field note
Axis camera default password, username, and IP address
Axis cameras have no default password. The default username and IP address by AXIS OS generation, and why a 401 is usually not a password problem at all.
2026-08-06
Axis cameras have no default password. On current AXIS OS you create an administrator account the first time you reach the device, which means there is no factory credential to look up and the credential lists circulating for Axis products are either about long-discontinued hardware or simply wrong. That answers the question most people are asking. The more useful question, and the one nothing on the first page of results addresses, is what to do when a camera you already own stops accepting a password you know is correct. Nine times out of ten that is not a credential problem, and treating it as one costs you a site visit.
This post is about credentials. If you are looking for how to flip an upside-down image, that is the rotate setting in the video stream configuration and it has nothing to do with passwords, despite what several search engines currently believe.
What the default actually is
Current Axis products ship with no account at all. Reaching the device the first time presents an account creation step, you set the administrator credential there, and that is the only credential that exists. Nothing is printed on the label and nothing is published in the datasheet, by design. Bosch and Hanwha ship the same way on current hardware, and the per-model lookup across all three vendors is the camera default passwords by model reference.
Two things follow that matter more than they sound:
Credential lists for Axis are unreliable. The root account is real and historically significant, but the widely reposted password pairings attached to it apply to specific discontinued products at specific firmware levels, if they were ever accurate. Trying them on a current camera wastes time and, on a device with lockout behavior configured, can cost you more than time.
Password requirements are about to tighten. AXIS OS 13, expected on the active track in September 2026, enforces password complexity on new and edited accounts with a minimum profile of 15 characters that cannot be disabled. Generic advice to use eight characters is already behind the platform. If anything in your provisioning generates camera credentials, check the generated length against that now, before the upgrade makes every new account creation fail at once.
Axis default username: root, and what changed
The Axis default username is root on every camera running AXIS OS 11.5 or earlier, and there is no fixed default username from AXIS OS 11.6 onward, because the first-login step lets you name the administrator account yourself. Which of those you are holding depends on the firmware generation the camera was commissioned on, and the credential lists that keep circulating collapse three generations into one line.
| Firmware generation | Default username | Default password | What happens at first access |
|---|---|---|---|
| Discontinued products, firmware before the first-login prompt | root | pass on the circulating lists; Axis does not document it for anything current | The camera came up with a working credential and expected you to change it |
| Firmware 5.x through AXIS OS 11.5 | root | None | A “Configure root password” dialog opens and you set the password for the fixed root account |
| AXIS OS 11.6 and 12.x | None fixed | None | You create an administrator account and choose the username; root is no longer present in the factory state |
| AXIS OS 13 (active track, from September 2026) | None fixed | None | Same as 11.6 and 12, with a 15-character minimum enforced on every new or edited account |
Two consequences follow. First, on a camera commissioned under AXIS OS 11.5 or earlier, the username is root whether or not anyone remembers setting it, so a login prompt that rejects “admin” is rejecting the wrong username, not the wrong password. Second, on AXIS OS 11.6 and later there is nothing to guess: whoever commissioned the camera picked the username, and if that person and their notes are gone, the only path back in is the reset described below.
The root and pass pairing on the lists is real history and useless in practice. It belongs to product generations that Axis has discontinued, and trying it against a current camera burns lockout attempts on a device that never had it.
Axis camera default IP address
The Axis default IP address is 192.168.0.90 on AXIS OS earlier than 11.8, and a link-local address in the 169.254.X.X range from AXIS OS 11.8 onward. On a normal network neither one is the address the camera is answering on. Axis publishes those defaults as the fallback for a network with no DHCP server. Most networks have one, the camera takes the address it is handed, and the default never comes into play.
| AXIS OS version | Default IP address, no DHCP server present |
|---|---|
| Earlier than 11.8 | 192.168.0.90 |
| 11.8 and later | A link-local address, 169.254.X.X |
That split matters for the same reason the credential split does. A guide written before 11.8 tells you to browse to 192.168.0.90, and on a current camera with no DHCP server nothing is at that address: the camera has given itself a link-local address instead, and reaching it means your own interface needs an address in the same range. Technicians follow the older advice, get nothing, and write up a dead camera that is sitting on the bench working correctly.
Two practical notes. On a network with DHCP, do not look for a default at all; find the address the server assigned, or use Axis’s documented procedure for reaching a device whose address you do not know. And on a camera you have just factory defaulted, the address behavior resets with everything else, so a camera that held a static address before will come back on DHCP or link-local depending on its AXIS OS version.
The 401 that is not a password problem
Here is the failure that sends people to the reset button, and the reason they should not go.
Starting with AXIS OS 12.1, a factory-defaulted camera changes how it authenticates over HTTP. Under the current default, the camera accepts Basic authentication over HTTPS, and digest authentication only over plain HTTP and RTSP. Digest over HTTPS, which is what a great deal of tooling and many VMS integrations were built around, is refused with a 401 even when the credentials are exactly right.
The part that makes this hard to spot: a camera upgraded in place keeps its old policy, so nothing breaks. A camera that was factory-defaulted during a repair, a redeploy, or a panic reset gets the new policy. Same model, same firmware, opposite behavior. We have confirmed this on an M4218-V running 12.4.59, where a digest probe over HTTPS returns 401 and Basic over HTTPS returns 200 for the same account and the same password.
So the symptom is a camera that rejects a known-good credential, and the instinct is to conclude the account is broken and reset the camera. That instinct is wrong often enough to be worth a rule: on an AXIS OS 12.x camera, test Basic over HTTPS before you conclude anything about the credentials.
What a factory default actually costs
If you do reach the bottom rung, understand what you are trading. A factory default does not just clear the password.
The authentication policy resets. On 12.1 and later, the camera comes back with the current default policy, which is very likely not what the rest of your fleet is running. You have just created the exact condition described above.
The device certificate is gone. On an 802.1X authenticated switch port, the camera can no longer authenticate to the network. It never gets an address, never appears in any tool, and reads as bricked while running perfectly well. Recovering it means an unauthenticated port or a provisioning VLAN, then reissuing the certificate. Tracking those certificates across a fleet is its own discipline, covered in camera certificates: expiry, 802.1X, and rotation.
The address changes. The camera returns to DHCP. If your VMS references cameras by address rather than identity, it is online and not recording.
The clock configuration is gone. NTP settings go with everything else, and timestamps start drifting immediately and silently.
One reset on one camera is an afternoon. The same reset applied as a standard response to 401s across a fleet is a multi-week cleanup.
How to reset an Axis camera password
There is no password recovery on an Axis camera. If the administrator credential is lost and no second administrator account exists, the only way back in is a factory default, which erases every setting on the device along with the credential. The procedure is the same across current Axis cameras and is printed in every user manual:
- Disconnect power from the camera.
- Press and hold the control button, then reconnect power while still holding it.
- Keep holding for 15 to 30 seconds, until the status LED flashes amber.
- Release the button. The reset is complete when the status LED turns green.
- Find the camera again. It requests an address by DHCP, and if no DHCP server answers it falls back to the default for its AXIS OS version: 192.168.0.90 before 11.8, a link-local 169.254.X.X address from 11.8 onward. AXIS IP Utility or AXIS Device Manager will find it either way.
- Open the camera in a browser. On AXIS OS 11.6 and later it presents the create-administrator step; on older firmware it asks you to set the
rootpassword. That account is the new credential.
The control button location varies by form factor. Domes typically have it under the cover, bullets and boxes near the network connector, and a handful of products behind a rubber plug. The product’s installation guide shows it.
If you still have any working login, the same reset is available from the web interface under the maintenance settings, and it is worth exhausting the alternatives first. A second administrator account, if one was created at commissioning, gets you in without touching the configuration. A VMS or management tool that still holds a working credential can change the password on the camera for you. Both are reversible. The reset is not, and the section above lists what it takes with it.
Then, once you are back in, do the thing that makes the next lockout a non-event: create a second administrator account, record both in whatever holds credentials for the rest of the fleet, and put the camera back on its static address, certificate, and time configuration before it is forgotten.
Rotating credentials without locking yourself out
Changing a camera password is trivial. Changing it across a fleet without creating a recording gap is not, because every consumer of that credential has to be cut over in the right order. The procedure that avoids gaps is in how to rotate camera passwords without breaking your VMS, and it applies to Axis the same as anything else.
Two Axis-specific notes to layer on top:
- Rotate before the OS 13 upgrade, not during it. Doing both at once means a failed rotation and a failed upgrade look identical, and the 15-character enforcement will reject generated credentials that worked yesterday.
- Verify authentication behavior after any wave that included a reset camera. That is where the policy mismatch hides. The firmware track context for that change is in AXIS OS upgrade paths explained.
Doing this across 500 cameras
At one camera, the ladder above is a two-minute check. Across a fleet, the problem is that nobody is running the ladder. A 401 arrives as a ticket, the tech resets the camera because that is the documented fix everywhere on the internet, and the certificate, address, and clock go with it. The failure repeats because nothing in the process ever learns.
MentatNOC handles authentication on both sides of the 12.1 policy change, so a factory-defaulted camera does not read as a credential failure in the first place, and it tracks each camera’s credential and certificate state continuously rather than at ticket time. Rotation runs in staged waves that never break monitoring. The write-side detail is on the firmware, password, and certificate actions page, and you can see it end to end in a live platform demo.
There is no Axis default password to find. There is an account you created, a policy that may have changed underneath it, and a reset button that costs far more than it looks like it does. Knowing which of those three you are dealing with is the entire job.