You Don't Have Permission to Shut Down This Computer: Fix for Windows 11, 10 and 7
"You don't have permission to shut down this computer" means the account you are signed in with does not hold the Windows user right called Shut down the system, or a policy has removed the Shut down command. To shut down right now, press Ctrl + Alt + Delete and use the power button in the bottom-right corner, or sign in as an administrator. To fix it for good on your own PC, open Local Security Policy (secpol.msc), go to Local Policies, User Rights Assignment, open Shut down the system, and make sure Users and Administrators are listed. On Windows Home, which has no Local Security Policy, check the NoClose registry policy instead. If it is a work or school PC, the restriction is deliberate: ask IT rather than working around it. Windows 7 users who saw this in February 2020 hit a short-lived bug, covered below.
Ethan runs the front desk at a small clinic, where three receptionists share one Windows 11 PC with their own standard accounts. One Monday, nobody could shut it down: the Start menu said they did not have permission, and the PC ran all night. Jake signed in as the administrator, ran one command to see which rights the receptionist accounts had, and found the answer in seconds: a security template applied by the old IT contractor had left only Administrators on the Shut down the system list. Adding Users back took a minute. This page explains every reason Windows shows this message, how to see which one applies to you, and how to fix each, for Windows 11, Windows 10, Windows 7 and Windows Server, including remote desktop sessions.
What "you don't have permission to shut down this computer" means
Windows decides who may turn a PC off. Shutting down affects everyone using the machine, every program running on it, and every service it provides to others, so it is a permission, not just a button. That permission is a user right called Shut down the system, known inside Windows as SeShutdownPrivilege. When your account does not hold it, Windows refuses the request and shows one of these messages:
- "You don't have permission to shut down this computer." The most common wording, shown when you choose Shut down from the Start menu.
- "You don't have permission to shut down and restart this computer." The same refusal, worded for both actions, often seen on Windows Server and in remote sessions.
- "Access is denied. (5)" from the
shutdowncommand in Command Prompt or PowerShell, which is the same refusal from the command line.
A different but related situation is when the Shut down option is simply missing from the Start menu or the power menu, with no message at all. That is usually a policy that hides the commands rather than a missing right. Both are covered below, because people often meet them together and the fixes sit side by side.
This is not the same as Windows trying to shut down and failing, getting stuck on a spinning circle, or restarting instead. If Windows accepts the command but never finishes, our guide to Windows that won't shut down covers fast startup, hung apps and wake devices. This page is about Windows saying no before it starts.
Why Windows says you don't have permission to shut down
"Why don't I have permissions on my own computer?" is the question behind most searches for this message. The causes fall into a short list.
| Cause | Where it happens | How to tell | Fix |
|---|---|---|---|
| Your account was removed from the Shut down the system right | Shared PCs, PCs with old security templates or hardening tools | whoami /priv does not list SeShutdownPrivilege | Add Users back in Local Security Policy |
| Standard user on Windows Server | Servers, including remote desktop hosts | Only Administrators and Backup Operators hold the right by default on servers | Ask an admin, or have the admin grant the right |
| Policy hides or blocks shut down | Work, school, kiosk and shared PCs | Shut down missing from Start; message on attempt | Group Policy or the NoClose registry value |
| Managed device rules | Work or school PCs managed by an organization | Settings show "managed by your organization" | Ask IT; do not bypass |
| Remote desktop session | Connecting to another PC or server | Only happens while connected remotely | Use an admin account or the shutdown command with rights |
| Windows 7 bug, February 2020 | Windows 7 PCs, suddenly, for many users at once | Started suddenly in early February 2020 | Ctrl + Alt + Delete power button; the bug faded within days |
| Corrupted user profile or broken policy | One account only, after a crash or failed update | Other accounts on the same PC can shut down | Check policies, then create a new profile |
On a home PC with one person using an administrator account, the message is rare, and when it appears it is almost always the first or third cause: something changed the user right or set a policy. On an office PC, it is usually intentional.
Shut down, restart, sleep, sign out: which actions need the right?
People often find that some power actions work and others do not, which is confusing until you see which ones depend on the same permission. Here is how each one behaves.
| Action | Needs Shut down the system? | Hidden by the Shut Down removal policy? | Notes |
|---|---|---|---|
| Shut down | Yes | Yes | The action the message is about |
| Restart | Yes | Yes | Same right as shut down; refused the same way |
| Sleep | Yes | Yes | Also needs sleep to be available in power settings |
| Hibernate | Yes | Yes | Also needs hibernation to be turned on |
| Sign out | No | No | Always available; ends your session only |
| Lock | No | No | Always available unless a separate lock policy is set |
| Switch user | No | No | Can be hidden by its own policy |
So if sign out works but shut down, restart and sleep are all refused or missing together, you are looking at the user right or the removal policy, not a broken power setting. If only sleep or hibernate is missing while shut down works, the cause is in power options instead, and our guides to missing sleep and hibernate options are the place to look.
How to shut down right now when Windows says no
Before fixing anything, you may simply need the PC off. These work in most cases, in this order.
- Ctrl + Alt + Delete. Press the three keys together. On the screen that appears, select the power icon in the bottom-right corner and choose Shut down. This route is controlled by a separate setting from the Start menu and often still works.
- Sign out, then use the sign-in screen. Sign out from the Start menu or the Ctrl + Alt + Delete screen. On the sign-in screen, use the power button in the bottom-right. Whether it appears depends on a policy covered below.
- Alt + F4 on the desktop. Click an empty part of the desktop, press Alt + F4, and choose Shut down in the box that opens. If the right is missing, this also refuses, but if the cause is only a hidden Start menu button, it works.
- Sign in as an administrator. Switch user, sign in with an administrator account, and shut down from there. Administrators hold the right on every Windows version by default.
- Use the physical power button. A short press of the PC's power button asks Windows to shut down properly, if the power button action is set to Shut down in power options. Holding the button for several seconds forces the PC off; use that only as a last resort, because open files can be damaged.
Our guide to every way to shut down or restart Windows 11 and 10 lists more routes, but all of them, including the shutdown command, are refused when the account lacks the right. That is the point of the right. If every route fails, fix the cause, and keep using Sign out at the end of the day in the meantime so nobody's session stays open on a shared PC.
Find out which cause you have
Two quick checks tell you whether the problem is the user right or a policy, which decides the fix.
Check 1: does your account have the shut down right?
Open Command Prompt as the affected user, not as administrator, and run:
whoami /priv
Look for SeShutdownPrivilege, with the description "Shut down the system". If it is listed, the account holds the right; the state column saying Disabled is normal, because Windows enables it only at the moment you shut down. If it is not listed at all, the account does not have the right, and the user rights fix below is what you need. In remote desktop sessions, you may see SeRemoteShutdownPrivilege instead or as well; that is the separate right to shut down from a remote system.
Check 2: is a policy hiding or blocking shut down?
Open Command Prompt and run:
gpresult /r
This lists the Group Policy Objects applied to the computer and the user. On a home PC you will usually see only Local Group Policy. On a work PC you will see policies from your organization's domain. For a full readable report, run gpresult /h "%USERPROFILE%\Desktop\gp.html" as administrator and open the file on your desktop; search it for "Shut Down" and "Shut down the system". You can also open rsop.msc on Pro, Enterprise and Education editions to see the combined result of all policies in a console.
If the user right is present and no policy mentions shut down, but you still get the message, the problem is most likely a damaged user profile or a third-party tool. Try a different account on the same PC. If the other account shuts down fine, the profile is the issue.
Check 3: see who shut the PC down, and when
On a shared PC it helps to know whether anyone can still shut down, and who did. Windows logs every shutdown and restart started by a person or a program. Open Event Viewer, go to Windows Logs, then System, select Filter Current Log, and enter 1074 as the event ID. Each entry names the account and the program that started the shutdown or restart, and the reason given. If the clinic PC shows entries only from the administrator account or from the system's scheduled task, standard users are not managing to shut it down, which matches the permission problem. Event ID 6008 in the same log marks an unexpected shutdown, such as someone holding the power button, which is a sign people are forcing the PC off because the normal route is refused.
Fix: give users the "Shut down the system" right again
This fixes the most common cause on Windows 11, 10 and Server Pro, Enterprise and Education editions. You need an administrator account.
- Press Windows + R, type
secpol.mscand press Enter. Local Security Policy opens. - In the left pane, open Local Policies, then User Rights Assignment.
- In the right pane, double-click Shut down the system.
- Check the list. On a Windows 11 or 10 PC it should normally include Administrators, Backup Operators and Users.
- If Users is missing, select Add User or Group, type
Users, select Check Names, then OK. - Select OK, close the window, and have the affected people sign out and sign back in. The right takes effect at the next sign-in.
If the Add User or Group button is grayed out, a domain policy controls this right and local changes are blocked. On a work PC, that is IT's setting. On a PC that left a company or school but still carries old policies, the PC may need to be removed from the domain or reset.
Here are the default members of the two shutdown rights, so you can compare with what you see.
| User right | Windows 11 and 10 (workstations) | Windows Server (member servers) | Domain controllers |
|---|---|---|---|
| Shut down the system (SeShutdownPrivilege) | Administrators, Backup Operators, Users | Administrators, Backup Operators | Administrators, Backup Operators, Server Operators, Print Operators |
| Force shutdown from a remote system (SeRemoteShutdownPrivilege) | Administrators | Administrators | Administrators, Server Operators |
If you prefer to grant the right only to specific people rather than all users, add their accounts or a group instead of Users. On a shared clinic PC like Ethan's, adding Users is right; on a server, adding individual trusted accounts is safer.
On Windows Home editions, secpol.msc is not included. User rights on Home are rarely changed, so if you see the message on Home, the policy section below is the more likely cause. Administrators can still export and inspect rights with the built-in secedit command; secedit /export /cfg "%USERPROFILE%\Desktop\rights.inf" /areas USER_RIGHTS run as administrator writes the current rights to a text file, where SeShutdownPrivilege lists the groups that hold it by their security identifiers. *S-1-5-32-545 is Users and *S-1-5-32-544 is Administrators.
Domain administrators: set the right with Group Policy
On PCs joined to an Active Directory domain, set the right centrally rather than PC by PC. In the Group Policy Management Console, edit the policy linked to the computers' organizational unit and go to Computer Configuration, Policies, Windows Settings, Security Settings, Local Policies, User Rights Assignment, Shut down the system. Define it with every group that should hold it. A defined domain setting replaces the local list completely, so include Administrators and Backup Operators along with Users or your chosen group; leaving a group out removes it on every PC the policy reaches. That replacement behavior is how many offices end up with the problem in the first place: a policy written for servers gets linked to workstations too.
Fix: Shut Down removed by policy (Group Policy and registry)
A separate policy can remove Shut Down, Restart, Sleep and Hibernate from the Start menu and the Ctrl + Alt + Delete screen, and block them for that user. Schools, kiosks and shared PCs use it to stop people turning machines off. If it was set on your PC by accident, or by an old tool, here is how to undo it.
With Group Policy (Pro, Enterprise, Education)
- Press Windows + R, type
gpedit.mscand press Enter. - Go to User Configuration, Administrative Templates, Start Menu and Taskbar.
- Find Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands.
- If it says Enabled, double-click it, choose Not Configured, and select OK.
- Open Command Prompt and run
gpupdate /force, then sign out and back in.
With the registry (all editions, including Home)
The same policy is stored as a registry value named NoClose. Back up the registry or create a restore point first.
- Press Windows + R, type
regeditand press Enter. - Go to
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer. - If there is a value named NoClose set to 1, delete it or set it to 0.
- Check the same path under
HKEY_LOCAL_MACHINE, which applies to all users, and do the same. - Sign out and back in, or restart.
From an administrator Command Prompt, the same fix for the current user is reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoClose /f. If the value comes back after a restart, something is setting it: a domain policy, device management, or a third-party lockdown tool.
Last resort on your own PC: reset local security settings to default
If an old hardening tool, a downloaded tweak pack or a forgotten template changed many security settings at once, and you cannot tell which, you can put the local security settings back to the Windows defaults in one command. This works on every edition, including Home, because it uses the built-in secedit tool rather than the Local Security Policy console. Do not do this on a work or school PC, and do not do it on a server; it is meant for a standalone home or small-office PC.
- Create a restore point first: search the Start menu for Create a restore point and select Create.
- Open Command Prompt as administrator.
- Run:
secedit /configure /cfg %windir%\inf\defltbase.inf /db defltbase.sdb /verbose - Wait for it to finish. It may report that some settings could not be applied; that is common and usually harmless.
- Restart the PC and test shutting down from a standard account.
This resets user rights such as Shut down the system, and security options, to the defaults Windows ships with. It does not delete your files or apps. It does undo any security settings you set on purpose, such as password rules, so note those first and set them again afterward. In most cases the targeted fixes above are better; this is for the PC that has been tweaked so many times that nobody knows what was changed.
A related cause on small-business PCs is a security baseline or hardening checklist written for servers and applied to desk PCs as well. Server baselines rightly limit Shut down the system to Administrators. On a receptionist's PC that means nobody can shut down at the end of the day. If your PCs were hardened by a consultant or a tool, ask which baseline was used and whether a workstation version exists; workstation baselines normally keep Users on the list.
Shut down from the sign-in screen: a separate setting
Whether the power button appears on the sign-in screen, before anyone signs in, is controlled by a different setting: the security option Shutdown: Allow system to be shut down without having to log on. It is enabled by default on Windows 11 and 10 and disabled by default on Windows Server.
- Open
secpol.msc. - Go to Local Policies, then Security Options.
- Double-click Shutdown: Allow system to be shut down without having to log on, choose Enabled or Disabled, and select OK.
On Home editions, the same setting is the registry value shutdownwithoutlogon under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System: 1 shows the button, 0 hides it. Our guides to the power button missing on the sign-in screen and to hiding it on purpose cover both directions in detail.
Remote desktop and Windows Server: "you don't have permission to shut down and restart"
Many people first see this message on a Windows Server or through Remote Desktop. That is by design. On servers, the Shut down the system right belongs only to Administrators and Backup Operators by default, because turning a server off affects everyone using it. A standard user signed in to a remote desktop host cannot shut it down, and should not be able to.
If you are an administrator connected through Remote Desktop and want to restart the remote machine, the Start menu power options can differ in a remote session, so the reliable way is the command line in the remote session:
shutdown /r /t 0
Use /s instead of /r to shut down instead of restart; but think twice before shutting down a remote PC, because you cannot turn it back on remotely unless it supports remote power-on. To shut down another computer from yours, without a remote desktop session, the account needs the Force shutdown from a remote system right on the target, which only Administrators hold by default. Our guide to remote shutdown with the command and PowerShell covers the firewall and permission setup.
For a server where some non-admin staff do need to restart it, grant the right to a specific group in Local Security Policy or through domain Group Policy, rather than making those people administrators. That keeps the permission narrow and visible.
Shutting down with PowerShell and the shutdown command
The command-line tools follow exactly the same rules as the Start menu. They do not bypass the right; they only make the refusal easier to read. On the local PC:
shutdown /s /t 0
shutdown /r /t 0
Stop-Computer
Restart-Computer
The first two lines are Command Prompt, shut down and restart now; the last two are the PowerShell equivalents. If the account lacks the right, the shutdown command returns Access is denied. (5) and PowerShell returns a privilege error. Neither needs an elevated window on a workstation when the account holds the right, because the right belongs to the account, not to administrator mode. On a server, run them from an administrator account.
For another computer, add the computer name: shutdown /r /m \\PC-NAME /t 60 or Restart-Computer -ComputerName PC-NAME. Those need the Force shutdown from a remote system right on the target, which only Administrators hold by default, plus network access through the firewall. Our guide to running Command Prompt as administrator shows how to open an elevated window when you need one.
On a work or school PC: why IT blocks shut down
If your PC belongs to an employer or school, the restriction is very likely intentional. Common reasons:
- Overnight updates and backups need the PC on. Turning it off at night delays security updates.
- Shared and kiosk PCs in reception areas, libraries and classrooms are kept running so the next person can use them.
- Remote support needs the PC reachable.
- Lab and exam PCs must not be restarted mid-session.
Signs that the PC is managed include a message in Settings saying some settings are managed by your organization, a work or school account under Settings, Accounts, Access work or school, and domain policies in gpresult /r. In that case, do not try to work around it with registry edits or tools; ask IT. They can grant the right, add a scheduled restart, or explain the rule. Working around a managed setting can break compliance rules and will often be undone automatically at the next policy refresh anyway.
A PC set up as a kiosk, using Windows assigned access to run a single app, hides the Start menu and power options entirely. That is a different setup from the permission message; only an administrator can leave kiosk mode, usually by pressing Ctrl + Alt + Delete and signing in with an administrator account.
Let a shared PC shut down on schedule without giving everyone the right
Some offices want the PC off every night but do not want every user able to shut it down during the day, for example a shared PC that must stay on for appointments. The clean answer is a scheduled task that runs as the system account, which always holds the right, so no user needs it.
- Sign in as an administrator and open Task Scheduler from the Start menu.
- Select Create Task, not Create Basic Task, so you can set the account.
- On the General tab, name it, select Change User or Group, type
SYSTEM, and select OK. Check Run with highest privileges. - On the Triggers tab, add a Daily trigger at your closing time.
- On the Actions tab, add Start a program with program
shutdown.exeand arguments/s /t 300 /c "Closing time: save your work, the PC shuts down in 5 minutes." - Select OK. The PC will warn users and shut down every evening, whatever their own rights.
The five-minute delay gives anyone still working time to save, and an administrator can cancel it with shutdown /a. Our guide to scheduling an automatic shutdown covers timers and other options. Ethan's clinic now uses exactly this: receptionists can shut down at closing time, and if they forget, the task does it at 8 p.m.
The Windows 7 shutdown permission bug of February 2020
In early February 2020, a few weeks after Windows 7 support ended, many Windows 7 users suddenly could not shut down. Choosing Shut down from the Start menu showed "You don't have permission to shut down this computer", on home PCs where the person was clearly the administrator. It appeared on many unrelated PCs at the same time, which pointed to an update rather than anything users had changed. Reports at the time linked it to an update of a third-party background service, and it faded within days as that was corrected.
The workarounds people used then still work for any Windows 7 PC with this message:
- Ctrl + Alt + Delete, then the power button in the bottom-right corner. This was the most reliable workaround.
- A clean boot. Press Windows + R, type
msconfig, open the Services tab, check Hide all Microsoft services, select Disable all, and restart. If shutdown then works, a third-party service is the cause; turn services back on a few at a time to find it, then update or remove that program. - The shutdown command from an administrator Command Prompt:
shutdown /s /t 0.
Our original 2020 version of this page also suggested enabling User Account Control: Run all administrators in Admin Approval Mode in Group Policy. That setting is on by default in Windows 7, 8.1, 10 and 11, and turning it off weakens security and breaks some apps, so check that it is enabled rather than changing it. Windows 7 has had no security updates since January 2020 for home users, so if you are still on it, the bigger fix is moving to a supported version.
Is UAC or a standard account the problem?
No, not by itself. A standard account can shut down a Windows 11 or 10 PC normally, because the Users group holds the Shut down the system right by default. Being a standard user is not a reason for this message; a changed right or a policy is. You do not need to make everyone an administrator to fix it, and you should not.
Likewise, User Account Control does not block shutting down. UAC prompts appear when a program asks for administrator rights. Shutting down does not need them on a workstation. If our page on UAC settings in Windows 11 and 10 led you here, leave UAC on: it is not involved.
Where account type does matter is the fix. Changing user rights or policies needs an administrator. If the only administrator account is lost or locked, you will need to recover it before you can fix the shutdown right. If you are an administrator and still get "access denied" on settings and files across the PC, our guide to access denied even though you are the administrator covers ownership and permission problems beyond shutdown.
When only one account is affected
If every other account on the PC can shut down, the rights and machine policies are fine, and the problem is that one user's settings. In order:
- Check
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorerfor NoClose while signed in as that user, as described above. - Check whether a parental control, family safety or lockdown app is installed for that account.
- Check whether the account is a member of an unusual group, in Computer Management, Local Users and Groups on Pro editions, or with
net user USERNAMEin Command Prompt. - Run
sfc /scannowfrom an administrator Command Prompt to repair damaged system files. - If nothing else works, create a new user account, move the files across, and stop using the old one. A damaged profile is rare, but a new one fixes it completely.
At Ethan's clinic it was the opposite: every standard account was affected and the administrator was not, which pointed straight at the user right. That pattern alone tells you which section to read.
Frequently asked questions
What does "you don't have permission to shut down this computer" mean?
It means your account does not hold the Windows user right Shut down the system, or a policy has removed the shut down command. Windows treats shutting down as a permission because it affects everyone and every program on the PC.
How do I fix "you don't have permission to shut down this computer" in Windows 11?
Sign in as an administrator, open secpol.msc, go to Local Policies, User Rights Assignment, open Shut down the system, and add Users if it is missing. Then check that the policy Remove and prevent access to the Shut Down commands is Not Configured, or that the NoClose registry value is absent. Sign out and back in.
How do I fix it in Windows 10?
The fix is the same as Windows 11: restore the Shut down the system right in Local Security Policy, clear the Shut Down removal policy in gpedit.msc or the NoClose registry value, and sign out and back in. Windows 10 Home has no secpol.msc, so check the registry policy first.
How can I shut down if I don't have permission?
Try Ctrl + Alt + Delete and the power icon in the bottom-right corner, sign out and use the sign-in screen power button, or sign in as an administrator. If none of these work, the right itself is missing, and only an administrator can fix it or shut the PC down.
Why don't I have permissions on my own computer?
Usually because something changed the defaults: an old security template, a hardening or lockdown tool, a former work or school policy, or a parental control app. On your own PC, an administrator account can restore the Shut down the system right and clear the policies.
Can a standard user shut down Windows 11?
Yes. On Windows 11 and 10 workstations, the Users group holds the Shut down the system right by default, so standard accounts can shut down normally. If they cannot, the right or a policy has been changed.
Why can't I shut down a Windows Server in remote desktop?
On Windows Server, only Administrators and Backup Operators hold the Shut down the system right by default. Standard users signed in to a server or remote desktop host cannot shut it down by design. An administrator can restart it with shutdown /r /t 0 in the session.
What is SeShutdownPrivilege?
It is the internal name of the Shut down the system user right. Run whoami /priv to see whether your account holds it. If it is listed, even as Disabled, you have the right; Windows enables it only when you shut down. If it is not listed, you do not.
What does "Access is denied (5)" mean when I run the shutdown command?
The shutdown command is refused for the same reason as the Start menu message: the account lacks the Shut down the system right, or, for a remote computer, the Force shutdown from a remote system right on the target. Run the command from an administrator account.
Why is there no shutdown option in Windows 11?
A policy is probably hiding it: Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands in Group Policy, or the NoClose registry value. On the sign-in screen, the separate setting Shutdown: Allow system to be shut down without having to log on controls the power button.
How do I remove the NoClose policy?
Open regedit, go to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, and delete NoClose or set it to 0. Check the same path under HKEY_LOCAL_MACHINE. Sign out and back in. If it returns, a domain policy or management tool is setting it.
What caused the Windows 7 shutdown permission bug in 2020?
In February 2020 many Windows 7 users suddenly got the message after support ended. Reports linked it to an update of a third-party background service, and it faded within days. Ctrl + Alt + Delete and the power button, or a clean boot, worked around it.
Does turning off UAC fix the shutdown permission error?
No. User Account Control does not control shutting down, and turning it off weakens security. Leave UAC on and fix the Shut down the system right or the shut down policy instead.
Can I shut down a work computer that says I don't have permission?
Only in the ways your organization allows. Managed PCs often block shutting down so updates, backups and remote support can run overnight. Ask IT rather than changing policies; workarounds are usually reversed at the next policy refresh and may break workplace rules.
How do I let only some users shut down a shared PC?
In secpol.msc, under User Rights Assignment, Shut down the system, remove Users and add the specific accounts or a group you create for them, keeping Administrators. Everyone else will see the permission message.
Why can one account shut down but another cannot?
The machine rights are fine, so the difference is in the affected account: a NoClose value in its own registry, a parental control or lockdown app, unusual group membership, or a damaged profile. Check those in order, and create a new account if nothing else works.
Is "you don't have permission to shut down" a virus?
Not normally. It is a genuine Windows message about rights and policies. Malware rarely causes it, but if it appeared at the same time as other strange behavior, run a full scan with Windows Security after you restore shutdown.
Is this the same as Windows not shutting down?
No. This message means Windows refuses to start shutting down. If Windows starts shutting down but hangs, restarts instead, or never turns off, the causes are fast startup, hung programs, drivers or wake devices, which need different fixes.
How can I see who shut down or restarted a Windows PC?
Open Event Viewer, go to Windows Logs, System, and filter for event ID 1074. Each entry shows the account and program that started the shutdown or restart. Event ID 6008 marks an unexpected shutdown, such as a forced power-off.
How do I reset user rights to the Windows defaults?
On a standalone home or small-office PC, create a restore point, open Command Prompt as administrator and run secedit /configure /cfg %windir%\inf\defltbase.inf /db defltbase.sdb /verbose, then restart. It resets local security settings, including Shut down the system, to defaults. Do not use it on managed PCs or servers.
The shutdown permission message looks like Windows has turned against you, but it is only Windows enforcing a rule someone set. Find which rule with whoami /priv and gpresult /r, restore the user right or clear the policy on your own PC, and leave a managed PC's rules to IT. Ethan's receptionists can shut down at closing time again, the old security template is gone, and the clinic's PC now sleeps at night instead of running until morning.
📌 If you keep one line from this page
No permission to shut down means the Shut down the system right or a NoClose policy: check with whoami /priv, fix in secpol.msc or the registry.
Ctrl + Alt + Delete and the power icon is the quickest way off in the meantime.
Revision note. Written October 3, 2026, rewriting our February 2020 post about the Windows 7 shutdown permission bug into a complete guide for Windows 11, 10, 7 and Server. It now covers the Shut down the system user right and its defaults, how to check it with whoami and gpresult, the NoClose policy for all editions, the sign-in screen setting, remote desktop and servers, managed PCs, and single-account problems. The Windows 7 section keeps the original workarounds and corrects our old Admin Approval Mode advice. May your PC always turn off when you ask it to.