HomeHow ToTemporarily Lock Your Windows Computer

Temporarily lock your Windows computer

If you're worried that someone is trying to guess your computer password, you can set Windows to temporarily block login attempts after a certain number of failed attempts.

login-screen-1 windows

Assuming you haven't configured Windows to allow users to log in, your system allows an unlimited number of password attempts for local user accounts. This feature is convenient when you can't remember your password, but it also offers an unlimited number of hacking attempts to other people who don't have physical access to your computer.

While there are ways to bypass or reset a password, setting Windows to temporarily suspend login attempts after several failed password entries can at least help prevent occasional break-in attempts if you're using a local user account. See below for how to set these settings.

Useful notes: By changing this setting, you allow someone to prank you by locking your computer for a period of time, simply by entering wrong passwords on purpose. It would be a good idea to have another administrator account that can unlock the regular account.

Also, these settings only apply to local user accounts, and don't work if you sign in to Windows 8 or 10 using a Microsoft account. If you want to use the lockout settings, you'll need to first reset your Microsoft account to a local one. If you'd rather continue using your Microsoft account, you can go to the Security settings page and sign in. From there, you'll be able to change things like adding two-step verification, creating trusted devices, and more. Unfortunately, there's no lockout setting for Microsoft accounts that works like the one in this example. However, the settings below will work just fine for local user accounts in Windows 7, 8, and 10.

For users of the Home edition of Windows, the only way to set the login attempt limit is via the command line. For Pro and Enterprise editions of Windows, you can use either the command line or a much easier process via editing local group policy.

Additionally, please note that if you start the procedures mentioned below, you must complete them, otherwise you may lock yourself out.

Using the Command Prompt
1. Open the Command Prompt with administrator privileges. If you don’t know how, press the Win + X keys simultaneously and from the drop-down menu select “Command Prompt (Admin)”.
2. In the Command Prompt, type the following command, and then press Enter: net accounts
lockout1
3. This command displays your current password policy, which by default should be “Restrict lockouts: Never”, which means that your account will not lock you out, no matter how many times you enter a password incorrectly. Let’s start by setting the failed attempts limit. You can set it to any number you want, but we recommend setting it to at least three attempts. Type the following command, replacing the number at the end with the number of failed password attempts you want:
net accounts /lockoutthreshold:3
4. Now let's set the duration of a lockout. This number determines how long, in minutes, an account will be locked out once the limit of failed password attempts is reached. We recommend 30 minutes, but you can set it to whatever you like. Remember that the number represents minutes of the hour.
net accounts /lockoutduration:30
5. Finally, we will set the duration of the observation window. This number determines how many minutes it will take for the failed attempts counter to reset, assuming of course that the maximum number of failed attempts has not been reached. So, for our example where we have a limit of 3 failed attempts, if someone makes two failed attempts and then stops, the counter will start counting three more attempts after the X minutes you set now. Set the observation window using the following command, replacing the number at the end with the number of minutes you want to use. Again, we think 30 minutes is a good amount of time.
net accounts /lockoutwindow:30
6. When you're done, you can use the net accounts command again to verify the settings you've made.
7. Close the command prompt window and you're done. When you're at a lock screen asking for a password, don't expect to see any indication of the number of attempts you have available, and if you get locked out, you won't get any notification for how long the computer will remain locked.

If you ever want to change the settings, simply repeat the steps with the new options you want. If you want to completely disable all of the above, all you have to do is open a command prompt with administrator privileges and set the account's failed attempts threshold to 0, using the following command:
net accounts /lockoutthreshold:0
You don't need to worry about the other two settings. When you set the lockout threshold to 0, the lockout duration and lockout window settings will become inapplicable.

Using Local Group Policy *(for Pro and Enterprise users)
If you are using a Pro or Enterprise edition, the easiest way to set the above limits is with the Local Group Policy Editor. An important note, though: if your computer is part of a corporate network, it is very likely that the Local Group Policy settings have already been set at the domain level and have overridden anything you set in the Local Group Policy. And anyway, if you are part of a corporate network, you should always check with your administrator before making any changes.

1. Open the Local Group Policy Editor. If you don’t know how, press Win + R at the same time and in the “Run” window that appears, type “gpedit.msc”, and then click the OK button. Alternatively, if you want to apply the policy to specific users or groups, open the MSC file of the specific users (if you have created one).
2. In the Local Group Policy Editor, go to the left pane and navigate to Computer Configuration > Windows Settings > Security Settings > Account Policies > Account Lockout Policy.
3. From there, go to the left pane and double-click on “Account Lockout Limit”.
lockout2
4. In the properties window of the setting, by default “invalid logon attempts” is set to 0, which essentially means that the setting is disabled. To change this, simply select a new number greater than one. We recommend setting it to at least three to ensure that you don’t get locked out of your own system if you accidentally type in the wrong password. Click “OK” when you’re done.
5. Windows will now automatically set the two related settings to thirty minutes. “Account lockout for” controls how long the computer will be locked out if the failed password attempt limit is exceeded. “Reset account lockout counter after” controls how much time must pass after the last failed password attempt before the limit counter resets. For example, let’s say you enter an invalid password and then type another incorrect password immediately after, but don’t proceed to a third try. Thirty minutes after the second attempt (at least, if you leave the settings imported by Windows), the counter will reset and you’ll have three more attempts. You can’t change these values ​​here, so just click the “OK” button to proceed.
lockout3
5. Back in the main Local Group Policy Editor window, you’ll see that all three settings in the “Account Lockout Policy” folder have changed to reflect the new configuration. You can change any of the settings by double-clicking on them to open their properties window, but thirty minutes is a pretty solid setting for both the lockout duration and the lockout counter reset.
6. Once you’re done with the settings, close the editor. The settings take effect immediately, but since they affect login, you’ll need to log out for the policy to take effect. And if you want to enable the entire setting, change the “invalid login attempts” to 0.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS