在已加入Active Directory的Windows Server 2012 R2中创建无密码本地用户的解决方案咨询
Hey there, I totally get your frustration—trying to create a local user without a password on your domain-joined 2012 R2 server but hitting that password policy error is no fun. Let’s walk through exactly how to fix this:
Why you’re seeing the error
By default, both local and domain-level password policies enforce rules like minimum password length and complexity. An empty password doesn’t meet those requirements, so the system blocks the user creation. Since we’re dealing with a local user (not a domain user), we can adjust the local security policy to allow empty passwords.
Step 1: Adjust Local Security Policy
First, we need to relax the local password rules to permit empty passwords:
- Press
Win + Rto open the Run dialog, typesecpol.msc, and hit Enter to launch the Local Security Policy editor. - Navigate to Security Settings > Account Policies > Password Policy.
- Double-click on Password must meet complexity requirements and set it to Disabled, then click OK.
- Next, double-click Minimum password length, set the value to
0(this allows empty passwords), and click OK.
Step 2: Create the Local User
Now that the policy allows it, you have two easy ways to create the user:
Option 1: Graphical Interface
- Right-click on This PC and select Manage to open Computer Management.
- Expand Local Users and Groups > Users.
- Right-click on Users and choose New User.
- Fill in the username you want, leave both password fields blank.
- Uncheck User must change password at next logon (optional but recommended for this use case), then click Create.
Option 2: Command Prompt (Admin)
- Right-click the Start menu and select Command Prompt (Admin).
- Run this command to create the user (replace
MyLocalUserwith your desired username):net user MyLocalUser "" /add - If you need to add this user to a local group (like Administrators), run:
net localgroup Administrators MyLocalUser /add
Important Note
If you still run into issues after adjusting the local policy, it might be because a domain Group Policy is overriding your local settings. In that case, you’ll need to reach out to your domain administrator to either adjust the policy for this specific server or create an exception for local accounts.
备注:内容来源于stack exchange,提问作者Hoygen

