How to Enable and Use Sudo for Windows 11 (24H2 and Later)

12 min read

Help Desk Geek is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

“‘sudo’ is not recognized as an internal or external command” or “Sudo is disabled on this machine” means Sudo for Windows is either missing from your PC or switched off. On Windows 11 24H2 or later, turn on Enable sudo in Settings > System > Advanced, then type sudo in front of any command that fails with “The requested operation requires elevation.” You still approve the elevation through a UAC prompt.

What Is Sudo for Windows?

Sudo for Windows is a command built into Windows 11. It lets you run one command with administrator rights from a normal Terminal, PowerShell, or Command Prompt window. You don’t need to close your session and reopen Terminal (Admin).

It borrows its name from the sudo command on Linux and macOS, but it is not a port of that tool. Microsoft wrote its own version on top of Windows’ User Account Control (UAC) and released the code as open source under the MIT license on GitHub. The other differences from Linux sudo:

  • It does not ask for your password in the terminal. It can only elevate through Windows’ User Account Control (UAC) prompt.
  • It does not have a sudoers file.
  • It ships with Windows, so there is nothing to download or buy.

Sudo for Windows is not a UAC bypass. It is a quicker way to request elevation, and Microsoft says it “can only be elevated via the User Account Control (UAC) security feature” (Microsoft Learn: Sudo for Windows).

Before You Begin

Make sure you have:

  • Windows 11, version 24H2 or later. Sudo is not available on Windows 10 or on Windows 11 23H2 and earlier (What’s new in Windows 11, version 24H2). Note that 24H2 Home and Pro editions reach end of servicing on October 13, 2026, so plan to move to 25H2 or 26H2, which also include sudo (Windows 11 Home and Pro lifecycle).
  • A way to approve UAC. On an administrator account you click Yes on a consent prompt. On a standard account, UAC asks for an administrator’s user name and password instead, so you need those credentials (How User Account Control works).
  • A device your workplace doesn’t lock down. Organizational policy can disable sudo or limit which modes you can use.
  • Windows Terminal, PowerShell, or Command Prompt.
RequirementDetails
DeviceAny Windows PC
OS versionWindows 11, version 24H2 (build 26100) or later
AccountAdministrator (consent prompt), or standard user with admin credentials
CostFree, included with Windows 11
Other platformsNone. Sudo for Windows is Windows-only

Step-by-Step Guide

Step 1: Check Your Windows 11 Version

  • Press Windows + R to open the Run box.
  • Type winver and press Enter.
  • Read the line under Microsoft Windows. You need Version 24H2 (OS Build 26100.x) or newer, such as 25H2 (OS Build 26200.x).
About Windows dialog opened from winver showing Windows 11 Version 24H2 with OS Build number highlighted

Expected result: The dialog shows 24H2 or a later version. If it shows 23H2 or older, go to Step 2. Otherwise, skip to Step 3.

Step 2: Update to Windows 11 24H2 (If Needed)

  • Open Settings > Windows Update.
  • Click Check for updates.
  • Install the offered Windows 11 feature update. Pick the newest version offered (25H2 or 26H2), since 24H2 Home and Pro stop receiving updates after October 13, 2026. You don’t need optional preview updates to get sudo.
  • Restart your PC when prompted.
  • Run winver again to confirm the new version.

Feature updates need plenty of free disk space. If your drive is nearly full, clear out old files first. On an older laptop, an SSD upgrade solves both the space and speed problems.

Step 3: Open the Sudo Setting

Microsoft documents the toggle under System > Advanced. Check these locations in order:

  • Open Settings > System > Advanced, and look for Enable sudo.
  • If it’s not there, open Settings > System > For developers (older builds and sudo’s own error message still call this the Developer Settings page).
  • If you can’t find it in either place, click the search box at the top of Settings and type:

sudo

Then select Enable sudo from the results.

Windows 11 Settings > System > Advanced page with Enable sudo turned on and the Configure how sudo runs applications dropdown open, showing In a new window, Input closed, and Inline.

Step 4: Turn On Enable Sudo

  • Switch the Enable sudo toggle to On.
  • Click Yes on the UAC prompt. If you use a standard account, enter administrator credentials.

Expected result: The toggle stays on, and a mode dropdown appears next to it or below it.

Step 5: Choose a Sudo Mode

Open the dropdown labeled Configure how sudo runs applications and pick one of the three modes. The table below explains what each mode does.

Mode in SettingsConfig nameWhat happensSecurity trade-off
In a new window (default)forceNewWindowThe elevated command opens in a separate console windowMost isolated. Your normal window can’t interact with the elevated one
Input closeddisableInputThe command runs in your current window but can’t accept keyboard inputGood middle ground for non-interactive commands such as sfc or netstat
InlinenormalThe command runs in your current window with full input and output, like Linux sudoLeast isolated. Other non-admin processes on the same console could interact with the elevated one

Which one to pick: Microsoft recommends keeping the default, In a new window, unless you understand and accept the risks of the other two modes. If you mostly run non-interactive commands such as sfc or netstat and want the output in your current window, Input closed is a reasonable compromise, but any command that asks a question (such as a Y/N confirmation) can’t receive your answer in that mode. Use Inline only if you need interactive elevated commands and trust everything running on your PC (Microsoft Learn: sudo configuration options).

Step 6: Open a Fresh Terminal Window

  • Close any Terminal, PowerShell, or Command Prompt windows that are open.
  • Right-click Start and choose Terminal. Don’t choose Terminal (Admin), because the goal is a normal window.

Windows that were already open usually pick up sudo too. Starting a fresh one simply rules that out if something doesn’t work.

Step 7: Run Your First Sudo Command

Try a command that fails without admin rights. In a normal window, this command:

netstat -ab

typically fails with “The requested operation requires elevation.” because the -b switch needs admin rights. Now add sudo in front:

sudo netstat -ab

Expected result: A UAC prompt asks you to verify that you want to continue. Click Yes (or enter admin credentials on a standard account). A list of connections appears, each with the program that created it. In In a new window mode, that list appears in a new console window. In the other two modes, it prints in your current window, as in the screenshot below. For a graphical view of the same traffic, see our guide to monitoring network traffic with Sniffnet.

Normal Windows Terminal PowerShell tab showing sudo netstat -ab output with the Active Connections table and the owning program for each connection, such as svchost.exe and msedge.exe.

Some other useful examples:

sudo sfc /scannow

Without sudo, this command returns “You must be an administrator running a console session in order to use the SFC utility.” With sudo, it starts the scan and ends with a result line such as “Windows Resource Protection did not find any integrity violations.”

sudo dism /online /cleanup-image /scanhealth

This should finish with “No component store corruption detected.” or a corruption report, followed by “The operation completed successfully.”

sudo notepad C:\Windows\System32\drivers\etc\hosts

This opens Notepad with admin rights, so you can save changes to the hosts file. Copy the original file to a USB flash drive or external SSD before you edit anything in System32.

Normal Windows Terminal PowerShell tab showing sudo sfc /scannow completing with the message Windows Resource Protection did not find any integrity violations.

Step 8 (Optional): Change the Mode From the Command Line

You can switch modes without opening Settings. Changing the mode with sudo config --enable must be done from an elevated window; from a normal window, sudo replies “You must run this command as an administrator.” (sudo source code).

  • Right-click Start and choose Terminal (Admin).
  • Click Yes on the UAC prompt.
  • Run the command for the mode you want:
sudo config --enable disableInput
Elevated Windows Terminal with Administrator in the title bar showing sudo config --enable disableInput and the confirmation output

Configuration Reference

The --enable commands need an elevated Terminal. Plain sudo config only reads the setting, so it works in a normal window and prints a line such as “Sudo is currently in Force New Window mode on this machine.”

CommandResult
sudo configShows the current sudo mode
sudo config --enable forceNewWindowSwitches to the In a new window mode
sudo config --enable disableInputSwitches to the Input closed mode
sudo config --enable normalSwitches to the Inline mode
sudo config --enable disableTurns sudo off

PowerShell cmdlets need a wrapper. Sudo launches the command line you give it as a new elevated process. PowerShell cmdlets, aliases and functions only exist inside a running PowerShell session, so sudo Restart-Service Spooler won’t work on its own. Run it through PowerShell like this:

sudo powershell -Command "Restart-Service Spooler"

If you use PowerShell 7, swap powershell for pwsh. The microsoft/sudo repository also includes an optional sudo.ps1 helper script (in its scripts folder) that makes sudo friendlier to use from PowerShell.

Sudo vs. Task Scheduler: Which One Do You Need?

These two tools solve different problems.

  • Sudo elevates individual commands on demand from a terminal. Each one still goes through a UAC prompt.
  • A Task Scheduler task set to “Run with highest privileges” launches one specific app elevated with no UAC prompt at all. Use it for a single trusted tool you open every day.

If your real goal is to stop the UAC prompts for a particular app, sudo won’t help. See HDG’s guide How to Run Apps as Administrator Without UAC Prompts for the Task Scheduler method. Sudo also doesn’t elevate desktop shortcuts or Start menu entries. It only works on the command line.

Fixing Common Sudo Problems

Fix #1: Restart Your Terminal

Close every Terminal, PowerShell, and Command Prompt window. Then open a new one. If you ran Terminal elevated before you enabled sudo, close that window too. Try sudo netstat -ab again.

Fix #2: Turn On the Toggle

You may see “Sudo is disabled on this machine. To enable it, go to the Developer Settings page in the Settings app.” This means sudo is installed but switched off.

  • Open Settings > System > Advanced, or For developers on some builds.
  • Switch Enable sudo to On.
  • Approve the UAC prompt.

Fix #3: Confirm Your Windows Version

You may see this error in Command Prompt:

‘sudo’ is not recognized as an internal or external command, operable program or batch file.

Or this one in PowerShell:

sudo : The term ‘sudo’ is not recognized as the name of a cmdlet, function, script file, or operable program.

Either error means sudo.exe isn’t on your system.

  • Run winver.
  • If the version is below 24H2, or the PC runs Windows 10, sudo isn’t available. Update by following Step 2 above.
  • If you installed gsudo or another third-party tool earlier, check that it isn’t overriding the built-in command. Running where.exe sudo should point to C:\Windows\System32\sudo.exe.

Fix #4: Run sudo config From an Elevated Window

If sudo config --enable replies “You must run this command as an administrator.”, you ran it from a normal window. Open Terminal (Admin) and run the command again. If it instead says “You cannot set a mode higher than…”, a policy on your PC caps the allowed mode (see Fix #6).

Fix #5: Switch Modes for Interactive Commands

If a sudo command ignores your typing, you’re in Input closed mode. Switch to Inline in Settings, or run sudo config --enable normal from an elevated Terminal. Only do this if you trust what runs on your PC.

Fix #6: Check for a Policy Block

On work or school PCs, the Enable sudo toggle may be grayed out or say it’s managed by your organization. Running sudo may print “Sudo is disabled by your organization’s policy.” An administrator has disabled or restricted sudo through Group Policy (Computer Configuration > Administrative Templates > System > Configure the behavior of the sudo command) or through an MDM tool such as Intune (Sudo Policy CSP). Ask your IT team. Don’t try to override the policy.

Security Considerations

  • UAC still applies. Sudo can only elevate through UAC, so with normal UAC settings each sudo command brings up a UAC prompt. If a sudo prompt appears that you didn’t start, click No and scan for malware.
  • Inline and Input closed carry extra risk. Microsoft warns that malicious processes could try to drive the elevated process through the connection between the unelevated and elevated sudo.exe. Input closed mitigates this by closing the input handle; Inline lets unelevated processes in the same console send input or read output. The default In a new window mode avoids both.
  • Read before you run. Sudo makes elevation so easy that it’s tempting to paste admin commands from forum posts without reading them. Read each command first, and back up important data before running anything that changes system files. If a power cut during a long DISM repair would worry you, plug the PC into a UPS.

Wrapping Up

For most people, Microsoft’s default In a new window mode is the safest choice. Switch to Input closed if you want output in your current window and mainly run non-interactive commands. Expect UAC prompts to continue, because that’s by design. If sudo stops working after a Windows update, check that the toggle is still on. If elevated commands like sfc keep finding corruption that won’t repair, suspect a failing drive or malware.

StepActionApplies To
1–2Confirm or update to 24H2 with winverWindows 11
3–5Turn on Enable sudo and pick a modeWindows 11 24H2+
6–7Run sudo <command> in a normal TerminalWindows 11 24H2+
8Change modes with sudo config --enableElevated Terminal

Resources

Sources retrieved October 3, 2026: