Windows Server 2019 – Only Local Administrator Account Is Locked Out and Cannot Log In

minh nguyen 20 Reputation points
2026-10-06T14:04:42.8333333+00:00

Hello,

I have a Windows Server 2019 virtual machine running on VMware ESXi.

The server is not joined to an Active Directory domain. It is a standalone server.

There is currently only one local administrator account available on this server (admin), and I know the correct password for this account.

However, when I try to log in, Windows displays the following error:

“The referenced account is currently locked out and may not be logged on to.”

I have already waited for a long period without attempting to log in, but the account remains locked.

Current situation:

Windows Server 2019

VMware ESXi virtual machine

Standalone server / not domain joined

Only one local administrator account is available

The local administrator account is locked out

I know the correct password

No other administrator account is available

No usable snapshot or backup is available

I would like to preserve all existing data, applications, and server configuration

Is there a Microsoft-supported method to unlock this local administrator account or regain administrative access without reinstalling Windows Server or losing data?

I have seen suggestions involving Windows Recovery Environment (WinRE) and commands such as:

net user administrator /active:yes

Would this work for a standalone Windows Server 2019 installation, or is there another supported recovery procedure?

Thank you.

Windows for business | Windows Server | Directory services | User logon and profiles
0 comments No comments

Answer accepted by question author
Jason Nguyen Tran 27,370 Reputation points Independent Advisor
2026-10-06T14:26:37.7366667+00:00

Hello

Based on the scenario you described, there is unfortunately no supported Microsoft method to directly unlock a local account offline while Windows is not running. If the account lockout policy is configured with a lockout duration, the account should automatically become available once that duration expires; however, if the policy is configured to require an administrator to unlock the account, access becomes difficult when no other administrative account exists.

Regarding the command net user administrator /active:yes, this command can enable the built-in Administrator account, but it must be executed from an operating system environment that has access to the local Security Accounts Manager (SAM) database. In practice, whether this helps depends on the current state of the built-in Administrator account and the recovery options available to you.

Since there are no additional administrator accounts, no usable backups, and no snapshots, the recommended approach is to first verify the local account lockout policy settings and determine whether the built-in Administrator account can be accessed through supported recovery procedures. This offers the best chance of regaining administrative access while preserving the server's existing applications, data, and configuration.

Before making any recovery changes, I strongly recommend creating a full backup or a copy of the virtual machine files at the VMware level to ensure the current state can be preserved if further recovery steps are required.

. If you find this answer helpful, please click "Accept Answer" so that other administrators facing a similar situation can benefit from it as well.

Jason

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.