User management on Linux server
Level: Beginner
Estimated time: ~30 minutes
Goal: Learn the CLI tools for creating and maintaining accounts, configure standard service access, and maintain uptime safely.
Introduction
Linux user management is a core skill for any system administrator. Proper access control ensures server stability, security, and accountability. In this tutorial, we will cover the fundamentals of adding accounts, granting privileges (including Linux privilege escalation), and maintaining standard service configuration safely.
Prerequisites
Before you begin, make sure the following conditions are met:
- Operating system: Ubuntu 22.04/24.04 LTS, Debian 12/13, AlmaLinux/Rocky Linux 8/9/10, RHEL 8/9/10
- Access: sudo or root access to the server via SSH
- System: Working package manager
- Required knowledge: confident use of the Linux command line
Understanding key concepts
Before making changes, you should understand how accounts function:
- UID (User ID): A unique numerical identifier assigned to each user for tracking ownership and permissions.
- GID (Group ID): A primary numerical identifier assigning a user to a specific group. Linux groups organize multiple users for shared permissions.
- Home directory: The default directory (
/home/username) where a user's personal files and configurations are stored. - Login shell: The command interpreter (like
/bin/bash) that starts when an authorized user logs in. An authorized user is an account permitted to access the system. - Password: A secret string of characters used for Linux user authentication. Authentication is the process of verifying a user's identity.
- Adduser: An interactive front-end script used to create accounts, primarily on Debian/Ubuntu systems.
- Useradd: A native, low-level binary utility used to create accounts across all Linux distributions.
- Account lock: The action of disabling password-based logins to secure the server.
- Account expiration: The action of automatically disabling an account on a specific date.
Step 1: Creating a new user
To create a new user, you use the adduser command (on Debian/Ubuntu) or the useradd command (on RHEL/AlmaLinux).
Replace johndoe with your desired username in the examples below. Run the following command to create a user named johndoe:
sudo adduser johndoe
You will be prompted to enter a password and optional user details.
Expected output:
The output will contain lines about creating the group, user, home directory, and copying files from /etc/skel. The exact UID/GID depends on your system.
On RHEL/AlmaLinux, use sudo useradd -m johndoe (the -m flag ensures the creation of /home/johndoe) and set the password manually with the passwd command: sudo passwd johndoe.
Step 2: Understanding sudo on Linux server
Standard users cannot modify system configurations or install software. The Linux sudo command allows permitted users to execute commands with root privileges.
2.1 Adding a user to the sudo group
The easiest way to grant privileges is to add the user to the predefined administrative group using the usermod command.
Ubuntu/Debian:
sudo usermod -aG sudo johndoe
RHEL/AlmaLinux:
sudo usermod -aG wheel johndoe
The usermod command appends (-a) the user to the supplementary group (-G). The user johndoe can now execute administrative tasks by prepending sudo to commands. The command produces no output on success. You can verify this using groups johndoe - the sudo (or wheel) group should appear in the list.
Step 3: Modifying user properties
You might need to lock an account or change its password.
3.1 Changing a password
To force a password change or update a forgotten password, run the following using the passwd command:
sudo passwd johndoe
You will be prompted to enter and confirm the new password. Once complete, the user can log in with the new credentials.
3.2 Locking an account
If a user leaves the company, you should perform an account lock to secure the server:
sudo usermod -L johndoe
The account is immediately locked, preventing any new password-based logins. To unlock the account later, use sudo usermod -U johndoe.
Both commands produce no output. You can verify the status using passwd -S johndoe (status L = locked, P = active).
3.3 Setting account expiration
To automatically disable an account on a specific date, you set an account expiration:
sudo usermod -e 2026-12-31 johndoe
This ensures temporary contractors lose access automatically.
You can check the expiration date with sudo chage -l johndoe. It might show the date one day earlier due to UTC boundary processing - this is normal, and the account will still expire correctly.
Step 4: Using the Linux sudo command securely for server security
The sudoers file (/etc/sudoers) controls exactly who can use sudo and what they can execute.
To edit the sudoers file, always use visudo. It checks for syntax errors before saving, preventing lockouts.
A recommended best practice is to create a separate file for each rule rather than editing the main file:
sudo visudo -f /etc/sudoers.d/johndoe
This simplifies rule rollback and reduces the risk of damaging the main sudoers configuration.
To allow johndoe to restart the time synchronization service without a password, add the appropriate line for your OS:
Ubuntu/Debian:
johndoe ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart systemd-timesyncd
RHEL/AlmaLinux:
johndoe ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart chronyd
Save and exit. johndoe can now restart the service without being prompted for a password.
The user johndoe must run the command as sudo systemctl restart systemd-timesyncd (or chronyd) - specifically through sudo. A direct call to restart the service without sudo will return a polkit error requiring interactive authentication.
Never edit sudoers files directly with nano or vim. A syntax error will break sudo access for the entire system, requiring a boot into rescue mode to fix.
Step 5: Deleting a user
When an account is no longer needed, remove it to maintain server hygiene.
To delete the user but keep their files:
sudo deluser johndoe
On RHEL/AlmaLinux: sudo userdel johndoe
Running the command without --remove-home (or -r) leaves /home/johndoe and the user's files on the disk. This is useful for archiving data, but you must be aware of the remaining files.
To delete the user and their home directory:
sudo deluser --remove-home johndoe
On RHEL/AlmaLinux: sudo userdel -r johndoe
To remove the user's sudoers file if one was created, run:
sudo rm -f /etc/sudoers.d/johndoe
The user account is now completely removed from the system.
Before removing a user, ensure no background services rely on their UID or Linux groups.
Verification
To verify the new user and their group memberships, use the id command:
id johndoe
Expected output:
The output will show the UID, GID (which may differ from 1001), and a list of groups. Verify that the sudo (Debian/Ubuntu) or wheel (RHEL/AlmaLinux) group is present. On Debian/Ubuntu, the users group may also appear in the list - this is normal.
To test sudo access, switch to the new user:
su - johndoe
Then run a command requiring privileges:
sudo ls /root
If prompted, enter johndoe's password (the password set in Step 1), not the root password. You should see the contents of the /root directory.
Troubleshooting
- Syntax errors in sudoers: If you accidentally break the sudoers file, you can often fix it by running
pkexec visudofrom another session. Ifpkexecis unavailable, you will need to boot the server into recovery/single-user mode to edit the file. - Lost sudo access: If you lose sudo access but still have the root password, log in directly as root (e.g., via
su -) to correct the group memberships. - Verifying user privileges: To check exactly what commands a user is allowed to run, use
sudo -l -U johndoe.
Rollback
If you need to revert the changes made in this tutorial:
- Remove the user from the sudo group:
sudo gpasswd -d johndoe sudo(orwheel). - Revert any additions made via
visudo. - Delete the user and their home directory:
sudo deluser --remove-home johndoe(orsudo userdel -r johndoe). - Remove their dedicated sudoers file:
sudo rm -f /etc/sudoers.d/johndoe.
Conclusion
Properly configuring accounts ensures you can safely manage users in Linux without compromising system security. By understanding the adduser command, the usermod command, and the passwd command, alongside secure sudo configuration, you maintain a stable and accountable environment.
Document Version: 1.0
Last Updated: May 2026
Owner: Technical Documentation Team