Desktop attempts. Microsoft notes that console logons may remain allowed while the account is locked. Do not treat the setting as a guarantee that every kind of Administrator sign-in will be blocked.
Lockout is only one layer of RDP protection. Restrict RDP to approved networks or administrative workstations, use a VPN or private access path where appropriate, enable Network Level Authentication, and apply firewall rules and monitoring. A lockout policy does not make an exposed RDP service safe by itself.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Why a patched PC may not already have the setting enabled
Microsoft says new Windows 11 22H2 systems—or systems whose initial setup includes the October 11, 2022 update—receive secure account-lockout defaults when the SAM database is first created. That is not the same as saying every older installation becomes protected automatically after a later update. A PC initially set up before the relevant update may need the policy enabled manually. Microsoft’s Windows identity-protection guidance describes current secure defaults; check the effective policy on the actual device rather than infer it from the fact that Windows is up to date.
Best Value
- Speed up your tasks with AI: Unlock new levels of productivity and creativity by upgrading to Intel Core Ultra processors with built-in AI.
- Supports multiple monitors: Connect up to four FHD monitors using DisplayPort and Daisy Chaining*. Or connect two 4K displays using HDMI 2.1 port and DisplayPort.
- Effortless upgrades: The tool-less entry and removable side panel let you quickly access the internal components, making upgrades convenient and stress-free.
- Ready for business: Keep your data secure with a hardware TPM security chip. And when you need to step away from your desk, simply secure your desktop using the built-in lock slot or padlock loop.
- Style meets sustainability: Dell Tower Desktop seamlessly combines elegance with sustainability. Its sleek, modern design, crafted from recycled materials and featuring refined corners, makes it a stylish addition to any home or office.
Verify safely and plan recovery
Before testing, confirm there is another usable administrative account and a documented recovery route. Where applicable, confirm out-of-band management access. Do not deliberately lock out the only administrator on a production endpoint. If validation is necessary, use a pilot device, test the logon type you care about—such as RDP—and avoid repeated failed attempts against a live production system.
Check the effective settings in secpol.msc and review gpresult output for the applied GPO. If the account is inaccessible, use a separate authorized recovery administrator or your established management process to unlock or reset it; the exact recovery route depends on how the device and account are managed.
Troubleshoot a missing or ineffective policy
- The policy is missing: Confirm Windows edition, version/build, and cumulative updates. Open the exact Account Lockout Policy branch in
secpol.mscor the relevant Group Policy editor. Check that the tools and templates used for domain policy editing are current. - The GPO does not appear to apply: Run
gpupdate /force, then reviewgpresult /ror the HTML report. Confirm the computer is in the GPO’s scope and inspect precedence for conflicting policy. - The account does not lock as expected: Verify that you are testing the built-in local Administrator account, not another administrator-group member or a domain identity. Confirm the account is enabled and the threshold is not set to 0. Test a network sign-in path; console behavior may differ.
- Unexpected lockouts occur: Look for services, scheduled tasks, saved credentials, or other systems retrying an old password. Adjust the threshold or timing only after identifying the source and confirming the recovery path.
Use lockout alongside other controls
If the built-in Administrator account is not required, disabling it reduces its exposure; renaming it may add friction but is not a substitute for strong authentication. Use unique, managed local administrator passwords—Windows LAPS is designed to help manage them—and prefer separate named administrative accounts over shared credentials. Limit Administrators group membership and follow a least-privilege model; Microsoft’s guidance covers least-privilege administration.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

