Share via


Local user accounts

Applies To: Windows 7, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012

Local user accounts

The Users folder, which is located in the Local Users and Groups Microsoft Management Console (MMC) snap-in, displays default user accounts as well as the user accounts that you create. These default user accounts are created automatically when you install the operating system. The following table describes each default user account that appears in Local Users and Groups.

Default user account Description

Administrator account

The Administrator account is disabled by default, but you can enable it. When it is enabled, the Administrator account has full control of the computer, and it can assign user rights and access control permissions to users as necessary. This account must be used only for tasks that require administrative credentials. It is highly recommended that you set up this account to use a strong password. For additional security considerations for accounts with administrative credentials, see Local Users and Groups best practices.

The Administrator account is a member of the Administrators group on the computer. The Administrator account can never be deleted or removed from the Administrators group, but it can be renamed or disabled. Because the Administrator account is known to exist on many versions of Windows, renaming or disabling this account will make it more difficult for malicious users to try and gain access to it. For more information about how to rename or disable a user account, see Rename a local user account and Disable or activate a local user account.

Important
Even when the Administrator account has been disabled, it can still be used to gain access to a computer through Safe Mode.

Guest account

The Guest account is used by people who do not have an actual account on the computer. A user whose account is disabled, but not deleted, can also use the Guest account. The Guest account does not require a password. The Guest account is disabled by default, but you can enable it.

You can set rights and permissions for the Guest account just like any user account. By default, the Guest account is a member of the default Guests group, which allows a user to log on to a computer. Additional rights, as well as any permissions, must be granted to the Guests group by a member of the Administrators group. The Guest account is disabled by default, and it is recommended that it stay disabled.

For more information about creating and managing local user accounts, see Manage Local Users.