How to Change Account Lockout Threshold in Windows 11
The account lockout threshold in Windows 11 controls how many wrong password tries lock your PC for a short time. This security setting stops anyone from guessing your password over and over.
Setting this rule to 5, for example, blocks access after five failed login tries. You can change this number using the Local Security Policy tool on Windows 11 Pro or Enterprise editions to keep your files safe from strangers.
You change the Windows 11 account lockout threshold using the Local Group Policy Editor (secpol.msc) or Windows Terminal. Navigate to Computer Configuration\Windows Settings \Security Settings\Account Policies\Account Lockout Policy, then double-click Account lockout threshold and enter a number between 1 and 999.
Prerequisites
Modifying these system policies requires administrator access. Standard user accounts lack the permissions necessary to change these system-wide security rules.
How to change the Account Lockout Threshold
Open the Local Group Policy Editor by pressing Win+R, typing gpedit.msc, and hitting Enter. This tool controls how many incorrect password attempts will lock a user’s account, protecting your computer from unauthorized access.
- Open the Local Group Policy Editor by pressing Win+R, typing
secpol.msc, and hitting Enter.

- Navigate to: Computer Configuration\Windows Settings \Security Settings\Account Policies\Account Lockout Policy.
- Double-click on Account lockout threshold.

- Enter a number between 1 and 999. Setting this to 0 disables the lockout feature entirely.
- Click OK to save.

Change the threshold using Windows Terminal
Command-line execution offers faster results for administrators needing speed.
- Open Windows Terminal as an administrator.

- Type the following command and press Enter:
net accounts /lockoutthreshold:<number>Troubleshooting Locked Accounts
Waiting for the Account lockout duration to expire resolves locked-out scenarios. Administrators can also open the Computer Management console to clear a lock. Right-click the affected user, select Properties, and uncheck ‘Account is locked out’.
Security Best Practices
Pairing a lockout threshold of 5-10 attempts with a strong password maximizes protection. Enable multi-factor authentication whenever available. Disabling the threshold completely leaves your system vulnerable to brute-force attacks (automated login scripts that guess passwords repeatedly).
Summary
Lockout thresholds provide a reliable defense against unauthorized login attempts.
Consult the official Microsoft documentation for advanced configuration details.
What is the recommended account lockout threshold?
Most security experts recommend a threshold between 5 and 10 failed attempts. This range blocks automated brute-force attacks (automated scripts attempting rapid password guesses) while preventing lockouts from everyday typos.
Does setting the threshold to 0 disable account lockout?
Setting the account lockout threshold to 0 disables the policy entirely. Windows ignores failed login attempts under this configuration, allowing unlimited password guesses. Network-connected computers face significant security risks with this setting disabled.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.
For all 3 parameters via command line:
net accounts /lockoutthreshold:15 /lockoutduration:15 /lockoutwindow:10
[…] you subject the built-in admin user to the account lockout policy, it will apply the Account lockout threshold policy setting, which determines the number of failed sign-in attempts that will cause a user […]
[…] account lockout threshold is now set to 10 failed sign-in attempts by […]
[…] account lockout threshold is now set to 10 failed sign-in attempts by […]