In Windows 10, a “limited” account is called a Standard user. Create a separate account from Settings > Accounts, then verify its account type is Standard User—not Administrator. Standard accounts can use the PC for everyday tasks but generally need an administrator’s approval for system-wide changes.
These steps apply to existing Windows 10 installations. Microsoft ended general support for Windows 10 on October 14, 2025, so creating a Standard account does not restore security updates or support. See Microsoft’s Windows 10 and Windows 11 in S mode FAQ for the support-status details.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
PC-TECH Compatible with Windows 10 Professional 64 Bit USB With Key. Factory fresh, Recover, Repair... | $49.89 | Buy on Amazon |
Before you create the account
- Sign in with an existing administrator account. You need administrator approval to add users or change account types.
- Choose whether the new user should sign in with a Microsoft account or a local account. “Local” describes how the account is connected; “Standard” describes its permission level. Either kind can be Standard.
- Keep at least one working administrator account on the PC, and make sure you know its password. Do not remove or downgrade the only administrator account.
Microsoft recommends limiting the number of administrator accounts because administrators can make broad changes to the device. Its instructions for managing accounts are at Manage User Accounts in Windows.
Create an account in Windows 10 Settings
- Sign in to an administrator account, then select Start > Settings > Accounts.
- Open Other users. Depending on the Windows 10 build, this may be labeled Family & other users.
- Select Add account.
- For a Microsoft account, enter the person’s email address and follow the prompts. For a local account, select I don’t have this person’s sign-in information, then Add a user without a Microsoft account.
- Enter the username and password. Complete the security questions or other prompts Windows displays.
- Return to Settings > Accounts > Other users. Select the new account and choose Change account type.
- Choose Standard User from the account-type menu and select OK.
Verify that the account is Standard
Do not assume an account is restricted just because it was newly created. Open Settings > Accounts > Other users, select the account, and choose Change account type. Confirm that the selection is Standard User. If it says Administrator, change it to Standard User and select OK.
#1 Best Overall
- Fresh USB Install With Key code Included
- 24/7 Tech Support from expert Technician
- Top product with Great Reviews
A Standard user normally runs without administrative privileges. When that user requests a change requiring elevation, Windows may show a User Account Control prompt for administrator credentials. If those credentials are not provided or the administrator declines, the operation will not proceed. UAC reduces unauthorized elevation; it is not a complete malware barrier or a replacement for updates, security software, and backups. Microsoft explains UAC at User Account Control.
What a Standard user can and cannot do
| Task | Typical result |
|---|---|
| Sign in, use the desktop, browse the web, and run installed apps | Usually allowed |
| Create files and change personal settings in their own profile | Usually allowed |
| Install an app only for their own profile | May be allowed; it depends on the installer |
| Install software for all users or change protected system settings | Usually requires administrator approval |
| Add administrator accounts or change another account’s type | Usually blocked without elevation |
| Open another user’s private files | Restricted by permissions, but not an absolute privacy guarantee |
Exact behavior depends on the operation, Windows edition, file permissions, installer, and UAC settings. Portable programs or software installed within a user profile may run without administrator approval; a Standard account does not guarantee that no software can run. Microsoft describes the local-account and group model at Local accounts.
Choose a local or Microsoft account
| Account type | Useful when | Trade-offs |
|---|---|---|
| Local Standard account | The account is for one PC, an offline user, or a guest who does not need Microsoft services. | It is specific to that device and does not automatically sync settings. Password recovery can be difficult without a recovery method. |
| Microsoft Standard account | The user needs Microsoft services, account-linked settings, or Microsoft Family Safety. | It links the Windows profile to an online identity; some family features require suitable account and device setup. |
Microsoft recommends a Microsoft account for Windows sign-in, but it is not required to create a Standard user. For local-account password recovery considerations, see Change From a Local Account to a Microsoft Account in Windows. Windows sign-in options such as password, PIN, fingerprint, or face recognition depend on the device and account configuration; see User Account Access in Windows.
Create a local user from Command Prompt
Use this method if Settings is unavailable or you need a repeatable command-line procedure. Open Command Prompt as administrator, replacing LimitedUser with the desired username:
net user LimitedUser * /add
The asterisk makes Windows prompt for the password instead of putting it in the command. Do not include a real password directly in a command, where it could appear in command history, process inspection, logs, or screenshots. Microsoft documents net user at net user.
To add the account to the standard local Users group and inspect its membership, run:
net localgroup Users LimitedUser /add
net user LimitedUser
If needed, list local accounts with:
net user
Check that the account is not also a member of Administrators. If it is, remove that membership:
net localgroup Administrators LimitedUser /delete
Use the exact local group name displayed by the system on non-English Windows installations. Creating an account or adding it to Users does not remove any existing Administrators membership; check before handing over the PC.
Free tools Windows power users keep installed
One-click scans. No signup required.
Optional: use Local Users and Groups
Some Windows configurations provide the Local Users and Groups console. Press Windows key + R, enter lusrmgr.msc, and press Enter. Open Users, choose Action > New User (or right-click an empty area and choose New User), and create the account. Then open its Properties > Member Of tab and confirm it belongs to Users, not Administrators. If the console does not open, use Settings or Command Prompt instead.
For a child: add Microsoft Family Safety
A Standard account limits administrative privileges; it does not by itself provide screen-time limits or web and app controls. For a child, use a separate Microsoft account, add the child to the Microsoft family group, add the Windows device, and keep the child’s Windows account set to Standard. Then configure the controls you want. Microsoft’s overview is Roles, permissions and data sharing in Family Safety.
- Family Safety can provide screen-time limits, app and game filters, website and search filters, activity reporting, and purchase approvals or consent controls.
- Microsoft’s web and search filtering works with Microsoft Edge when the family member is signed in with their Microsoft account; it is not a universal filter for every browser. Details: Filter websites and searches using Microsoft Family Safety.
- If controls are not applying, check that the child is signed in to the intended Microsoft account, the device is added to the family group, the child remains a Standard user, and the supported browser and permissions are in place. See Troubleshooting Microsoft Family Safety.
Troubleshoot common problems
The new account does not appear at sign-in
Sign out of the current session or restart the PC; locking the screen is not the same as signing out. At the sign-in screen, select Other user if needed. To confirm that the account exists, open an administrator Command Prompt and run net user. Windows can switch users without ending the other session, but unsaved work and running apps remain with that session; see User Account Access in Windows.
Windows asks for an administrator password
This is expected when a Standard user requests an administrative action. Approve it only when you trust and intend the change, using the separate administrator account. Do not make the everyday account an administrator simply to avoid approval prompts.
Recommended Free Tools
The user cannot install an app, printer, or device
System-wide software, drivers, and device changes often require administrator approval. The administrator can install or configure the item while signed in, or approve the specific UAC request. If an application needs elevated access every time, check whether its vendor supports a standard-user configuration before changing account privileges.
The user can still run software
That can be normal. Some installers place an app only in the user’s profile, and portable software may run without a system-wide installation. Standard status limits administrative privileges; it does not block all applications or guarantee protection against software that exploits a security weakness.
A local-account password is forgotten
Use any recovery method already configured, such as security questions or a password reset disk where supported. Without an available recovery method, access to a local account may be difficult or impossible to restore. Keep a separate administrator account and its credentials in a safe place; Microsoft discusses recovery considerations at Change From a Local Account to a Microsoft Account in Windows.
The account needs access to a shared folder
Do not promote the user to administrator just to share files. Grant the specific user or group the required folder permissions, or use a shared location deliberately.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →The account was accidentally made an administrator
From another administrator account, open Settings > Accounts > Other users, select the account, choose Change account type, set it to Standard User, and select OK. Confirm that another working administrator remains on the PC before making the change.
Quick Recap
Choose the right setup for the user
- Guest: A local Standard account can provide a separate profile without administrator rights. Remove it when it is no longer needed.
- Child: Use a Microsoft account as a Standard user and configure Family Safety separately.
- Shared household PC: Keep one private administrator account and give regular users separate Standard accounts rather than sharing a sign-in.
- Work or school: Organizations may need managed identities and centralized device policies instead of manually creating many local accounts. See Add Your Work or School Account to a Windows Device.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

