Remove Unauthorised User Accounts From Windows

    Safely back up data from a suspicious account, demote it from Administrator, and delete it without losing your own files.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 2 min read

    Step 1: Sign in to your own admin account

    Make sure you are signed in to your account and that it is an administrator. If your account has been demoted, sign in instead to the built-in Administrator (Step 5 below has a fallback).

    Step 2: Inspect the suspicious account before deleting

    Open C:\Users\<suspicious-account-name> in File Explorer. If it contains files you actually want to keep, copy them to your own user folder first.
    Take a screenshot of the account properties (Settings → Accounts → Other users → click the account) — useful if you ever need to report this.

    Step 3: Demote then delete

    Settings → Accounts → Other users → click the suspicious account → Change account type → set to Standard User. This immediately strips its admin powers.
    Then click RemoveDelete account and data.

    Important

    Removing the account also deletes its profile folder. Make sure you copied anything important first.

    Step 4: Reset your own password

    Whoever created the extra account had admin access — they may also know or have changed your password. Reset it now from Settings → Accounts → Sign-in options → Password → Change.
    Use a long, unique password stored in your password manager.

    Step 5: If your own account was demoted

    Reboot, then on the sign-in screen press Shift 5 times rapidly to confirm Sticky Keys is disabled (a common attacker backdoor).
    Sign in with the built-in Administrator account if it is enabled, or boot from a Windows installer USB and use 'Repair your computer → Troubleshoot → Command Prompt' to run net localgroup administrators <your-username> /add.

    Important

    If you cannot recover admin access, a clean reinstall of Windows is faster and safer than fighting for control. Back up your files to an external drive first.

    Step 6: Run a malware sweep

    Whoever created the account got in somehow. Run Malwarebytes and a Defender offline scan to find the entry point — usually a remote-access tool or a credential-stealer.

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Device Security