Privacy

Setting Up Your Windows PC Privately: The OOBE\BYPASSNRO Method

Windows 11 local-account setup options, including BYPASSNRO, Rufus, Pro setup, and newer reported methods, with build limitations and practical privacy guidance.

Start here: choose a method for your situation

  • Windows 11 Pro: Look for “Domain join instead” in the work-or-school setup path, if offered.
  • Already at the Microsoft sign-in screen: The newly reported “Learn more” link may open local-account creation. Treat it as a temporary, unverified workaround.
  • Installing from USB: Rufus can prepare installation media with its Microsoft-account requirement removal option.
  • Using older or compatible installation media: Try BYPASSNRO, or the registry equivalent if the script is missing. Neither is universal.
  • Want the documented route without setup workarounds? Complete setup, then switch to a local account in Settings. This does involve Microsoft-account sign-in during setup.

Record the Windows edition, build, and installation-media date before troubleshooting. During setup, Shift + F10 (sometimes Fn + Shift + F10) opens Command Prompt; ver shows the running environment’s version. After installation, use winver. Public and Insider builds, OEM recovery images, and online setup updates can behave differently. Do not change an employer-managed setup without your IT team.

Windows 11 Pro: “Domain join instead,” when available

  1. During OOBE, choose Set up for work or school if offered.
  2. On the sign-in page, open Sign-in options, then Domain join instead.
  3. Create the local username and a strong password, and complete the remaining setup screens.

This path can create a local account without joining a domain at that moment. It is not a Windows Home option. Organization-managed devices or different setup builds may not offer it.

New September 2026 report: the small “Learn more” link

Windows Latest reports testing this on a fresh Windows 11 Home virtual machine. Its report does not establish that all editions or public builds support it.

  1. Continue setup with internet connected until Let’s add your Microsoft account.
  2. Look for the small “Learn more” text link in the paragraph beneath “Sign-in options”, not the larger Learn More button near the bottom.
  3. If it takes you to Who’s going to use this device?, create your local account and complete setup.
  4. If it only opens help or returns to sign-in, use another option below.

Status: newly reported, not independently verified by CM. This appears to be unintended behavior, not an officially supported feature, and Microsoft may change it. Unlike the offline methods below, the reported procedure uses an internet connection.

Preparing a new USB installer with Rufus

If you have access to another Windows PC, Rufus provides a way to prepare installation media before you begin. Download Windows from Microsoft and Rufus from rufus.ie, not a repackaged “debloated” ISO site.

  1. Back up your PC’s data and the USB drive. Creating the installer erases the selected USB drive. A clean Windows installation can also erase existing files; do not format or delete partitions containing data you need.
  2. Open Rufus on a Windows PC, select the intended USB drive and official Windows ISO, then choose Start.
  3. In the Windows User Experience dialog, select Remove requirement for an online Microsoft account when offered. You do not need to disable TPM or Secure Boot requirements just to use a local account.
  4. Boot the target PC from the prepared USB. For the documented account-bypass option, keep the network disconnected at account creation: unplug Ethernet and do not join Wi-Fi.
  5. Complete local-account setup, reconnect, and run Windows Update.

The Rufus FAQ explicitly explains the offline requirement. Rufus runs on Windows, not natively on macOS. Compatibility remains dependent on the Rufus version and Windows image; its documentation does not promise support for every Insider build.

The original OOBE\BYPASSNRO method: compatible builds only

OOBE means Out-of-Box Experience. BYPASSNRO restores an offline setup path on builds that still honor it. It is not a Windows activation bypass.

  1. At setup, disconnect Ethernet and Wi-Fi.
  2. Press Shift + F10, or Fn + Shift + F10 on some laptops.
  3. Enter the following command. Use a backslash; capitalization does not matter.
OOBE\BYPASSNRO
  1. If the script exists and works, the PC restarts. Continue without reconnecting.
  2. Choose I don’t have internet, then Continue with limited setup, if those options appear.
  3. Create your local account and finish all remaining setup screens.

If “OOBE\BYPASSNRO is not recognized” appears

The script may be missing from that image. On builds that still honor the registry value, its equivalent is:

reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE /v BypassNRO /t REG_DWORD /d 1 /f
shutdown /r /t 0

Run these as two separate commands in setup’s Command Prompt. The second immediately restarts the PC. Stay offline afterward. Creating the value does not prove the build will honor it. If the offline choice is still absent, do not keep restarting or stacking unrelated bypasses.

If an offline method needs Wi-Fi disconnected

Unplug Ethernet first. If setup already joined Wi-Fi, you can disable that adapter temporarily from Command Prompt:

netsh wlan show interfaces
netsh interface set interface name="Wi-Fi" admin=disable

Replace Wi-Fi with the actual interface name listed by the first command. Disconnecting alone does not guarantee offline setup. After reaching the desktop, re-enable the adapter from an Administrator Command Prompt:

netsh interface set interface name="Wi-Fi" admin=enable

Why other instructions may not work

Microsoft’s October 6, 2025 Dev Channel notes for build 26220.6772 announce removal of known local-only setup mechanisms. That is evidence about an Insider rollout, not proof every public installer behaves identically.

  • start ms-cxh:localonly and related URI commands have been reported blocked on newer Insider builds. Do not treat them as the guaranteed replacement for BYPASSNRO.
  • Registry, HideOnlineAccountScreens, and developer-console techniques have conflicting third-party results. Pureinfotech reports alternatives, but we are not presenting them as verified fixes for every build.
  • Fake email/password tricks and forcibly ending setup processes can fail or loop. They are not our recommended fallback.

Supported fallback: switch to a local account after setup

Microsoft documents switching account types in Settings. If you are comfortable signing in during setup:

  1. Complete the standard setup with your Microsoft account.
  2. Open Settings → Accounts → Your info.
  3. Choose Sign in with a local account instead.
  4. Follow the prompts to create your local credentials, then select Sign out and finish.
  5. Sign back in and check OneDrive, Windows Backup, and individual app sign-ins separately.

Switching Windows sign-in does not delete data already synced to Microsoft, close the Microsoft account, or necessarily sign every app out. Before changing cloud backup or sync, confirm your important files are downloaded and safely backed up.

What a local account does, and does not, do for privacy

A local account separates Windows sign-in from a Microsoft online identity. It reduces account coupling, but does not make Windows offline, stop all telemetry, or prevent apps from sending data to cloud services. You can still choose to sign in to OneDrive, Microsoft 365, or other apps separately.

Windows Update and security updates still work with a local account. Microsoft-account users can also normally sign in offline after initial setup, so offline login is not exclusive to local accounts. The trade-off is managing your own local password recovery and deciding how to handle sync, backup, and encryption recovery keys.

After setup: finish the privacy and security work

  • Reconnect and install Windows security updates and appropriate device drivers.
  • Review Settings → Privacy & security, including optional diagnostic data and app permissions.
  • Check OneDrive folder backup, Windows Backup, browser sync, and app accounts before assuming files stay local.
  • Check Device Encryption or BitLocker status. Save any recovery key somewhere you control, separate from the PC, before relying on encryption.
  • Use a strong local password and a recovery plan; set up a separate, tested backup of important files.

Keep the goal, not a particular workaround

The goal is a Windows setup you understand and control. A specific shortcut may disappear. Choose a method that fits your edition and build, and use the supported account-switching path if the setup workarounds fail.

Sources and update history

September 23, 2026: Expanded the original BYPASSNRO guide with Pro and Rufus options, the newly reported Learn more method, build-specific limitations, Microsoft’s supported post-setup switch, and corrected privacy guidance. Original publication: December 20, 2023.

Need a technical partner?

Let’s make the next move cleaner.

If this surfaced a messy system, a privacy concern, or a website issue you want handled, we can help you turn it into a practical plan.