Linux User Management: adduser, usermod & sudo Guide | INTROSERV
EUR
european

EUR

usa

USD

English En
Ex. VAT Ex. VAT 0%

User management on Linux server

Level: Beginner
Estimated time: ~30 minutes
Goal: Learn the CLI tools for creating and maintaining accounts, configure standard service access, and maintain uptime safely.

Introduction

Linux user management is a core skill for any system administrator. Proper access control ensures server stability, security, and accountability. In this tutorial, we will cover the fundamentals of adding accounts, granting privileges (including Linux privilege escalation), and maintaining standard service configuration safely.

Prerequisites

Before you begin, make sure the following conditions are met:

  • Operating system: Ubuntu 22.04/24.04 LTS, Debian 12/13, AlmaLinux/Rocky Linux 8/9/10, RHEL 8/9/10
  • Access: sudo or root access to the server via SSH
  • System: Working package manager
  • Required knowledge: confident use of the Linux command line

Understanding key concepts

Before making changes, you should understand how accounts function:

  • UID (User ID): A unique numerical identifier assigned to each user for tracking ownership and permissions.
  • GID (Group ID): A primary numerical identifier assigning a user to a specific group. Linux groups organize multiple users for shared permissions.
  • Home directory: The default directory (/home/username) where a user's personal files and configurations are stored.
  • Login shell: The command interpreter (like /bin/bash) that starts when an authorized user logs in. An authorized user is an account permitted to access the system.
  • Password: A secret string of characters used for Linux user authentication. Authentication is the process of verifying a user's identity.
  • Adduser: An interactive front-end script used to create accounts, primarily on Debian/Ubuntu systems.
  • Useradd: A native, low-level binary utility used to create accounts across all Linux distributions.
  • Account lock: The action of disabling password-based logins to secure the server.
  • Account expiration: The action of automatically disabling an account on a specific date.

Step 1: Creating a new user

To create a new user, you use the adduser command (on Debian/Ubuntu) or the useradd command (on RHEL/AlmaLinux).

Replace johndoe with your desired username in the examples below. Run the following command to create a user named johndoe:

sudo adduser johndoe

You will be prompted to enter a password and optional user details.

Expected output:

The output will contain lines about creating the group, user, home directory, and copying files from /etc/skel. The exact UID/GID depends on your system.

Info

On RHEL/AlmaLinux, use sudo useradd -m johndoe (the -m flag ensures the creation of /home/johndoe) and set the password manually with the passwd command: sudo passwd johndoe.

Step 2: Understanding sudo on Linux server

Standard users cannot modify system configurations or install software. The Linux sudo command allows permitted users to execute commands with root privileges.

2.1 Adding a user to the sudo group

The easiest way to grant privileges is to add the user to the predefined administrative group using the usermod command.

Ubuntu/Debian:

sudo usermod -aG sudo johndoe

RHEL/AlmaLinux:

sudo usermod -aG wheel johndoe

The usermod command appends (-a) the user to the supplementary group (-G). The user johndoe can now execute administrative tasks by prepending sudo to commands. The command produces no output on success. You can verify this using groups johndoe - the sudo (or wheel) group should appear in the list.

Step 3: Modifying user properties

You might need to lock an account or change its password.

3.1 Changing a password

To force a password change or update a forgotten password, run the following using the passwd command:

sudo passwd johndoe

You will be prompted to enter and confirm the new password. Once complete, the user can log in with the new credentials.

3.2 Locking an account

If a user leaves the company, you should perform an account lock to secure the server:

sudo usermod -L johndoe

The account is immediately locked, preventing any new password-based logins. To unlock the account later, use sudo usermod -U johndoe.

Both commands produce no output. You can verify the status using passwd -S johndoe (status L = locked, P = active).

3.3 Setting account expiration

To automatically disable an account on a specific date, you set an account expiration:

sudo usermod -e 2026-12-31 johndoe

This ensures temporary contractors lose access automatically.

Info

You can check the expiration date with sudo chage -l johndoe. It might show the date one day earlier due to UTC boundary processing - this is normal, and the account will still expire correctly.

Step 4: Using the Linux sudo command securely for server security

The sudoers file (/etc/sudoers) controls exactly who can use sudo and what they can execute.

To edit the sudoers file, always use visudo. It checks for syntax errors before saving, preventing lockouts.

A recommended best practice is to create a separate file for each rule rather than editing the main file:

sudo visudo -f /etc/sudoers.d/johndoe

This simplifies rule rollback and reduces the risk of damaging the main sudoers configuration.

To allow johndoe to restart the time synchronization service without a password, add the appropriate line for your OS:

Ubuntu/Debian:

johndoe ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart systemd-timesyncd

RHEL/AlmaLinux:

johndoe ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart chronyd

Save and exit. johndoe can now restart the service without being prompted for a password.

The user johndoe must run the command as sudo systemctl restart systemd-timesyncd (or chronyd) - specifically through sudo. A direct call to restart the service without sudo will return a polkit error requiring interactive authentication.

Warning

Never edit sudoers files directly with nano or vim. A syntax error will break sudo access for the entire system, requiring a boot into rescue mode to fix.

Step 5: Deleting a user

When an account is no longer needed, remove it to maintain server hygiene.

To delete the user but keep their files:

sudo deluser johndoe

On RHEL/AlmaLinux: sudo userdel johndoe

Warning

Running the command without --remove-home (or -r) leaves /home/johndoe and the user's files on the disk. This is useful for archiving data, but you must be aware of the remaining files.

To delete the user and their home directory:

sudo deluser --remove-home johndoe

On RHEL/AlmaLinux: sudo userdel -r johndoe

To remove the user's sudoers file if one was created, run:

sudo rm -f /etc/sudoers.d/johndoe

The user account is now completely removed from the system.

Info

Before removing a user, ensure no background services rely on their UID or Linux groups.

Verification

To verify the new user and their group memberships, use the id command:

id johndoe

Expected output:

The output will show the UID, GID (which may differ from 1001), and a list of groups. Verify that the sudo (Debian/Ubuntu) or wheel (RHEL/AlmaLinux) group is present. On Debian/Ubuntu, the users group may also appear in the list - this is normal.

To test sudo access, switch to the new user:

su - johndoe

Then run a command requiring privileges:

sudo ls /root

If prompted, enter johndoe's password (the password set in Step 1), not the root password. You should see the contents of the /root directory.

Troubleshooting

  • Syntax errors in sudoers: If you accidentally break the sudoers file, you can often fix it by running pkexec visudo from another session. If pkexec is unavailable, you will need to boot the server into recovery/single-user mode to edit the file.
  • Lost sudo access: If you lose sudo access but still have the root password, log in directly as root (e.g., via su -) to correct the group memberships.
  • Verifying user privileges: To check exactly what commands a user is allowed to run, use sudo -l -U johndoe.

Rollback

If you need to revert the changes made in this tutorial:

  1. Remove the user from the sudo group: sudo gpasswd -d johndoe sudo (or wheel).
  2. Revert any additions made via visudo.
  3. Delete the user and their home directory: sudo deluser --remove-home johndoe (or sudo userdel -r johndoe).
  4. Remove their dedicated sudoers file: sudo rm -f /etc/sudoers.d/johndoe.

Conclusion

Properly configuring accounts ensures you can safely manage users in Linux without compromising system security. By understanding the adduser command, the usermod command, and the passwd command, alongside secure sudo configuration, you maintain a stable and accountable environment.

Document Version: 1.0
Last Updated: May 2026
Owner: Technical Documentation Team

VAT

  • Other

    Ex. VAT

    0%
  • austria

    Austria

    20%
  • Belgium

    Belgium

    21%
  • Bulgaria

    Bulgaria

    20%
  • Croatia

    Croatia

    25%
  • Cyprus

    Cyprus

    19%
  • Czech Republic

    Czech Republic

    21%
  • Denmark

    Denmark

    25%
  • Estonia

    Estonia

    22%
  • France

    France

    20%
  • Finland

    Finland

    24%
  • Germany

    Germany

    19%
  • Greece

    Greece

    24%
  • Hungary

    Hungary

    27%
  • Ireland

    Ireland

    23%
  • Italy

    Italy

    22%
  • Latvia

    Latvia

    21%
  • Lithuania

    Lithuania

    21%
  • Luxembourg

    Luxembourg

    17%
  • Malta

    Malta

    18%
  • Netherlands

    Netherlands

    21%
  • Poland

    Poland

    23%
  • Portugal

    Portugal

    23%
  • Romania

    Romania

    19%
  • Slovakia

    Slovakia

    20%
  • Slovenia

    Slovenia

    22%
  • Spain

    Spain

    21%
  • Sweden

    Sweden

    25%
  • USA

    USA

    0%
european
states
  • germany
  • Español
  • Italiano
  • Poland
  • Slovenski
  • Türkçe
  • ukraine
  • kingdom
  • French
  • Hrvatska
  • Other
  • Austria
  • Belgium
  • Bulgaria
  • Croatia
  • Cyprus
  • Czech Republic
  • Denmark
  • Estonia
  • Finland
  • France
  • Germany
  • Greece
  • Hungary
  • Ireland
  • Italy
  • Latvia
  • Lithuania
  • Luxembourg
  • Malta
  • Netherlands
  • Poland
  • Portugal
  • Romania
  • Slovakia
  • Slovenia
  • Spain
  • Sweden
  • USA