Skip to main content
FixMyTech

Reset a Forgotten Windows Password Without Losing Files

By

Published

8 min read

Share

Short answer

If the sign-in screen shows an email address, you have a Microsoft account — reset the password at account.microsoft.com from a phone or another PC, then sign in normally with the new one. If it shows only a name, it is a local account, and your only built-in routes are a password reset disk or the security questions you set when you created it. Both preserve every file.

On this page

There is one question that decides everything here, and it is not which Windows version you are running. It is whether your account is a Microsoft account or a local account.

Look at the sign-in screen. If an email address appears beneath your name, it is a Microsoft account and the fix takes five minutes from your phone. If only a username appears, it is a local account, and your options are narrower and depend on preparation you may or may not have done.

This guide covers the routes available to the person who owns the machine. If you cannot prove ownership of the account, there is no legitimate recovery path, and that is by design.

Work out which account you have

What the sign-in screen shows Account type Route
Your name plus an email address Microsoft account Online reset
Only a username, no email Local account Reset disk or security questions
“Other user” / domain or work name Work or school account Your IT department resets it

That last row is worth taking seriously. A device joined to a company domain or to Microsoft Entra ID has its password managed centrally, and nothing you do on the machine will reset it. The service desk can, in about a minute.

Microsoft account: the five-minute route

You do not need access to the locked PC at all for this.

  1. On a phone, tablet or any other computer, go to account.microsoft.com and click Sign in, then Forgot password.
  2. Enter the email address shown on the locked PC’s sign-in screen.
  3. Choose a verification method — a code to your recovery email, a text to your phone, or an approval in the Microsoft Authenticator app.
  4. Set a new password.
  5. Back at the locked PC, connect it to a network first. On the sign-in screen, the network icon in the bottom-right corner lets you join Wi-Fi before signing in.
  6. Sign in with the new password.

Step 5 is the one people miss. Windows caches the last known good password locally, so until the machine reaches Microsoft’s servers it will keep rejecting the new one and accepting the old one. On a wired connection this happens automatically; on Wi-Fi you have to join the network from the lock screen.

If you no longer have access to any of the verification methods, Microsoft offers an account recovery form that asks detailed questions about your usage of the account. It takes several days and it is genuinely strict, because the whole point of it is that a stranger should not pass it.

A quicker option if you have a PIN

Windows Hello PINs are stored on the device and verified by the TPM, so a PIN works even when the account password does not. If you remember the PIN, sign in with it, then go to Settings → Accounts → Sign-in options → Password → Change to set a password you will remember.

Local account: what actually works

A local account exists only on that machine. There is no server holding a recovery copy, which is precisely why it is more private and also why it is harder to recover.

Another administrator account

The simplest fix by far. If any other account on the PC has administrator rights — a second family profile, the account you set up and forgot about — sign into that one and reset the locked account from there.

Open Control Panel → User Accounts → User Accounts → Manage another account, select the account, and choose Change the password. Alternatively, in Terminal (Admin), net user on its own lists local accounts.

One consequence worth knowing before you do this: resetting another account’s password from an admin account discards that account’s stored credentials — saved Wi-Fi passwords, credentials in Windows Credential Manager, and any files encrypted with EFS. Documents, photos and installed programs are untouched.

A password reset disk

This is the mechanism Microsoft built for local accounts, and it has to be created while you can still sign in. If you made one, insert the USB stick, enter any wrong password once so the Reset password link appears under the box, and follow the wizard.

If you have not made one and you can currently sign in to a local account, make one now. Search the Start menu for Create a password reset disk, insert a USB stick, and follow the three-step wizard. The file is tiny and it is specific to that one account on that one machine — which is also why it should live somewhere a stranger cannot reach.

Security questions

Local accounts created on Windows 10 1803 or later are prompted to set three security questions. If you answered them, enter a wrong password once at the sign-in screen and a Reset password link appears. Answer the questions and set a new password on the spot.

To check or change yours while you can still sign in: Settings → Accounts → Sign-in options → Password → Update your security questions.

The honest answer when none of those apply

A local account with no reset disk, no security questions, no second administrator account and no cached PIN has no supported recovery route. Windows is working correctly when it refuses you — an account that could be unlocked by anyone sitting at the keyboard would not be an account.

What that leaves is:

  • Recover the files, then reinstall. Remove the drive and connect it to another PC via a USB enclosure, or boot the machine from a Linux live USB, and copy your documents off. Then do a clean install of Windows. Your files survive; your installed applications and settings do not.
  • This fails if the drive is encrypted. BitLocker-protected drives, and recent consumer PCs often enable Device Encryption automatically, cannot be read from another machine without the 48-digit recovery key. On a Microsoft account that key is stored at account.microsoft.com under your device. On a local account it was shown once during setup, and if it was not saved the data is not recoverable by anyone.

That is a bleak paragraph, and it is accurate. It is also the strongest possible argument for linking a Microsoft account or at least printing the BitLocker recovery key.

Set things up so it cannot happen again

Once you are back in, twenty minutes of preparation removes this problem permanently:

  • Add a second administrator account and give it a password you store in a password manager. Settings → Accounts → Other users → Add account.
  • Save the BitLocker recovery key somewhere off the machine. Search Start for Manage BitLocker, then Back up your recovery key. Print it if you have no better option.
  • Set a Windows Hello PIN. It survives a forgotten password and is faster to type anyway.
  • Record your recovery phone and email on your Microsoft account while you can still reach the settings. An outdated recovery number is the single most common reason the online reset fails.

If the broader concern is account access rather than this one PC, seeing where your Google account is signed in covers the equivalent audit on the other account most people cannot afford to lose.

Realistic expectations

Microsoft account holders are back at the desktop in five minutes, assuming the recovery phone or email still works, and the only real delay is remembering to connect the locked PC to Wi-Fi before trying the new password.

Local accounts split sharply. With a reset disk, security questions or a second admin account, it takes two minutes and nothing is lost. Without any of them, no amount of searching produces a supported route, and the realistic plan is recovering the files to another machine and reinstalling — provided the drive is not encrypted.

Frequently asked questions

Does resetting a Windows password delete my files?
Resetting through a Microsoft account, a password reset disk or security questions does not touch your files at all. The one exception is a file encrypted with EFS or a BitLocker drive unlocked by that password, where losing the credential can mean losing access to the data permanently.
How do I know if I have a Microsoft account or a local account?
Look at the sign-in screen. A Microsoft account shows your email address under your name; a local account shows only a username. If you can reach the desktop on another account, Settings → Accounts → Your info says "Local account" explicitly when it is one.
What is a password reset disk and can I make one now?
It is a small key file written to a USB stick that resets a specific local account's password. It must be created while you can still sign in, which is why it is useless to most people who need it. If you can get into any admin account, making one for your other local accounts takes two minutes.
Can I use another administrator account to reset a forgotten one?
Yes, and it is the simplest fix when a second admin account exists. From that account, Control Panel's user accounts section lets an administrator set a new password for any local user, though doing so discards that account's stored browser and network credentials.
What happens to BitLocker if I reset the password?
BitLocker is unlocked by its own recovery key, not your sign-in password, so a normal password reset leaves it alone. You will need the 48-digit recovery key if Windows asks for it at boot, and on a Microsoft account that key is usually saved at account.microsoft.com/devices/recoverykey.

All Windows guides