Where are local users and groups in Windows 10. Overview of the Local Users and Groups snap-in

To create a user using the Windows 10 Command Prompt, run it as an administrator (for example, through the right-click menu on the Start button), then enter the command (if the username or password contains spaces, use quotes):

net user username password /add

And press Enter.

After successful execution of the command, a new user will appear in the system. You can also make him an administrator using the following command (if the command did not work and you do not have a Windows 10 license, try writing administrators instead of Administrators):

net localgroup Administrators username /add

The newly created user will have a local account on the computer.

Create a user in Local Users and Groups Windows 10

And one more way to create a local account using the Local Users and Groups control:


To make the created user an administrator, right-click on his name and select “Properties”.

Then, on the Group Membership tab, click the Add button, type Administrators, and click OK.

Done, now the selected Windows 10 user will have administrator rights.

control userpasswords2

And one more way that I forgot about, but was reminded in the comments:


If you have any questions or something doesn’t work out as simply as described in the instructions, write to me, I’ll try to help.

If you use a PC with other people, it is advisable that each person have their own account. In this case, each user can personalize their profile. Accounts also help control what files and applications users can use and what changes they can make to the computer. There are two types of account:

  1. Local - contains a user profile that can only be used on this computer. To use, you need to select a user name and enter a password if required.
  2. Microsoft - uses an email address and password to log into Microsoft services with Windows 10, thereby profile settings are not tied to a specific PC, but can be synchronized with other devices.

In this guide, we will look at how to create a new user on Windows 10 local type. the topic of a separate article. Profile files are created after the first login to a new account. To follow the steps in this guide, you need to be an administrator.

Adding via parameters

Use the combination + I to enter the parameters. Visit the Accounts section.

On the left, select "Family and Other People." On the right, click the add a new user link.

Next, click on the link that indicates that this person does not have login information.

The next step is to click the link to add a user without a Microsoft account.

Write the user name. If necessary, set a password and confirm it. When using a password, be sure to select 3 security questions and enter the answers to them. Click Next.

The account has now been created. The profile folder will be added as soon as you log in to your account for the first time. By default, the new account will be assigned the “Standard User” type, but you can change it to “Administrator” if necessary. To do this, LMB click on the new account to make hidden buttons appear. Next, click the button to change account type.

In this window, specify the account type you need. Click OK.

Creation via netplwiz

Type netplwiz into the input line, click OK.

Make sure that the option to require a username and password is checked. Click Add.

Click the sign in without a Microsoft account link, which is not recommended.

Accordingly, choose a local account.

Enter a name, set a password and a hint for it if necessary. Click "Next".

To add an account in Windows 10, click "Done".

A new account will appear in the netplwiz window, the group of which is “Users”. To change the group, select the account by clicking “Properties”.

Go to the Group Membership tab, setting the access level, for example, administrator. Click OK and OK.

Adding via local users and groups

The Local Users and Groups snap-in is not available in the Home edition of Windows 10. If your edition is higher, you can use this method. Launch Run (Win + R). Type lusrmgr.msc and click OK.

Click on the “Users” section. On the right, click on “More Actions” by selecting “New User” from the menu.

Fill in the "User" field. Fill in other fields as required. You can leave the checkboxes at the bottom of the window unchecked and leave them at default. To add a user, click Create. Next, close the window.

In order for the user to acquire administrator rights, right-click on the new account and select “Properties”.

In the Group Membership section, click Add. In the bottom input field, write “Administrators” by clicking OK and OK again.

Creation via Cmd

You can also add a user to Windows 10 through the command line. Run Cmd with elevated rights (read). Enter the following structure:

net user "XXXX" /add

Where XXXX is the user name. Once you have set your name, click Enter. The construction above creates a user without password protection, to have protection, use the following construction:

net user "XXXX" "YYYY" /add

Where XXXX is the user name, and YYYY is your password. Don't forget to press Enter after entering structures. This will create a “standard user” account type. If he needs to add admin status, then use this construction:

net localgroup Administrators "XXXX" /add

Where XXXX, as is already clear, is the user name. Click Enter.

As a result of using one of the methods above, a user will be added. Click “Start”, then on the account management icon, where you will see new names, select the one you need. Next, wait for the profile to be generated.

Now you know how to create an account in Windows 10 in a variety of ways. If there are two users on one PC, you definitely need to add a second profile, and maybe even several. Another important aspect is the transfer of the account to administrative status.

In the new Windows 10, Microsoft has continued the tradition of delimiting computer space with separate accounts for cases when several people use the device. We will not see any fundamental changes compared to its predecessor Windows 8.1 in the new system. Windows 10, like Windows 8.1, provides for working with both local user accounts and connected Microsoft accounts.

The latter is still preferred. As before, a Microsoft account is something of an access key to synchronize system settings, to operate some Metro functionality, as well as other Microsoft web services. The changes in the functionality of accounts are minor, but they are there: unlike its predecessors, Windows 10 offers a more thoughtful system for using one computer device by several users. Now the operating system strictly separates them into their And strangers . For its Windows 10, it provides for the creation of special accounts for family members, including children’s accounts with a parental control function that can be configured online.

Let's take a closer look at the functionality of accounts in Windows 10.

  1. Standard tools for working with accounts

The tools for working with accounts in Windows 10, as in Windows 8.1, are scattered across two types of system settings - in the control panel and in Metro app "Settings" . The Windows 10 control panel still has functions for changing the name, password, and account type. There is also the possibility of removing them. But the prerogative of creation belongs purely Metro-system functionality.

So, most of the functions for working with accounts are concentrated in Metro-application, this is, accordingly, the section.

In the accounts section Metro- system settings, you can connect and disconnect Microsoft accounts, create and delete new accounts, change passwords and PIN codes, configure synchronization settings, connect to resources from your place of work or study, etc.

Switching between computer accounts is done in the menu "Start". The current user is logged out of their account, and another user logs in instead of them on the system lock screen. It is also possible to quickly switch to another account without fiddling with the lock screen when another user is selected directly from the menu "Start". In this case, the account of the current user is blocked, and no one will log in without a password.

  1. Adding a non-family user account

For users not from the family circle in Windows 10 you can create separate accounts, as was the case in previous versions of the system. To do this you just need to have administrator rights. A connected Microsoft account is optional. In the application accounts section, go to the tab. In the window on the right, select the column and click the add new users button.

The system will first offer to create an account with a connection Microsoft account. To do this, all you need to do is enter the email address from this account. You can do without connecting a Microsoft account and create a regular local account by selecting the link below in this window. It is provided for those who have not yet acquired a Microsoft account.

The window that opens via this link will also primarily focus on your Microsoft account, offering to create it immediately. And only at the very bottom we will see an inconspicuous option that provides for adding a local account.

Then a window for entering local account information will appear. When creating the latter, it is not necessary to come up with a password. Unlike a Microsoft account, a regular local account can be used without passwords and PIN codes, without wasting time entering them during the operating system boot process.

After creating an account, it will appear in the column where you can change its type.

By default, Windows assigns all added accounts standard user type. In the list of account types to which you can change the standard user, we will see only the administrator.

The type of child account, as it was in Windows 8.1, in Windows 10 is configured within family accounts.

  1. Benefits of Family Accounts

What are the benefits of family accounts? The accounts of family members connected to one computer device will subsequently be available after synchronization on other devices running Windows 10. Family account settings are made on the Internet, in a special section of the Microsoft account -. Now a parent does not have to have physical access to a Windows 10-based computer to deny or allow certain features for their child, as in previous versions of the operating system. Parents can now manipulate their children by making changes to the parental control settings of their accounts from anywhere in the world where there is Internet access. Moreover, Microsoft has taken care of equal rights for parents in raising children. You can connect the same Microsoft account of another adult to the Microsoft account of one adult, and that adult will also be able to make changes to the parental control settings of the child’s account on a Windows 10 device.

  1. Family Member Account

Since linked family accounts are synchronized using the administrator's Microsoft account, the administrator must have a connected Microsoft account to create them. In the tab, select the button to add a family member.

And if it is not there, in this case the system will no longer offer an alternative with a local account. You will have to create a Microsoft account.

We confirm the addition of a new user from among family members.

Then we will see a notification from the system that the newly added family member will be able to manage the parental control function in children's accounts if they accept the invitation sent to them by email. Actually, now all that remains for him is to check his mailbox and press the button to accept the invitation.

In all other respects, the accounts of family members are no different from the accounts of ordinary users. A type change is also available for them, and if necessary, any family member can be made a second computer administrator.

To add a child’s account, use the same button for adding a new family member located in the tab.

After adding a child's account, you must confirm the parental control function. To activate this function yourself the child must give consent in a letter, sent to his email. Illogical, but according to all the rules of democracy.

After the child agrees to activate the parental control function in his account, we will see a new item appear in the tab, which provides for managing family settings online.

This is a direct link to the Microsoft account section, where you can configure parental control – prohibit visiting certain websites, using certain applications and games, limit the time you use the computer, and also periodically monitor your child’s activity on the Internet.

  1. Limited access for individual accounts

The limited access mode from its predecessor Windows 8.1 has migrated to the new Windows 10 with one minor change. The operating system still allows you to install for individual computer accounts (except for the administrator account, of course) special mode with limited access, when only one Metro-applications. This setting in Windows 10 is available at the very bottom of the tab.

In the settings window that appears, you must select account and the only one available to her Metro-application.

Restriction mode turns an entire account into a single application, deployed to fill the entire screen. No access to any menu "Start", nor to other applications of the system.

You can exit such a restricted account using hotkeys. In Windows 8.1, you need to quickly press the Win key five times. In Windows 10, Microsoft decided to use the classic hotkey combination to log out of a restricted account - Ctrl + Alt + Del.

  1. Deleting accounts

Deleting unused accounts is carried out in Metro-application. The delete button appears when you click on a particular account in the tab.

You can also delete accounts in the system control panel. In the section, click the option to manage another account.

Then select the one to be deleted account and, in fact, we delete it - either with saving the user profile files, or without.

Deleting a family member's account is done in the Microsoft account section.

After which the account on a specific computer device can be deleted using the control panel functionality.

You can temporarily prevent family members from logging in on a specific device. Instead of a delete option, family members' accounts in the app contain a button blocking. After pressing it, you must confirm the entry ban.

You can unblock a family member from logging in at any time.

We've already discussed Windows' ability to allow users to access certain objects. These objects were folders or files. Accordingly, we could give some users access to selected objects and deny others access. File access rights are one thing, but how do you configure access rights to certain components and features of the Windows operating system? How can one user be allowed to use the remote desktop, while another cannot change the network or time settings? Here, regular NTFS access rights are no longer sufficient.

To solve this problem, Windows has special user groups with specific access rights. The best known and most used Windows user groups are groups Administrators, Users And Guests. The rights of users included in these groups are approximately clear, but today I will introduce you to them more closely. In addition, do not forget that the number of user groups ranges from 10 to 20-25, so you will be interested to know about the main ones.

How to change user access rights?

Windows provides two tools that allow you to manipulate the contents of Windows operating system user groups. In other words, adding a user to a specific group or, conversely, kicking him out of there can be done with two Windows tools at once:

  1. Console Computer management.
  2. .

Let's consider both options.

Setting up Windows user groups through the Computer Management console

How to add a user to a Windows user group:

  1. Right-click on the item with your computer mouse My computer.
  2. In the context menu, select Control.
  3. In the window that opens, expand the node Local users and groups.
  4. Select node Groups.
  5. In the central window, select the required group and open it.
  6. In the window that opens, select Add.
  7. In the next window, enter the name of the Windows user you want to add to this group. If necessary, use the button Check names.
  8. After selecting a user or several users at once, press the button OK.

How to remove a user from a group:

  1. Do the first 5 steps described above.
  2. In the window that opens, select the desired user and click the button Delete.
  3. Click OK.

Working with Windows User Groups in the Local Group Policy Editor

How to add/remove a user to/from a WIndows user group/group:

  1. Through open Local Group Policy Editor. The called file is named gpedit.msc.
  2. Go to node Computer Configuration - Windows Configuration - Security Settings - Local Policies - Assigning User Rights.
  3. Select the required policy (each policy implies certain access rights).
  4. Next, you need to proceed by analogy - to add a user, follow steps 6-8, and to remove 2-3 from the corresponding settings items through the console Computer management.

Policy difference from console Computer control The point is that they allow you to configure access rights step by step. If Windows user groups in Computer management have quite extensive rights and restrictions, then policies allow you to configure Windows user rights down to such a small detail as the ability to change the time or time zone.

Windows user groups and their access rights

And here is the long-awaited list of the main Windows user groups:

  • Administrators. Unlimited access.
  • Archive operators. Members of this group have the right to create a backup copy even of objects to which they do not have access.
  • Advanced users. They are of little use, since the group is included only for compatibility with previous versions
  • Performance Monitor Users. There is a wonderful thing called System Monitor(perfmon.msc), with which you can track the use of various resources by your computer. And the group gives access to this tool.
  • Network Configuration Operators. Group members can change TCP/IP settings.
  • Remote Desktop Users. Users in this group will be able to log in via remote desktop.
  • Performance Log Users. Group 4 provides only superficial access to System Monitor. This group gives more complete rights.
  • DCOM users. Group users can manipulate distributed DCOM objects.
  • Cryptographic operators. Members of this group can perform cryptographic operations.
  • Event log readers. I think there is no point in explaining, everything is very clear.

This list could be much wider. Here are only the main groups of Windows users that are found on almost all machines running the Microsoft operating system.

Many PC users often share their gadget with other users. Because of this, conflicts arise. Someone accidentally deleted a file, installed an unnecessary program, or performed some action that led to a system crash. To avoid such problems, you should add a new user to your PC in Windows 10. Let’s look at all the existing methods on how to do this.

Creating a new user in Windows 10 through the Settings section

The easiest way to add a user to Windows 10 is to use the options in the Settings section. In order to add another account on Windows 10, you should do the following:

  • Click “Start”, “Settings” and select the “Accounts” section.
  • In the menu on the left, select the “Family and other people” section. Click “Add a user for this computer.”

  • A new window will appear. The system will ask you to enter the user's name or phone number. If you want to create a new user in Windows 10 without specifying that the account belongs to a specific person, you should click “I don’t have this person’s login information.”

  • A new window will appear again. Click “Add a user without a Microsoft account.”

  • Next, you need to come up with a new user name and enter a password and password hint.

The creation of the new local user account is complete.

Creating a new account via Command Line

The second way to create a new user in Windows 10 is to use the command line. To do this you need to do the following:

  • Right-click on the “Start” icon and select “Command Prompt (Admin).”

  • The console will launch. You need to enter the following command “net user Username Password /add”, where “Username” is the name of the new account, and the password is a combination of numbers. In an example it looks like this.

  • Press “Enter” to add a new user.

  • Now, when you log in, you can select a different user.

Using Local Group to Add a New User in Windows 10

You can create accounts for users of one PC not only using the above methods, but also using the “Local groups and users” section.

  • Press “Win+R” and enter “lusrmgr.msc”.

  • A new window will open. Select the “Users” section. Right-click on an empty space and select “New User”.

  • A small window will appear. Enter the new username, password and confirm the password.

User added. You can log in using a new account in the standard way.

Adding a new user using the Run command

The last method for Windows 10 to get an account is to run the “control userpasswords2” command in the Run window.

The User Accounts section will appear. Click on the “Add” button.

A window for creating a new account will open, the same as in the method above (Creation through the Settings section). Enter all the data and follow the instructions. A new entry will be created.

To learn how to add a new user in Windows 10, watch the video: