Windows Command #25 – net accounts (Windows OS)

Neon green Windows command prompt and account security symbols representing the net accounts command.

The Windows net accounts command displays and changes local password and sign-in policy settings from Command Prompt.

In Windows Command #24 – net localgroup, we managed local group membership. net accounts shifts the focus to account policy: password age, minimum password length, password history, lockout thresholds, and related settings.

Display the current account policy

net accounts

Run the command without additional options to inspect the effective local account-policy values exposed by the command. On a standalone Windows workstation, this is a fast way to check several password and lockout settings from one screen.

Video 1: The Windows net command

SecOps Insider introduces the Windows net command family and the administrative tasks available through it.

Set a minimum password length

net accounts /minpwlen:12

The /minpwlen option sets the minimum number of characters required by the local password policy. Administrative privileges are required to change policy settings. Before changing a production machine, record the existing value and follow the site’s change-control requirements.

Control password age

net accounts /minpwage:1
net accounts /maxpwage:90

/minpwage controls how soon a password may be changed again, while /maxpwage controls how long a password can remain valid before Windows requires a change under that policy. Organizations increasingly evaluate password-expiration rules alongside modern identity guidance, so technicians should implement the policy they are actually assigned rather than inventing one.

Set password history

net accounts /uniquepw:5

The /uniquepw option specifies how many previous passwords Windows remembers when enforcing password-history requirements. This can help prevent immediate reuse when password history is part of the organization’s local policy.

Video 2: Windows password policy

This Windows Server administration lesson demonstrates password-policy concepts such as password age, length, complexity, and lockout settings in a managed Windows environment.

Configure account lockout

net accounts /lockoutthreshold:5
net accounts /lockoutduration:30
net accounts /lockoutwindow:30

The lockout threshold controls how many failed sign-in attempts trigger a lockout. The duration controls how long a locked account remains locked, and the lockout window controls the interval Windows uses when counting failed attempts. These settings interact, so inspect the current policy before modifying them.

Local policy versus domain policy

A workstation’s local settings are not necessarily the final authority in an organization. Domain Group Policy, Microsoft Entra management, Intune, or other enterprise controls may define or enforce account-security requirements. A technician should therefore identify whether the machine is standalone or centrally managed before treating a local command result as the organization’s complete policy.

Video 3: Modern local administrator password management

John Savill’s Technical Training explains Microsoft Windows LAPS and why centrally managed local-administrator passwords matter in modern Windows security.

A technician audit workflow

net accounts
net user
net localgroup administrators

This three-command sequence gives a useful local snapshot: account policy, local user accounts, and membership of the local Administrators group. The previous net user and net localgroup lessons provide the account and group-management context behind the audit.

Common beginner mistakes

  • Changing password policy without first recording the existing values.
  • Assuming local policy overrides centrally managed domain or device policy.
  • Setting an aggressive lockout threshold without considering help-desk and denial-of-service consequences.
  • Confusing net accounts with net user; the first manages policy while the second manages individual accounts.
  • Testing policy changes on a production system instead of an approved lab or maintenance window.

Practice

  1. Open Command Prompt and run net accounts.
  2. Identify the minimum password length and maximum password age shown on your lab system.
  3. Identify the lockout threshold and duration.
  4. Run net user and compare what it reports with net accounts.
  5. On an approved disposable lab VM, change one policy value, verify it with net accounts, and restore the original setting.

Key takeaway

net accounts is a compact Windows command for inspecting and administering local account-policy settings. Use it to understand password and lockout configuration, but always distinguish local policy from centrally managed enterprise policy before making changes.

Leave a comment