Networking August 24, 2026 5 min read

The Ultimate Guide to Resetting a Lost Windows Password

Locked out of your Windows server or PC? Discover the step-by-step professional guide to resetting local administrator passwords safely using Hiren's PE, HPE iLO, and Microsoft recovery tools.

A
azzani
2 views

Table of Contents

  • Loading table of contents...

Introduction

Losing access to a critical Windows machine—whether it's a personal workstation or an enterprise server—can bring productivity to a grinding halt. Password recovery is a delicate process, especially when handling sensitive corporate data. If done incorrectly, you risk data corruption or triggering encryption lockouts.

In this comprehensive, high-end guide, we will walk you through the most effective and professional methods to recover a lost Windows password. We will cover the industry-standard offline recovery method using Hiren's BootCD PE, enterprise-level recovery using HPE iLO, and official Microsoft fallback methods.

Crucial First Step: Check for BitLocker and EFS

Warning: Before attempting any password reset, you must verify whether the drive is encrypted with BitLocker or if the user utilizes the Encrypting File System (EFS).

  • BitLocker: If the OS drive is encrypted with BitLocker, booting from an external USB (like Hiren's PE) will prompt you for the BitLocker Recovery Key. If you do not have this 48-digit key, do not proceed. Changing the local SAM database without unlocking the drive is impossible.
  • EFS (Encrypting File System): If the user has EFS-encrypted files, resetting their password via offline tools will permanently destroy their access to those encrypted files. EFS relies on the user's original password hash to decrypt the master key.

If neither of these encryption methods is active, you are safe to proceed with the offline recovery environment.

Method 1: The Offline Recovery Environment (Hiren's BootCD PE)

Hiren's BootCD PE (Preinstallation Environment) is an indispensable tool for IT professionals. It provides a lightweight Windows 10/11 environment running entirely from a USB drive, allowing you to bypass the locked OS and directly edit the Security Account Manager (SAM) database.

Step 1: Prepare the USB Boot Drive

Download the latest Hiren's BootCD PE ISO from the official repository. Use a tool like Rufus or BalenaEtcher to create a bootable USB flash drive. Ensure your target machine's BIOS/UEFI is configured to boot from USB first.

Step 2: Boot into Hiren's PE

Insert the USB drive into the locked Windows machine and power it on. Boot into the Hiren's PE environment. You will be greeted with a familiar Windows-like desktop.

Step 3: Verify Volumes & Create a Backup Image (Optional but Recommended)

Before modifying system files, navigate to This PC to ensure the Windows OS volume (usually C:) is visible and accessible. If you cannot see the drive, you may need to load specific RAID or NVMe storage drivers.

Pro Tip: As a best practice, use the imaging tools included in Hiren's PE (like Macrium Reflect or AOMEI Backupper) to take a snapshot or image of the OS drive before making changes.

Step 4: Reset the Local Administrator Password

Hiren's PE comes pre-loaded with several password reset utilities (e.g., NT Password Edit or Lazesoft Password Recovery). Navigate to the Security > Passwords folder in the Start Menu.

  1. Launch your preferred password reset tool.
  2. Point the tool to your Windows SAM file (typically located at C:\Windows\System32\config\SAM).
  3. Select the locked user account (e.g., Administrator).
  4. Click Reset/Unlock or change the password to a temporary known value.
  5. Save the changes and exit the utility.

Step 5: Reboot Safely

Remove the USB drive and reboot the system normally. You should now be able to log in to the local Administrator account using the new password (or no password, if you cleared it). Immediately set a new, strong password.


Method 2: Enterprise Recovery via HPE iLO

If you are managing physical enterprise servers, such as Hewlett Packard Enterprise (HPE) ProLiant servers, you have access to out-of-band management via Integrated Lights-Out (iLO).

HPE iLO allows administrators to access the server's console remotely, mount virtual ISO media (like Hiren's PE), and perform low-level recovery without physical access to the data center.

Steps for HPE iLO Recovery:

  1. Log into the HPE iLO web interface using your management credentials.
  2. Navigate to the Virtual Media section.
  3. Mount the Hiren's PE ISO directly from your local machine or a network share.
  4. Open the Remote Console and reboot the server.
  5. Press F11 (or the relevant key) to open the boot menu and boot from the Virtual CD-ROM.
  6. Follow the steps outlined in Method 1 to reset the password.

Official Resource: For more detailed information on managing HPE servers and iLO configurations, refer to the HPE Support Center Documentation.


Method 3: Official Microsoft Recovery Methods

For standard consumer or corporate environments tightly integrated with Microsoft 365, offline recovery might not be necessary. Microsoft provides several built-in recovery paths.

1. Local Account Security Questions

If the machine is running Windows 10 (version 1803 or later) or Windows 11, and the user set up a local account with security questions, resetting the password is trivial. Click "Reset password" on the lock screen and answer the predefined questions.

2. Microsoft Account Recovery

If the Windows login is tied to a Microsoft Account (Outlook, Hotmail, Live), the local SAM bypass will not work correctly. Instead, you must reset the password online using another device.

  1. Visit the Microsoft password reset page on a smartphone or another PC.
  2. Verify your identity via email, SMS, or the Microsoft Authenticator app.
  3. Create a new password.
  4. Ensure the locked Windows machine is connected to the internet, and log in with the new credentials.

Conclusion & Best Practices

Resetting a lost Windows password ranges from a simple online form to a complex offline registry edit using Hiren's PE or HPE iLO. Always prioritize data safety by verifying encryption statuses (BitLocker/EFS) and making backups before altering system files.

Moving forward, implement enterprise password management solutions like Local Administrator Password Solution (LAPS) or Azure AD / Entra ID to prevent localized lockouts and ensure seamless, secure access to your infrastructure.

{# Provenance for articles generated from a source document. Rendered here rather than stored in the body so it stays accurate and cannot be edited away, and so the sealed draft stays purely generated. #}

Related Articles

Discussion 0

No comments yet. Be the first to start the discussion!

Leave a Comment