WDAGUtilityAccount in Windows 11/10

WDAGUtilityAccount is part of the Windows Defender Application Guard. It remains disabled until Application Guard is enabled on your system. There are multiple system accounts that are built-in to Windows and WDAGUtilityAccount is one of them. When enabled, you may see an alert in your log solution for a new local account created for username: WDAGUtilityAccount (Event ID 4720 or 4722).  It can at times get in your way – for instance, when trying to delete a file, you are prompted with Access is denied, administrator permission is necessary message. When you choose to ignore it and press ‘Continue’ you get another message saying you need the permission of another account – WDAGUtilityAccount. But this is for your security.

You can verify if WDAGUtilityAccount is active on your system as follows: Double-clicking on it will open its Properties. Here you will be able to see if it is active or not.

Can you delete or rename WDAGUtility account

Since the WDAGUtility account is a special ‘system managed account’ in Windows 10, we do not recommend that you rename or delete it using the Administrator account. I hope this helps.