Only for the record, until it lasted (seemingly noone has been interested in finding and updating the patterns to be patched or maybe some other security measure was implemented in later Windows 10) the "best" way (IMHO) was to patch a file.
Booting from USB with grub4dos, patching the .dll then continuing booting and you could login as the original user but without (or with "any") password:
http://reboot.pro/index.php?showtopic=18588
There are (were) derivatives to be run from a WinPE, but any hex editor that could access the .dll would have done.
Let's say that it was a poor man's Konboot, that has (or at least used to have) a similar approach, but patching files in memory.