Linux User Management: useradd, usermod & userdel Explained

linux user management useradd

Every person and every service on a Linux server should have its own account, with only the access it needs. useradd, usermod
and userdel are the three commands that manage that lifecycle, and each has one flag that causes most of the real-world mistakes.

This guide creates users properly, explains primary versus supplementary groups, grants admin rights safely, and covers disabling and removing
accounts without leaving orphaned files or cron jobs behind. For fine-grained admin rights, continue with
configuring sudoers safely.

Quick answer: sudo useradd -m -s /bin/bash alice, sudo passwd alice, and sudo usermod -aG sudo alice — never forget the -a.

Where Account Information Lives

Linux keeps accounts in three plain-text databases: the passwd database (usernames, UIDs, home directories, shells), the shadow database (password hashes, readable only by root), and the group database. getent reads them the same way the system does, including accounts from LDAP or other sources.

bashlook up an account
getent passwd alice
getent group sudo
id alice
Linux account databases
passwd, shadow, group

Create a User Properly

useradd on its own creates an account with no home directory on some distributions and a minimal shell on others. Pass -m for a home directory and -s for a real shell. On Debian and Ubuntu, adduser is an interactive wrapper that does this for you.

bashcreate and set a password
sudo useradd -m -s /bin/bash -c "Alice Smith" alice
sudo passwd alice
TipFor a service account that should never log in, use sudo useradd -r -s /usr/sbin/nologin appsvc: a system UID and no interactive shell.
Creating a user
Home directory, shell, password

Primary vs Supplementary Groups

Every user has one primary group, which owns the files they create, and any number of supplementary groups that grant extra access, such as sudo, docker or a shared project group.

bashinspect and create groups
id alice
sudo groupadd developers
Primary and supplementary groups
Ownership versus extra access

Add to a Group Without Removing the Others

This is the single most damaging user-management mistake. usermod -G replaces the user’s entire supplementary group list. usermod -aG appends. Forget the -a and you can silently strip an admin of sudo.

bashthe safe way
sudo usermod -aG developers alice
id alice
Warningsudo usermod -G developers alice (no -a) removes Alice from every other supplementary group, including sudo. Group changes take effect at the user’s next login.
usermod -aG versus -G
Append, don’t replace

Grant Admin Rights

Debian and Ubuntu grant sudo to the sudo group; RHEL, AlmaLinux and Rocky use wheel. For anything narrower than full root, use a file in /etc/sudoers.d/ instead.

bashfull admin
sudo usermod -aG sudo alice     # Debian / Ubuntu
sudo usermod -aG wheel alice    # RHEL family
bashone command only (edit with visudo)
sudo visudo -f /etc/sudoers.d/alice-nginx
# alice ALL=(root) /usr/bin/systemctl reload nginx
Granting sudo
sudo, wheel, or sudoers.d

Disable an Account Without Deleting It

When someone leaves, lock the account first so nothing is lost while you check what they owned. Locking the password blocks password logins; expiring the account also blocks SSH key logins.

bashlock and expire
sudo usermod -L alice
sudo chage -E 0 alice
sudo chage -l alice
NoteA locked password alone does not stop an SSH key login. Expire the account, or remove their authorized_keys, to fully cut access.
Locking an account
Lock, expire, keep the files

Remove a User Safely

Before deleting, find what they own outside their home directory and any scheduled jobs, so nothing breaks or becomes orphaned.

bashcheck, then delete
sudo find / -xdev -user alice 2>/dev/null | head
sudo crontab -l -u alice
ps -u alice
sudo userdel -r alice
Deleting a user
Find their files first

Audit Accounts Regularly

Check who can log in, that only root has UID 0, and when accounts were last used. Stale accounts are an easy way in.

bashquick audit
getent passwd | awk -F: '$7 !~ /(nologin|false)$/ {print $1, $7}'
getent passwd | awk -F: '$3 == 0 {print $1}'
lastlog | grep -v 'Never logged in'
Account audit
Shells, UID 0, last login

What is the difference between useradd and adduser?

useradd is the low-level command available on every distribution. adduser on Debian and Ubuntu is an interactive wrapper that creates the home directory, sets the shell and prompts for a password for you.

How do I add a user to a group in Linux?

Run sudo usermod -aG groupname username. The -a flag appends; without it, -G replaces all of the user’s existing supplementary groups.

Why doesn’t my new group membership work?

Group membership is read at login. The user must log out and back in, or start a new session with newgrp groupname.

How do I give a user sudo access?

Add them to the sudo group on Debian/Ubuntu or the wheel group on RHEL-family systems, or create a narrower rule in /etc/sudoers.d/ using visudo.

How do I delete a user and their home directory?

Run sudo userdel -r username. Check first for files they own elsewhere and for cron jobs or running processes.

Cheat Sheet

  • useradd -m -s /bin/bash; passwd; usermod -aG (never forget -a)
  • Lock with usermod -L + chage -E 0; delete with userdel -r after checking

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.