List All User Accounts in Windows 11 and 10 (and Find the Hidden Admins)

Logeshwaran
—

Listing the user accounts on a Windows 11 or 10 PC takes one command (net user), and the list it returns surprises almost everyone the first time: alongside your own account there are names you never created, such as DefaultAccount, WDAGUtilityAccount, Guest and a built-in Administrator, all of which are supposed to be there and all of which are disabled. This guide shows every way to see the accounts (Settings, the command line, PowerShell, Computer Management), how to tell which ones can actually sign in and which ones are administrators, what each built-in account is for, and, for anyone responsible for more than one PC, how to pull the same list from every machine on the network to find the account somebody left behind.

⚡ Quick Answer

• Fastest: open a terminal and type net user. Every local account, hidden ones included. Steps.

• With detail (enabled? last sign-in? local or Microsoft account?): PowerShell Get-LocalUser | Select-Object Name, Enabled, LastLogon, PrincipalSource. Steps.

• Who is an administrator: net localgroup Administrators, or Get-LocalGroupMember Administrators. Steps.

• Point and click: Settings → Accounts → Other users, or Win+R → lusrmgr.msc (Pro and above). Steps.

• The names you didn't create (DefaultAccount, WDAGUtilityAccount, Guest, Administrator): built in, disabled, leave them. What they are.

• Every PC in the office: one Invoke-Command line that lists local accounts and admins per machine. The admin section.

If you only read this box: net user shows who exists; net localgroup Administrators shows who matters.

The "support" account nobody remembered creating

Jake's shop had a new till software installed by a contractor two years ago. When Jake typed net user on the counter PC for the first time (he was following a guide to check something else), the list came back:

Administrator    DefaultAccount    Guest    Jake    support    WDAGUtilityAccount

"Four of those I don't know," he told Ethan. "And one of them is called support. Is that a virus?"

"Three of the four are Windows' own, disabled, on every PC in the world," Ethan said. "The fourth is the one to care about. support isn't a Windows name. Someone made it." net user support showed it: created two years earlier, password never expires, last logon three months ago, member of Administrators.

It was the contractor's account, still an administrator, still enabled, with a password Jake didn't have, on a PC that ran the shop's money. Nobody had done anything wrong; nobody had done the audit either. Disabling it took one command. The rest of this page is that audit, for one PC and for many.

📚 READ THESE FIRST

New to running AI on your own machine? These five make the rest of this guide easy:

⚡ Two minutes each. Come back here when they are done.

Method 1: net user (every account, including the hidden ones)

Open Terminal, PowerShell or Command Prompt (no admin rights needed to list) and type:

net user

Windows prints every local account on the machine, in columns, including accounts that never appear on the sign-in screen. For detail on one account:

net user Jake

That shows: full name, whether the account is active, when the password was last set and when it expires, whether the user may change it, the last logon time, the logon hours allowed, and the local group memberships (Administrators, Users, and so on). Two lines to read on any account you don't recognize: Account active and Local Group Memberships.

What net user doesn't show: Microsoft accounts are listed by their short local name (the first five letters of the email, typically), not the email; and domain accounts (on a work PC joined to Active Directory) aren't listed at all, because they live on the domain controller, not the PC. The PowerShell method fixes the first; the admin section covers the second.

Method 2: PowerShell Get-LocalUser (enabled, last logon, local vs Microsoft account)

Get-LocalUser | Select-Object Name, Enabled, LastLogon, PasswordRequired, PrincipalSource, Description | Format-Table -AutoSize
ColumnWhat it tells you
EnabledTrue means the account can sign in. The built-in ones show False
LastLogonWhen it last signed in; blank means never on this PC. The first thing to check on an account you don't recognize
PasswordRequiredFalse on an account that can sign in is worth fixing
PrincipalSourceLocal for a local account, MicrosoftAccount for one linked to a Microsoft account, ActiveDirectory or AzureAD for work accounts that have a local profile
DescriptionThe built-in accounts describe themselves here, which is how you confirm they're Windows' own

For one account: Get-LocalUser -Name Jake | Format-List *. To save the list for a record: pipe to Export-Csv C:\temp\accounts.csv -NoTypeInformation. Get-LocalUser needs Windows PowerShell 5.1 or PowerShell 7 on Windows; it's on every supported Windows 10 and 11.

Method 3: Who is an administrator (the list that matters)

Existing is one thing; being able to change anything is another. The members of the local Administrators group are the accounts that can install software, change other accounts and turn off protections:

net localgroup Administrators

or, with the account type shown:

Get-LocalGroupMember -Group Administrators | Select-Object Name, ObjectClass, PrincipalSource

On a healthy home PC that list is: the built-in Administrator (disabled, but still listed) and the one or two people who own the machine. Anything else (a contractor's account, support, a software vendor's account, a Microsoft account you don't recognize) is the finding. Our guide to checking whether your own account is administrator or standard covers the other direction: what to do when you aren't on this list and should be.

On a domain-joined PC, Domain Admins and any group your IT added appear here as groups; membership of those is on the domain, not the PC.

Method 4: Settings, Computer Management and Control Panel (point and click)

- Settings → Accounts → Other users (Windows 11; Family & other users on Windows 10): the accounts that can sign in, with their type. It hides the built-in disabled accounts and doesn't show last logon. - Win+R → lusrmgr.msc → Users (Pro, Enterprise and Education; not on Home): every local account, with a red arrow on disabled ones, and double-click for the Member Of tab. Also Win+X → Computer Management → Local Users and Groups. This is the GUI equivalent of everything above. - Win+R → control userpasswords2 (the classic User Accounts dialog): every account that can sign in, with its group, plus the Users must enter a user name and password checkbox. - Control Panel → User Accounts → Manage another account: the oldest view, still present, showing sign-in-capable accounts with their pictures.

On Windows Home, lusrmgr.msc doesn't exist; net user and Get-LocalUser do exactly the same job without it.

The accounts you didn't create, and what each one is for

AccountWhat it isEnabled by default?Should you touch it?
AdministratorThe built-in local admin, present since Windows NT; used by some recovery scenariosNoLeave disabled. Enabling it with no password is a classic mistake; if you must, give it a strong password (our guide to the admin password)
GuestLegacy account for anonymous sign-in; Windows 10 and 11 no longer allow it to sign inNoLeave it
DefaultAccountThe Default System Managed Account, used by Windows to run some multi-user apps and shared-device featuresNoLeave it; it can't be deleted
WDAGUtilityAccountUsed by Windows Defender Application Guard (the isolated Edge/Office container) and related virtualization featuresNoLeave it; it's created even if Application Guard isn't turned on
defaultuser0Appears on some machines after setup (the account the out-of-box experience used) with no profileSometimesHarmless; safe to delete if it bothers you
Accounts ending in $Computer or service accountsn/aLeave them

If Get-LocalUser shows Enabled = True on Administrator or Guest, someone turned them on; that's worth a question. Everything else in your list should be a person or a service you can name.

🙋‍♂️ Jake's Reality Check

"Can I just delete the accounts I don't recognize?"

The straight answer: disable first, delete later, and never delete the built-in four. Disabling (net user support /active:no, or the full guide) stops the sign-in immediately and keeps the profile, so if it turns out the till software used that account to run a service, you find out with an error you can reverse, not with a folder you can't get back. Delete after a month of nothing breaking. Jake's support account was disabled on the spot and deleted at Christmas.

Which accounts have actually used this PC (profiles, and domain users)

net user lists accounts that exist locally. On a work PC, people who sign in with domain or Microsoft Entra accounts don't appear there at all, yet they have profiles under C:\Users. To see everyone who has ever signed in:

Get-CimInstance Win32_UserProfile | Where-Object { -not $_.Special } |
  Select-Object LocalPath, LastUseTime, Loaded | Sort-Object LastUseTime -Descending

Each row is a profile folder with when it was last used. That's the list that answers "who used this laptop before me?", and it's the list you clean up (Settings → System → About → Advanced system settings → User Profiles → Settings) when a shared PC's disk fills with old profiles. The WMIC replacement guide explains why this is Get-CimInstance and not the wmic useraccount command older pages show.

Domain accounts (Active Directory): Get-ADUser -Filter * on a machine with the RSAT tools, or net user /domain for the old-style list. Microsoft Entra (Azure AD) joined PCs: the users are in the Entra admin center; on the device, dsregcmd /status shows the join state and the signed-in account's tenant.

For IT admins: every local account and every local admin, across the network

The account that Jake found is the one every audit finds: a local administrator created for a one-off job and never removed. One Invoke-Command produces the list for every PC:

Invoke-Command -ComputerName (Get-Content C:\temp\pcs.txt) -ScriptBlock {
  $admins = (Get-LocalGroupMember Administrators).Name -join '; '
  Get-LocalUser | ForEach-Object {
    [pscustomobject]@{ PC = $env:COMPUTERNAME; Account = $_.Name; Enabled = $_.Enabled
      LastLogon = $_.LastLogon; Source = $_.PrincipalSource; IsAdmin = $admins -like "*\$($_.Name)" -or $admins -like "*$($_.Name)*" }
  }
} | Where-Object Enabled | Export-Csv C:\temp\local-accounts.csv -NoTypeInformation

Sort the CSV by IsAdmin and LastLogon: enabled local admins with a last logon months ago (or never) are the findings. The remoting setup is the same as for the system-configuration inventory.

Three things the fleet list leads to:

- Windows LAPS (built into Windows 11 and Windows 10 since 2023): lets each PC keep a unique, rotating password for its built-in Administrator, stored in Active Directory or Microsoft Entra. It's the supported answer to "we need one local admin per machine"; it replaces the shared-password support account pattern entirely. - Restricted Groups / Intune account protection: Group Policy (Computer Configuration → Windows Settings → Security Settings → Restricted Groups) or Intune (Endpoint security → Account protection → Local user group membership) can define exactly who is in Administrators, and remove everyone else at every refresh. Once that's in place, a contractor's account is demoted automatically within the hour. - Audit sign-ins, not just accounts: Security log Event 4624 (logon) with Logon Type 10 (remote interactive) or 2 (console) for the accounts in question tells you whether that dormant admin is truly dormant; 4720 is an account created, 4732 a member added to a local group. Filter those two across the fleet and you see new admins the day they appear.

✅ The admin's version in one line

List enabled local accounts and Administrators members from every PC monthly, disable what nobody can name, put the built-in Administrator under LAPS, and let Restricted Groups (or Intune account protection) enforce the admins list so it can't drift again.

User account listing problems: the fix table

What you seeWhat it meansWhat to do
net user shows accounts not on the sign-in screenDisabled or built-in accountsNormal; check Enabled with Get-LocalUser
A Microsoft account shows a short odd nameLocal name is derived from the emailGet-LocalUser → PrincipalSource = MicrosoftAccount; the full name is in Settings → Accounts
Domain users missing from net userThey live on the domainUse Get-CimInstance Win32_UserProfile for who has signed in; net user /domain for the domain list
lusrmgr.msc not foundWindows HomeUse net user and Get-LocalUser
Get-LocalUser not recognizedVery old PowerShell, or you're in Command PromptOpen PowerShell or Terminal; needs 5.1+
Administrator or Guest shows Enabled = TrueSomeone enabled itDisable: net user Administrator /active:no, unless you deliberately use it under LAPS
An account you don't recognize is an adminLeftover contractor/vendor/installer accountDisable it now, delete after a month; check event 4720/4732 for when it was made
"Access is denied" listing group membersNot elevatedRun the terminal as administrator
Account exists but can't sign inDisabled, expired, or logon hours restrictednet user NAME shows all three lines
Profile folder exists for an account that isn't listedDeleted account, orphaned profileRemove via System Properties → User Profiles

Listing user accounts in Windows: the questions people search

How do I see all user accounts on Windows 11?

Open a terminal and type net user: it lists every local account, including hidden and disabled ones. For detail (enabled, last logon, local or Microsoft account), use PowerShell: Get-LocalUser | Select-Object Name, Enabled, LastLogon, PrincipalSource.

What is the command to list users in Windows?

net user for the list, net user NAME for one account's details, net localgroup Administrators for the admins. In PowerShell, Get-LocalUser and Get-LocalGroupMember Administrators.

Why do I see accounts I never created, like DefaultAccount and WDAGUtilityAccount?

They're built into Windows: DefaultAccount is the system-managed account some shared-device features use, WDAGUtilityAccount belongs to Application Guard, and Administrator and Guest are the classic built-ins. All are disabled by default and should stay that way.

How do I find out which accounts are administrators?

net localgroup Administrators or Get-LocalGroupMember -Group Administrators. On a home PC the list should be the built-in Administrator (disabled) plus the people who own the machine.

How do I see when an account last signed in?

Get-LocalUser | Select-Object Name, LastLogon. For accounts without a local entry (domain or Entra users), Get-CimInstance Win32_UserProfile shows each profile's LastUseTime.

How do I list user accounts on Windows 11 Home without lusrmgr?

net user and Get-LocalUser work on every edition. control userpasswords2 gives a GUI list of sign-in-capable accounts on Home.

How do I see hidden user accounts?

net user and Get-LocalUser show them; Settings and the sign-in screen hide disabled and built-in accounts by design.

Is the WDAGUtilityAccount a virus?

No. It's created by Windows for Windows Defender Application Guard and related isolation features, is disabled, and exists on machines that never turned Application Guard on. Leave it.

Should I enable the built-in Administrator account?

Not for everyday use. It bypasses UAC prompts and, if enabled with a weak or blank password, is an open door. In a business, manage it with Windows LAPS instead of enabling it by hand.

How do I list domain users from a Windows PC?

net user /domain for the old-style list, or Get-ADUser -Filter * with the RSAT Active Directory module installed. Locally, Get-CimInstance Win32_UserProfile shows which domain users have signed in on this PC.

How do I export the list of user accounts to a file?

Get-LocalUser | Select-Object Name, Enabled, LastLogon, PrincipalSource | Export-Csv C:\temp\accounts.csv -NoTypeInformation, or net user > C:\temp\accounts.txt.

How do IT admins find local administrator accounts on all computers?

Run Get-LocalGroupMember Administrators and Get-LocalUser through Invoke-Command against the list of PCs and export the results; then enforce the admins list with Restricted Groups or Intune account protection, and put the built-in Administrator under Windows LAPS.

What is defaultuser0?

A leftover from Windows setup on some machines. It has no usable profile and can be deleted safely; it's not a sign of anything wrong.

How do I tell a local account from a Microsoft account in the list?

Get-LocalUser → PrincipalSource: Local, MicrosoftAccount, ActiveDirectory or AzureAD.

Can I list accounts on a remote computer?

Yes: Invoke-Command -ComputerName PCNAME -ScriptBlock { Get-LocalUser } with PowerShell remoting enabled, or Get-LocalUser inside a remote session (Enter-PSSession PCNAME).

Does this work the same on Windows 10?

Yes. net user, Get-LocalUser, lusrmgr.msc and the Settings page (under Family & other users) all behave the same on Windows 10.

📖 ALSO READ

More local-AI guides, same honest voice:

⚡ Bookmark this page. The list grows as new guides land.

If your list came back with names you didn't recognize, take the thirty seconds to check which of them are Windows' own and which one is somebody's leftover; the second kind is common, rarely malicious, and always worth closing. If a screen or a name here has changed by the time you read it, tell me through the contact page; Windows adds built-in accounts between versions, and this page stays accurate because readers write in.

📌 If you keep one line from this page

net user lists every local account; Get-LocalUser adds enabled, last logon and account type; net localgroup Administrators shows who can change things.

Administrator, Guest, DefaultAccount and WDAGUtilityAccount are Windows' own and disabled; anything else should be a person or a service you can name.

Revision note. Originally published August 2015 for Windows 10; rewritten September 26, 2026, for Windows 11 25H2 and Windows 10, adding Get-LocalUser, the built-in accounts table, profiles and domain users, and the fleet audit with LAPS and Restricted Groups. Commands are current as of that date. Next check: when Windows adds or renames a built-in account. List them, name them, disable the one you can't.

Related