How to Change Account Lockout Threshold in Windows 11
The account lockout threshold in Windows 11 locks your PC after a specific number of failed sign-in attempts to block hackers from guessing your password. Setting this rule to 5, for example, blocks access after five wrong tries.
You can change this number using the Local Security Policy tool (a built-in app for managing advanced security rules) on Windows 11 Pro or Enterprise editions.
You change the Windows 11 account lockout threshold using the Local Group Policy Editor (secpol.msc) or Windows Terminal. Navigate to Computer Configuration\Windows Settings \Security Settings\Account Policies\Account Lockout Policy, then double-click Account lockout threshold and enter a number between 1 and 999.
Prerequisites
Modifying these system policies requires administrator access. Standard user accounts lack the permissions necessary to change these system-wide security rules.
How to change the Account Lockout Threshold
Changing the Windows 11 account lockout threshold lets you set how many times someone can type the wrong password before Windows locks the account. You can change this number using the Local Group Policy Editor to protect your computer from guessing attacks. Open the run box by pressing the Win plus R, type gpedit.msc, and press Enter to start.
- Open the Local Group Policy Editor by pressing Win+R, typing
secpol.msc, and hitting Enter.

- Navigate to: Computer Configuration\Windows Settings \Security Settings\Account Policies\Account Lockout Policy.
- Double-click on Account lockout threshold.

- Enter a number between 1 and 999. Setting this to 0 disables the lockout feature entirely.
- Click OK to save.

Change the threshold using Windows Terminal
Command-line execution offers faster results for administrators needing speed.
- Open Windows Terminal as an administrator.

- Type the following command and press Enter:
net accounts /lockoutthreshold:<number>
Troubleshooting Locked Accounts
Wait for the account lockout duration to expire, or clear the lock manually. Administrators can also open the Computer Management console to clear a lock. Right-click the affected user, select Properties, and uncheck ‘Account is locked out’.
Security Best Practices
Pairing a lockout threshold of 5-10 attempts with a strong password maximizes protection. Enable multi-factor authentication whenever available. Disabling the threshold completely leaves your system vulnerable to brute-force attacks (automated programs that try thousands of password combinations).
Summary
Lockout thresholds provide a reliable defense against unauthorized login attempts.
Consult the official Microsoft documentation for advanced configuration details.
What is the recommended account lockout threshold?
Most security experts recommend a threshold between 5 and 10 failed attempts. This range blocks automated brute-force attacks (automated scripts attempting rapid password guesses) while preventing lockouts from everyday typos.
Does setting the threshold to 0 disable account lockout?
Setting the account lockout threshold to 0 disables the policy entirely. Windows ignores failed login attempts under this configuration, allowing unlimited password guesses. Network-connected computers face significant security risks with this setting disabled.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.
For all 3 parameters via command line:
net accounts /lockoutthreshold:15 /lockoutduration:15 /lockoutwindow:10
[…] you subject the built-in admin user to the account lockout policy, it will apply the Account lockout threshold policy setting, which determines the number of failed sign-in attempts that will cause a user […]
[…] account lockout threshold is now set to 10 failed sign-in attempts by […]
[…] account lockout threshold is now set to 10 failed sign-in attempts by […]