A PC arrives on your bench signed in with someone's personal Microsoft account: a former employee, a contractor, the cousin who set it up. The account owns the BitLocker key, the OneDrive sync and the admin rights, and the person who owns the account has left the building. Here's how to remove a Microsoft account from Windows 11 without locking the disk or stranding the user, and what to do differently when the device belongs to a company tenant.
Two Different Jobs With the Same Name
"Remove the Microsoft account" means one of two things, and the steps are different.
The first job is switching the signed-in account from a Microsoft account to a local one. The profile, files and apps stay. Only the sign-in changes. This is what people want when they say "I don't want to log into Windows with my email".
The second job is removing another user's account from the PC entirely. Microsoft's manage-user-accounts page is blunt about what that does: it "removes their sign-in information and data from the device". The Microsoft account itself keeps existing on Microsoft's side. Only its presence on this PC goes.
The Windows setting that confuses people sits between the two. Settings, then Accounts, then Email and accounts lists the account the PC is signed in with, and its Remove button is missing. That's the r/techsupport thread below in one sentence. You can't remove the account you are signed in with from under yourself. You switch it to local first, or you remove it from a different admin account.
Check the BitLocker Key Before You Touch the Account
Do this first, because it is the step that turns a five-minute job into a data loss ticket.
Microsoft's device encryption page says that when you first sign in or set up a device with a Microsoft account, or a work or school account, device encryption is turned on and a recovery key is attached to that account. The BitLocker recovery overview adds that for devices that are not Entra joined or domain joined, the Microsoft account is the default recommended place to store the recovery password. In other words: the account you are about to remove is where the key lives.
Removing the account does not decrypt the drive. The drive stays encrypted, and the next firmware update, TPM clear or motherboard swap drops it into recovery. Our BitLocker guide lists what triggers that screen. If the key only exists in a departed employee's Microsoft account, nobody can answer it.
So before anything else, from an elevated PowerShell:
powershell# What protectors exist, and is the OS drive encrypted at all manage-bde -status C: (Get-BitLockerVolume -MountPoint C:).KeyProtector # Copy the 48-digit recovery password somewhere you control (Get-BitLockerVolume -MountPoint C:).KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword' | Select-Object KeyProtectorId, RecoveryPassword
Save that password in your documentation tool or password manager under the device name. If the device is heading into a company tenant, BackupToAAD-BitLockerKeyProtector escrows it to Entra ID after the join. If it stays standalone, print it or store it with the asset record. Then, and only then, touch the account.
Switch the Signed-In Account to a Local One
This is the first job: same profile, different sign-in.
- Sign in as the Microsoft account you want to detach.
- Open Settings, then Accounts, then Your info.
- Under Account settings, select Sign in with a local account instead.
- Confirm with your PIN or password, set a local username and password, then Sign out and finish.
The profile folder, Desktop, Documents and installed apps stay where they were. What changes: settings sync stops, Microsoft Store purchases tied to the account won't update, OneDrive keeps running only if you sign into the OneDrive app separately, and Windows Hello is re-enrolled for the new local sign-in. Microsoft's Hello overview notes that Hello with a local account isn't backed by the same key-based protection as Hello with a Microsoft or Entra account, so expect a plain PIN rather than the phish-resistant kind.
Two things catch technicians here. First, the first Microsoft account on a home PC is an administrator, and switching it to local keeps it an administrator. Decide whether it should stay one; our guide on how to change the administrator covers the account type switch. Second, if the Microsoft account was also used for Office or Microsoft 365 apps, those apps keep their own sign-in and will keep working until their token expires.
Remove Another User's Microsoft Account From the PC
This is the second job, and it needs an administrator account other than the one being removed.
- Sign in as a different administrator (local or Microsoft).
- Open Settings, then Accounts, then Other users.
- Expand the account, then next to Account and data select Remove.
- Confirm Delete account and data.
Microsoft's page says what happens: the person's sign-in information and data leave the device. The C:\Users\name folder is deleted with it. If anything in it matters, copy it out first or sign in as the user and move it to a share. There is no undo.
If there is no second administrator, create one before you start. Settings, then Accounts, then Other users, then Add account, pick the "I don't have this person's sign-in information" route, then "Add a user without a Microsoft account", and set its type to Administrator. Local, no email, no sync. That account becomes the device's standing admin and the Microsoft account becomes removable.
The poster above has the classic shape of the problem: one account on the PC, it's the wrong person's, and it's the only one. The fix is the same order. Create the local admin, sign into it, remove the other.
Work or School Accounts Are a Different Animal
A personal Microsoft account and a work or school account look alike on the sign-in screen and behave nothing alike underneath.
A work or school account on a Microsoft Entra joined device isn't "added" to the PC the way a Microsoft account is. The device itself is joined to the tenant, the organization owns it, and Microsoft's Entra join page says sign-in requires an organizational account. There is no local account to switch to, because the join is the sign-in.
| What you see | What it is | How to remove it |
|---|---|---|
| Settings, Accounts, Email and accounts: an email listed under "Accounts used by other apps" | A Microsoft or work account connected for app sign-in only | Select it, Remove. Nothing else changes |
| Settings, Accounts, Access work or school: an account with Manage and Disconnect | Entra registered (personal device, work access) or Entra joined (company device) | Disconnect. On a joined device this unjoins the whole PC and needs a local admin to fall back to |
| Settings, Accounts, Your info shows a personal email | The PC's sign-in is a Microsoft account | Sign in with a local account instead |
| A second person's account under Other users | Another user profile on this PC | Remove from a different admin |
Disconnecting a work account from an Entra joined device is a device-level change, not a user-level one. Before you do it, confirm the BitLocker key is in Entra ID (Microsoft's recovery overview says that is where Entra joined devices store it, and the admin center shows it under the device's Show Recovery Key), create a local administrator, and understand that Intune policies, compliance and any conditional access that trusted the device all stop applying. The admin side is in Entra ID, Devices, and Microsoft's manage-devices page is explicit that deleting the device object there removes everything attached to it, including the BitLocker keys, and can't be reversed.
Who Gets Local Admin on an Entra Joined Device
Removing a person's account from a company PC is only half the offboarding. Local admin rights on Entra joined devices come from three places, per Microsoft's local-administrators page, and only one of them is on the device.
At join time, Entra adds the user who performed the join, the Global Administrator role and the Microsoft Entra Joined Device Local Administrator role to the local Administrators group. The last two are roles, not users: Microsoft's page says those users aren't listed in the local group at all, they get the right through their sign-in token. Removing the person's account from the PC does nothing to the role. Removing them from the role in Entra does, but the page gives it up to four hours and a sign-out to take effect.
That's why a leaver checklist for a tenant has an Entra line and a device line. Disable the user in Entra (which revokes the token on the next refresh), remove them from any admin role, and if the device is reused, remove them from the local group on the device with Remove-LocalGroupMember. The device registration setting "Registering user is added as local administrator" can be turned off so the next person who joins a PC doesn't inherit admin by default. For the longer view of who should hold which rights, see our piece on endpoint privilege management.
Stop It Happening Again: the Fleet Policy
On a managed fleet, the goal is that personal Microsoft accounts never get added to company PCs in the first place.
The Group Policy is Accounts: Block Microsoft accounts, under Computer Configuration, Windows Settings, Security Settings, Local Policies, Security Options. Microsoft documents two levels. "Users can't add Microsoft accounts" lets existing connected accounts keep signing in but blocks adding new ones or connecting a local account to one. "Users can't add or log on with Microsoft accounts" blocks both. Microsoft's own best-practice line recommends the first option when you need to limit Microsoft accounts, and notes the change applies without a restart.
The MDM equivalent is the Accounts policy CSP. Accounts/AllowMicrosoftAccountConnection set to 0 blocks using a Microsoft account for non-email connection authentication and services, and Accounts/AllowAddingNonMicrosoftAccountsManually set to 0 blocks adding non-Microsoft email accounts through the UI. Both are device scope, Pro and up, and both live under the Accounts node in Intune's settings catalog. One caution from the same page: AllowMicrosoftAccountSignInAssistant is a different switch, and disabling that service stops feature updates and Pro to Enterprise step-up activation. Leave it alone.
For the admin group itself, the LocalUsersAndGroups policy CSP (Windows 10 20H2 and later) lets Intune replace or update the local Administrators membership with named Entra users and group SIDs, so a leaver's rights go when the group policy next applies rather than when someone remembers the device. To find the PCs that still carry a stray account, a script across the fleet that lists Get-LocalUser and Get-LocalGroupMember Administrators is enough; OpenFrame can run that across a client's devices and collect each one's output.
One Last Reminder About the Account That Set the PC Up
Since the 26200 Insider builds in March 2025, Microsoft has been closing the setup-time ways to skip a Microsoft account on Windows 11 Home and Pro, so more PCs arrive with a personal account as the first administrator. On a home PC that's fine. On a business PC it means a personal account holds the BitLocker key, the admin rights and the OneDrive folder until someone removes it.
The r/windows poster above is two years in and asking if it's too late to go local. It isn't. The switch keeps everything. It's never too late to go local; it's only ever too late to copy the recovery key.
The whole procedure, in order: copy the BitLocker recovery password, create or confirm a local administrator, switch or remove the account, then set the policy so you don't do this again next quarter. For the hand-over of a PC between people rather than away from an account, our guides on changing the administrator and a clean factory reset finish the job.

"Fae" Grace Meadows
Lead AI Fairy
Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.
