“‘sudo’ is not recognized as an internal or external command” or “Sudo is disabled on this machine” means Sudo for Windows is either missing from your PC or switched off. On Windows 11 24H2 or later, turn on Enable sudo in Settings > System > Advanced, then type sudo in front of any command that fails with “The requested operation requires elevation.” You still approve the elevation through a UAC prompt.
What Is Sudo for Windows?
Sudo for Windows is a command built into Windows 11. It lets you run one command with administrator rights from a normal Terminal, PowerShell, or Command Prompt window. You don’t need to close your session and reopen Terminal (Admin).
It borrows its name from the sudo command on Linux and macOS, but it is not a port of that tool. Microsoft wrote its own version on top of Windows’ User Account Control (UAC) and released the code as open source under the MIT license on GitHub. The other differences from Linux sudo:
- It does not ask for your password in the terminal. It can only elevate through Windows’ User Account Control (UAC) prompt.
- It does not have a
sudoersfile. - It ships with Windows, so there is nothing to download or buy.
Sudo for Windows is not a UAC bypass. It is a quicker way to request elevation, and Microsoft says it “can only be elevated via the User Account Control (UAC) security feature” (Microsoft Learn: Sudo for Windows).
Before You Begin
Make sure you have:
- Windows 11, version 24H2 or later. Sudo is not available on Windows 10 or on Windows 11 23H2 and earlier (What’s new in Windows 11, version 24H2). Note that 24H2 Home and Pro editions reach end of servicing on October 13, 2026, so plan to move to 25H2 or 26H2, which also include sudo (Windows 11 Home and Pro lifecycle).
- A way to approve UAC. On an administrator account you click Yes on a consent prompt. On a standard account, UAC asks for an administrator’s user name and password instead, so you need those credentials (How User Account Control works).
- A device your workplace doesn’t lock down. Organizational policy can disable sudo or limit which modes you can use.
- Windows Terminal, PowerShell, or Command Prompt.
| Requirement | Details |
|---|---|
| Device | Any Windows PC |
| OS version | Windows 11, version 24H2 (build 26100) or later |
| Account | Administrator (consent prompt), or standard user with admin credentials |
| Cost | Free, included with Windows 11 |
| Other platforms | None. Sudo for Windows is Windows-only |
Step-by-Step Guide
Step 1: Check Your Windows 11 Version
- Press
Windows + Rto open the Run box. - Type
winverand pressEnter. - Read the line under Microsoft Windows. You need Version 24H2 (OS Build 26100.x) or newer, such as 25H2 (OS Build 26200.x).
Expected result: The dialog shows 24H2 or a later version. If it shows 23H2 or older, go to Step 2. Otherwise, skip to Step 3.
Step 2: Update to Windows 11 24H2 (If Needed)
- Open Settings > Windows Update.
- Click Check for updates.
- Install the offered Windows 11 feature update. Pick the newest version offered (25H2 or 26H2), since 24H2 Home and Pro stop receiving updates after October 13, 2026. You don’t need optional preview updates to get sudo.
- Restart your PC when prompted.
- Run
winveragain to confirm the new version.
Feature updates need plenty of free disk space. If your drive is nearly full, clear out old files first. On an older laptop, an SSD upgrade solves both the space and speed problems.
Step 3: Open the Sudo Setting
Microsoft documents the toggle under System > Advanced. Check these locations in order:
- Open Settings > System > Advanced, and look for Enable sudo.
- If it’s not there, open Settings > System > For developers (older builds and sudo’s own error message still call this the Developer Settings page).
- If you can’t find it in either place, click the search box at the top of Settings and type:
sudo
Then select Enable sudo from the results.
Step 4: Turn On Enable Sudo
- Switch the Enable sudo toggle to On.
- Click Yes on the UAC prompt. If you use a standard account, enter administrator credentials.
Expected result: The toggle stays on, and a mode dropdown appears next to it or below it.
Step 5: Choose a Sudo Mode
Open the dropdown labeled Configure how sudo runs applications and pick one of the three modes. The table below explains what each mode does.
| Mode in Settings | Config name | What happens | Security trade-off |
|---|---|---|---|
| In a new window (default) | forceNewWindow | The elevated command opens in a separate console window | Most isolated. Your normal window can’t interact with the elevated one |
| Input closed | disableInput | The command runs in your current window but can’t accept keyboard input | Good middle ground for non-interactive commands such as sfc or netstat |
| Inline | normal | The command runs in your current window with full input and output, like Linux sudo | Least isolated. Other non-admin processes on the same console could interact with the elevated one |
Which one to pick: Microsoft recommends keeping the default, In a new window, unless you understand and accept the risks of the other two modes. If you mostly run non-interactive commands such as sfc or netstat and want the output in your current window, Input closed is a reasonable compromise, but any command that asks a question (such as a Y/N confirmation) can’t receive your answer in that mode. Use Inline only if you need interactive elevated commands and trust everything running on your PC (Microsoft Learn: sudo configuration options).
Step 6: Open a Fresh Terminal Window
- Close any Terminal, PowerShell, or Command Prompt windows that are open.
- Right-click Start and choose Terminal. Don’t choose Terminal (Admin), because the goal is a normal window.
Windows that were already open usually pick up sudo too. Starting a fresh one simply rules that out if something doesn’t work.
Step 7: Run Your First Sudo Command
Try a command that fails without admin rights. In a normal window, this command:
netstat -ab
typically fails with “The requested operation requires elevation.” because the -b switch needs admin rights. Now add sudo in front:
sudo netstat -ab
Expected result: A UAC prompt asks you to verify that you want to continue. Click Yes (or enter admin credentials on a standard account). A list of connections appears, each with the program that created it. In In a new window mode, that list appears in a new console window. In the other two modes, it prints in your current window, as in the screenshot below. For a graphical view of the same traffic, see our guide to monitoring network traffic with Sniffnet.
Some other useful examples:
sudo sfc /scannow
Without sudo, this command returns “You must be an administrator running a console session in order to use the SFC utility.” With sudo, it starts the scan and ends with a result line such as “Windows Resource Protection did not find any integrity violations.”
sudo dism /online /cleanup-image /scanhealth
This should finish with “No component store corruption detected.” or a corruption report, followed by “The operation completed successfully.”
sudo notepad C:\Windows\System32\drivers\etc\hosts
This opens Notepad with admin rights, so you can save changes to the hosts file. Copy the original file to a USB flash drive or external SSD before you edit anything in System32.
Step 8 (Optional): Change the Mode From the Command Line
You can switch modes without opening Settings. Changing the mode with sudo config --enable must be done from an elevated window; from a normal window, sudo replies “You must run this command as an administrator.” (sudo source code).
- Right-click Start and choose Terminal (Admin).
- Click Yes on the UAC prompt.
- Run the command for the mode you want:
sudo config --enable disableInput
Configuration Reference
The --enable commands need an elevated Terminal. Plain sudo config only reads the setting, so it works in a normal window and prints a line such as “Sudo is currently in Force New Window mode on this machine.”
| Command | Result |
|---|---|
sudo config | Shows the current sudo mode |
sudo config --enable forceNewWindow | Switches to the In a new window mode |
sudo config --enable disableInput | Switches to the Input closed mode |
sudo config --enable normal | Switches to the Inline mode |
sudo config --enable disable | Turns sudo off |
PowerShell cmdlets need a wrapper. Sudo launches the command line you give it as a new elevated process. PowerShell cmdlets, aliases and functions only exist inside a running PowerShell session, so sudo Restart-Service Spooler won’t work on its own. Run it through PowerShell like this:
sudo powershell -Command "Restart-Service Spooler"
If you use PowerShell 7, swap powershell for pwsh. The microsoft/sudo repository also includes an optional sudo.ps1 helper script (in its scripts folder) that makes sudo friendlier to use from PowerShell.
Sudo vs. Task Scheduler: Which One Do You Need?
These two tools solve different problems.
- Sudo elevates individual commands on demand from a terminal. Each one still goes through a UAC prompt.
- A Task Scheduler task set to “Run with highest privileges” launches one specific app elevated with no UAC prompt at all. Use it for a single trusted tool you open every day.
If your real goal is to stop the UAC prompts for a particular app, sudo won’t help. See HDG’s guide How to Run Apps as Administrator Without UAC Prompts for the Task Scheduler method. Sudo also doesn’t elevate desktop shortcuts or Start menu entries. It only works on the command line.
Fixing Common Sudo Problems
Fix #1: Restart Your Terminal
Close every Terminal, PowerShell, and Command Prompt window. Then open a new one. If you ran Terminal elevated before you enabled sudo, close that window too. Try sudo netstat -ab again.
Fix #2: Turn On the Toggle
You may see “Sudo is disabled on this machine. To enable it, go to the Developer Settings page in the Settings app.” This means sudo is installed but switched off.
- Open Settings > System > Advanced, or For developers on some builds.
- Switch Enable sudo to On.
- Approve the UAC prompt.
Fix #3: Confirm Your Windows Version
You may see this error in Command Prompt:
‘sudo’ is not recognized as an internal or external command, operable program or batch file.
Or this one in PowerShell:
sudo : The term ‘sudo’ is not recognized as the name of a cmdlet, function, script file, or operable program.
Either error means sudo.exe isn’t on your system.
- Run
winver. - If the version is below 24H2, or the PC runs Windows 10, sudo isn’t available. Update by following Step 2 above.
- If you installed gsudo or another third-party tool earlier, check that it isn’t overriding the built-in command. Running
where.exe sudoshould point toC:\Windows\System32\sudo.exe.
Fix #4: Run sudo config From an Elevated Window
If sudo config --enable replies “You must run this command as an administrator.”, you ran it from a normal window. Open Terminal (Admin) and run the command again. If it instead says “You cannot set a mode higher than…”, a policy on your PC caps the allowed mode (see Fix #6).
Fix #5: Switch Modes for Interactive Commands
If a sudo command ignores your typing, you’re in Input closed mode. Switch to Inline in Settings, or run sudo config --enable normal from an elevated Terminal. Only do this if you trust what runs on your PC.
Fix #6: Check for a Policy Block
On work or school PCs, the Enable sudo toggle may be grayed out or say it’s managed by your organization. Running sudo may print “Sudo is disabled by your organization’s policy.” An administrator has disabled or restricted sudo through Group Policy (Computer Configuration > Administrative Templates > System > Configure the behavior of the sudo command) or through an MDM tool such as Intune (Sudo Policy CSP). Ask your IT team. Don’t try to override the policy.
Security Considerations
- UAC still applies. Sudo can only elevate through UAC, so with normal UAC settings each sudo command brings up a UAC prompt. If a sudo prompt appears that you didn’t start, click No and scan for malware.
- Inline and Input closed carry extra risk. Microsoft warns that malicious processes could try to drive the elevated process through the connection between the unelevated and elevated sudo.exe. Input closed mitigates this by closing the input handle; Inline lets unelevated processes in the same console send input or read output. The default In a new window mode avoids both.
- Read before you run. Sudo makes elevation so easy that it’s tempting to paste admin commands from forum posts without reading them. Read each command first, and back up important data before running anything that changes system files. If a power cut during a long DISM repair would worry you, plug the PC into a UPS.
Wrapping Up
For most people, Microsoft’s default In a new window mode is the safest choice. Switch to Input closed if you want output in your current window and mainly run non-interactive commands. Expect UAC prompts to continue, because that’s by design. If sudo stops working after a Windows update, check that the toggle is still on. If elevated commands like sfc keep finding corruption that won’t repair, suspect a failing drive or malware.
| Step | Action | Applies To |
|---|---|---|
| 1–2 | Confirm or update to 24H2 with winver | Windows 11 |
| 3–5 | Turn on Enable sudo and pick a mode | Windows 11 24H2+ |
| 6–7 | Run sudo <command> in a normal Terminal | Windows 11 24H2+ |
| 8 | Change modes with sudo config --enable | Elevated Terminal |
Resources
Sources retrieved October 3, 2026: