List All User Accounts in Windows 11 and 10 (and Find the Hidden Admins)
Listing the user accounts on a Windows 11 or 10 PC takes one command (net user), and the list it returns surprises almost everyone the first time: alongside your own account there are names you never created, such as DefaultAccount, WDAGUtilityAccount, Guest and a built-in Administrator, all of which are supposed to be there and all of which are disabled. This guide shows every way to see the accounts (Settings, the command line, PowerShell, Computer Management), how to tell which ones can actually sign in and which ones are administrators, what each built-in account is for, and, for anyone responsible for more than one PC, how to pull the same list from every machine on the network to find the account somebody left behind.
The "support" account nobody remembered creating
Jake's shop had a new till software installed by a contractor two years ago. When Jake typed net user on the counter PC for the first time (he was following a guide to check something else), the list came back:
Administrator DefaultAccount Guest Jake support WDAGUtilityAccount
"Four of those I don't know," he told Ethan. "And one of them is called support. Is that a virus?"
"Three of the four are Windows' own, disabled, on every PC in the world," Ethan said. "The fourth is the one to care about. support isn't a Windows name. Someone made it." net user support showed it: created two years earlier, password never expires, last logon three months ago, member of Administrators.
It was the contractor's account, still an administrator, still enabled, with a password Jake didn't have, on a PC that ran the shop's money. Nobody had done anything wrong; nobody had done the audit either. Disabling it took one command. The rest of this page is that audit, for one PC and for many.
Method 1: net user (every account, including the hidden ones)
Open Terminal, PowerShell or Command Prompt (no admin rights needed to list) and type:
net user
Windows prints every local account on the machine, in columns, including accounts that never appear on the sign-in screen. For detail on one account:
net user Jake
That shows: full name, whether the account is active, when the password was last set and when it expires, whether the user may change it, the last logon time, the logon hours allowed, and the local group memberships (Administrators, Users, and so on). Two lines to read on any account you don't recognize: Account active and Local Group Memberships.
What net user doesn't show: Microsoft accounts are listed by their short local name (the first five letters of the email, typically), not the email; and domain accounts (on a work PC joined to Active Directory) aren't listed at all, because they live on the domain controller, not the PC. The PowerShell method fixes the first; the admin section covers the second.
Method 2: PowerShell Get-LocalUser (enabled, last logon, local vs Microsoft account)
Get-LocalUser | Select-Object Name, Enabled, LastLogon, PasswordRequired, PrincipalSource, Description | Format-Table -AutoSize
| Column | What it tells you |
|---|---|
| Enabled | True means the account can sign in. The built-in ones show False |
| LastLogon | When it last signed in; blank means never on this PC. The first thing to check on an account you don't recognize |
| PasswordRequired | False on an account that can sign in is worth fixing |
| PrincipalSource | Local for a local account, MicrosoftAccount for one linked to a Microsoft account, ActiveDirectory or AzureAD for work accounts that have a local profile |
| Description | The built-in accounts describe themselves here, which is how you confirm they're Windows' own |
For one account: Get-LocalUser -Name Jake | Format-List *. To save the list for a record: pipe to Export-Csv C:\temp\accounts.csv -NoTypeInformation. Get-LocalUser needs Windows PowerShell 5.1 or PowerShell 7 on Windows; it's on every supported Windows 10 and 11.
Method 3: Who is an administrator (the list that matters)
Existing is one thing; being able to change anything is another. The members of the local Administrators group are the accounts that can install software, change other accounts and turn off protections:
net localgroup Administrators
or, with the account type shown:
Get-LocalGroupMember -Group Administrators | Select-Object Name, ObjectClass, PrincipalSource
On a healthy home PC that list is: the built-in Administrator (disabled, but still listed) and the one or two people who own the machine. Anything else (a contractor's account, support, a software vendor's account, a Microsoft account you don't recognize) is the finding. Our guide to checking whether your own account is administrator or standard covers the other direction: what to do when you aren't on this list and should be.
On a domain-joined PC, Domain Admins and any group your IT added appear here as groups; membership of those is on the domain, not the PC.
Method 4: Settings, Computer Management and Control Panel (point and click)
- Settings → Accounts → Other users (Windows 11; Family & other users on Windows 10): the accounts that can sign in, with their type. It hides the built-in disabled accounts and doesn't show last logon. - Win+R → lusrmgr.msc → Users (Pro, Enterprise and Education; not on Home): every local account, with a red arrow on disabled ones, and double-click for the Member Of tab. Also Win+X → Computer Management → Local Users and Groups. This is the GUI equivalent of everything above. - Win+R → control userpasswords2 (the classic User Accounts dialog): every account that can sign in, with its group, plus the Users must enter a user name and password checkbox. - Control Panel → User Accounts → Manage another account: the oldest view, still present, showing sign-in-capable accounts with their pictures.
On Windows Home, lusrmgr.msc doesn't exist; net user and Get-LocalUser do exactly the same job without it.
The accounts you didn't create, and what each one is for
| Account | What it is | Enabled by default? | Should you touch it? |
|---|---|---|---|
| Administrator | The built-in local admin, present since Windows NT; used by some recovery scenarios | No | Leave disabled. Enabling it with no password is a classic mistake; if you must, give it a strong password (our guide to the admin password) |
| Guest | Legacy account for anonymous sign-in; Windows 10 and 11 no longer allow it to sign in | No | Leave it |
| DefaultAccount | The Default System Managed Account, used by Windows to run some multi-user apps and shared-device features | No | Leave it; it can't be deleted |
| WDAGUtilityAccount | Used by Windows Defender Application Guard (the isolated Edge/Office container) and related virtualization features | No | Leave it; it's created even if Application Guard isn't turned on |
| defaultuser0 | Appears on some machines after setup (the account the out-of-box experience used) with no profile | Sometimes | Harmless; safe to delete if it bothers you |
Accounts ending in $ | Computer or service accounts | n/a | Leave them |
If Get-LocalUser shows Enabled = True on Administrator or Guest, someone turned them on; that's worth a question. Everything else in your list should be a person or a service you can name.
🙋♂️ Jake's Reality Check
"Can I just delete the accounts I don't recognize?"
The straight answer: disable first, delete later, and never delete the built-in four. Disabling (net user support /active:no, or the full guide) stops the sign-in immediately and keeps the profile, so if it turns out the till software used that account to run a service, you find out with an error you can reverse, not with a folder you can't get back. Delete after a month of nothing breaking. Jake's support account was disabled on the spot and deleted at Christmas.
Which accounts have actually used this PC (profiles, and domain users)
net user lists accounts that exist locally. On a work PC, people who sign in with domain or Microsoft Entra accounts don't appear there at all, yet they have profiles under C:\Users. To see everyone who has ever signed in:
Get-CimInstance Win32_UserProfile | Where-Object { -not $_.Special } |
Select-Object LocalPath, LastUseTime, Loaded | Sort-Object LastUseTime -Descending
Each row is a profile folder with when it was last used. That's the list that answers "who used this laptop before me?", and it's the list you clean up (Settings → System → About → Advanced system settings → User Profiles → Settings) when a shared PC's disk fills with old profiles. The WMIC replacement guide explains why this is Get-CimInstance and not the wmic useraccount command older pages show.
Domain accounts (Active Directory): Get-ADUser -Filter * on a machine with the RSAT tools, or net user /domain for the old-style list. Microsoft Entra (Azure AD) joined PCs: the users are in the Entra admin center; on the device, dsregcmd /status shows the join state and the signed-in account's tenant.
For IT admins: every local account and every local admin, across the network
The account that Jake found is the one every audit finds: a local administrator created for a one-off job and never removed. One Invoke-Command produces the list for every PC:
Invoke-Command -ComputerName (Get-Content C:\temp\pcs.txt) -ScriptBlock {
$admins = (Get-LocalGroupMember Administrators).Name -join '; '
Get-LocalUser | ForEach-Object {
[pscustomobject]@{ PC = $env:COMPUTERNAME; Account = $_.Name; Enabled = $_.Enabled
LastLogon = $_.LastLogon; Source = $_.PrincipalSource; IsAdmin = $admins -like "*\$($_.Name)" -or $admins -like "*$($_.Name)*" }
}
} | Where-Object Enabled | Export-Csv C:\temp\local-accounts.csv -NoTypeInformation
Sort the CSV by IsAdmin and LastLogon: enabled local admins with a last logon months ago (or never) are the findings. The remoting setup is the same as for the system-configuration inventory.
Three things the fleet list leads to:
- Windows LAPS (built into Windows 11 and Windows 10 since 2023): lets each PC keep a unique, rotating password for its built-in Administrator, stored in Active Directory or Microsoft Entra. It's the supported answer to "we need one local admin per machine"; it replaces the shared-password support account pattern entirely. - Restricted Groups / Intune account protection: Group Policy (Computer Configuration → Windows Settings → Security Settings → Restricted Groups) or Intune (Endpoint security → Account protection → Local user group membership) can define exactly who is in Administrators, and remove everyone else at every refresh. Once that's in place, a contractor's account is demoted automatically within the hour. - Audit sign-ins, not just accounts: Security log Event 4624 (logon) with Logon Type 10 (remote interactive) or 2 (console) for the accounts in question tells you whether that dormant admin is truly dormant; 4720 is an account created, 4732 a member added to a local group. Filter those two across the fleet and you see new admins the day they appear.
✅ The admin's version in one line
List enabled local accounts and Administrators members from every PC monthly, disable what nobody can name, put the built-in Administrator under LAPS, and let Restricted Groups (or Intune account protection) enforce the admins list so it can't drift again.
User account listing problems: the fix table
| What you see | What it means | What to do |
|---|---|---|
net user shows accounts not on the sign-in screen | Disabled or built-in accounts | Normal; check Enabled with Get-LocalUser |
| A Microsoft account shows a short odd name | Local name is derived from the email | Get-LocalUser → PrincipalSource = MicrosoftAccount; the full name is in Settings → Accounts |
Domain users missing from net user | They live on the domain | Use Get-CimInstance Win32_UserProfile for who has signed in; net user /domain for the domain list |
lusrmgr.msc not found | Windows Home | Use net user and Get-LocalUser |
Get-LocalUser not recognized | Very old PowerShell, or you're in Command Prompt | Open PowerShell or Terminal; needs 5.1+ |
| Administrator or Guest shows Enabled = True | Someone enabled it | Disable: net user Administrator /active:no, unless you deliberately use it under LAPS |
| An account you don't recognize is an admin | Leftover contractor/vendor/installer account | Disable it now, delete after a month; check event 4720/4732 for when it was made |
| "Access is denied" listing group members | Not elevated | Run the terminal as administrator |
| Account exists but can't sign in | Disabled, expired, or logon hours restricted | net user NAME shows all three lines |
| Profile folder exists for an account that isn't listed | Deleted account, orphaned profile | Remove via System Properties → User Profiles |
Listing user accounts in Windows: the questions people search
How do I see all user accounts on Windows 11?
Open a terminal and type net user: it lists every local account, including hidden and disabled ones. For detail (enabled, last logon, local or Microsoft account), use PowerShell: Get-LocalUser | Select-Object Name, Enabled, LastLogon, PrincipalSource.
What is the command to list users in Windows?
net user for the list, net user NAME for one account's details, net localgroup Administrators for the admins. In PowerShell, Get-LocalUser and Get-LocalGroupMember Administrators.
Why do I see accounts I never created, like DefaultAccount and WDAGUtilityAccount?
They're built into Windows: DefaultAccount is the system-managed account some shared-device features use, WDAGUtilityAccount belongs to Application Guard, and Administrator and Guest are the classic built-ins. All are disabled by default and should stay that way.
How do I find out which accounts are administrators?
net localgroup Administrators or Get-LocalGroupMember -Group Administrators. On a home PC the list should be the built-in Administrator (disabled) plus the people who own the machine.
How do I see when an account last signed in?
Get-LocalUser | Select-Object Name, LastLogon. For accounts without a local entry (domain or Entra users), Get-CimInstance Win32_UserProfile shows each profile's LastUseTime.
How do I list user accounts on Windows 11 Home without lusrmgr?
net user and Get-LocalUser work on every edition. control userpasswords2 gives a GUI list of sign-in-capable accounts on Home.
How do I see hidden user accounts?
net user and Get-LocalUser show them; Settings and the sign-in screen hide disabled and built-in accounts by design.
Is the WDAGUtilityAccount a virus?
No. It's created by Windows for Windows Defender Application Guard and related isolation features, is disabled, and exists on machines that never turned Application Guard on. Leave it.
Should I enable the built-in Administrator account?
Not for everyday use. It bypasses UAC prompts and, if enabled with a weak or blank password, is an open door. In a business, manage it with Windows LAPS instead of enabling it by hand.
How do I list domain users from a Windows PC?
net user /domain for the old-style list, or Get-ADUser -Filter * with the RSAT Active Directory module installed. Locally, Get-CimInstance Win32_UserProfile shows which domain users have signed in on this PC.
How do I export the list of user accounts to a file?
Get-LocalUser | Select-Object Name, Enabled, LastLogon, PrincipalSource | Export-Csv C:\temp\accounts.csv -NoTypeInformation, or net user > C:\temp\accounts.txt.
How do IT admins find local administrator accounts on all computers?
Run Get-LocalGroupMember Administrators and Get-LocalUser through Invoke-Command against the list of PCs and export the results; then enforce the admins list with Restricted Groups or Intune account protection, and put the built-in Administrator under Windows LAPS.
What is defaultuser0?
A leftover from Windows setup on some machines. It has no usable profile and can be deleted safely; it's not a sign of anything wrong.
How do I tell a local account from a Microsoft account in the list?
Get-LocalUser → PrincipalSource: Local, MicrosoftAccount, ActiveDirectory or AzureAD.
Can I list accounts on a remote computer?
Yes: Invoke-Command -ComputerName PCNAME -ScriptBlock { Get-LocalUser } with PowerShell remoting enabled, or Get-LocalUser inside a remote session (Enter-PSSession PCNAME).
Does this work the same on Windows 10?
Yes. net user, Get-LocalUser, lusrmgr.msc and the Settings page (under Family & other users) all behave the same on Windows 10.
If your list came back with names you didn't recognize, take the thirty seconds to check which of them are Windows' own and which one is somebody's leftover; the second kind is common, rarely malicious, and always worth closing. If a screen or a name here has changed by the time you read it, tell me through the contact page; Windows adds built-in accounts between versions, and this page stays accurate because readers write in.
📌 If you keep one line from this page
net user lists every local account; Get-LocalUser adds enabled, last logon and account type; net localgroup Administrators shows who can change things.
Administrator, Guest, DefaultAccount and WDAGUtilityAccount are Windows' own and disabled; anything else should be a person or a service you can name.
Revision note. Originally published August 2015 for Windows 10; rewritten September 26, 2026, for Windows 11 25H2 and Windows 10, adding Get-LocalUser, the built-in accounts table, profiles and domain users, and the fleet audit with LAPS and Restricted Groups. Commands are current as of that date. Next check: when Windows adds or renames a built-in account. List them, name them, disable the one you can't.