Introduction
Every Linux server, whether it hosts a small personal project or a large-scale production application, depends on one fundamental administrative task: user management. Properly managed users and groups are the first line of defense for your server's security, and they form the foundation of a well-organized, maintainable system.
When I first started working with Linux servers, user management seemed like a simple topic — just create a user, set a password, and move on. In practice, it is much more than that. Understanding how users, groups, permissions, and privileges work together is essential for anyone who administers a server, whether you are a DevOps engineer, a backend developer deploying your first application, or a student building a home lab.
In this article, I will walk you through everything you need to know about user management on a Linux server: creating and deleting users, managing groups, assigning sudo privileges, securing SSH access, and following industry best practices.
Why User Management Matters
Before diving into commands, it is important to understand why this topic deserves your attention:
- Security: Each user account is a potential entry point. Unused accounts, weak passwords, and excessive privileges are among the most common ways servers get compromised.
- Accountability: When every action can be traced back to a specific user, auditing and troubleshooting become far easier.
- Least privilege: Users should only have the access they actually need — no more, no less.
- Collaboration: Groups allow teams to share files and resources safely without exposing them to everyone else.
Understanding Users in Linux
In Linux, every user is identified by two values:
-
Username: The human-readable name used to log in (for example,
yeasin). -
UID (User ID): The numeric identifier the system actually uses internally. Regular users typically start at
1000, while system accounts use lower values.
User information is stored in a few key files:
| File | Purpose |
|---|---|
/etc/passwd |
Stores usernames, UIDs, home directories, and default shells |
/etc/shadow |
Stores encrypted passwords and password aging policies |
/etc/group |
Stores group names, GIDs, and group memberships |
/etc/sudoers |
Defines which users or groups may run commands with sudo
|
You should never edit these files directly with a text editor. Instead, use the dedicated commands covered below, which handle locking and validation for you.
Creating Users
1. Adding a New User
The standard command to create a user is useradd, but on most modern distributions, adduser is a friendlier, interactive alternative.
sudo adduser yeasin
This command automatically:
- Creates the user,
- Assigns a UID,
- Creates a home directory at
/home/yeasin, - Copies default configuration files into the home directory,
- Prompts you to set a password and optional details.
If your distribution only ships the low-level useradd command, create a user with a home directory and Bash shell like this:
sudo useradd -m -s /bin/bash yeasin
sudo passwd yeasin
Here, the -m flag creates the home directory, and -s sets the default shell.
2. Verifying the User
Confirm that the user was created correctly:
id yeasin
Example output:
uid=1001(yeasin) gid=1001(yeasin) groups=1001(yeasin)
Managing Passwords and Account Policies
A strong password policy is a core part of server security. Set or change a user's password with:
sudo passwd yeasin
You can also enforce password aging so that passwords expire periodically:
sudo chage -M 90 yeasin
This forces the user to change their password every 90 days. To review a user's password policy:
sudo chage -l yeasin
For production servers, consider requiring strong passwords using PAM (Pluggable Authentication Modules) configuration, and always prefer key-based authentication over passwords for remote access.
Working with Groups
Groups make permission management dramatically simpler. Instead of assigning permissions to users one by one, you assign them to a group once.
1. Creating a Group
sudo groupadd developers
2. Adding a User to a Group
sudo usermod -aG developers yeasin
The -aG flags are critical: -a appends the user to the group without removing them from other groups, and -G specifies the group. If you omit -a, the user will be removed from all their other secondary groups — a common and painful mistake.
Verify group membership after the user logs in again:
groups yeasin
3. Deleting a Group
sudo groupdel developers
Granting Sudo Privileges
Sometimes a user needs administrative rights. There are two recommended ways to grant them.
1. Using the Sudo Group
On Ubuntu and Debian, members of the sudo group automatically receive administrative privileges:
sudo usermod -aG sudo yeasin
On CentOS, RHEL, and Fedora, the equivalent group is called wheel:
sudo usermod -aG wheel yeasin
2. Using a Custom Sudoers File
For fine-grained control, create a dedicated sudoers file for the user:
sudo visudo -f /etc/sudoers.d/yeasin
Add this line to allow full access:
yeasin ALL=(ALL:ALL) ALL
Always use visudo when editing sudo configuration. It validates the syntax before saving, which prevents you from accidentally locking yourself out of administrative access.
Locking, Unlocking, and Deleting Users
1. Locking an Account
When someone leaves a team, disable their account immediately:
sudo usermod -L yeasin
Unlock it later if needed:
sudo usermod -U yeasin
2. Deleting a User
To remove a user along with their home directory and mail spool:
sudo userdel -r yeasin
Double-check the username before running this command, because deletion is permanent.
Securing SSH Access
User management on a server goes hand in hand with SSH security. A few essential practices:
1. Use Key-Based Authentication
Generate a key pair on your local machine:
ssh-keygen -t ed25519
Copy the public key to the server:
ssh-copy-id yeasin@your-server-ip
2. Disable Root Login and Password Authentication
Edit the SSH daemon configuration at /etc/ssh/sshd_config:
PermitRootLogin no
PasswordAuthentication no
Then restart the SSH service:
sudo systemctl restart sshd
3. Restrict Which Users Can Log In
Allow only specific users to connect over SSH:
AllowUsers yeasin deploy
Keep an SSH session open while testing configuration changes, so you never lock yourself out of your own server.
Best Practices Checklist
To summarize the habits of a well-managed server:
- Create a separate user for every person and every service; never share accounts.
- Disable root login over SSH and use
sudofor administrative tasks instead. - Prefer key-based authentication over password authentication.
- Apply the principle of least privilege: grant only the access a user actually needs.
- Regularly audit accounts with
last,lastlog, and/var/log/auth.log. - Lock or delete accounts as soon as they are no longer needed.
- Enforce password aging policies with
chagewhere key-based login is not possible.
Conclusion
User management may appear to be a basic administrative chore, but it is genuinely one of the most important pillars of Linux server security. A server with carefully controlled users, groups, and privileges is dramatically harder to compromise, far easier to audit, and much simpler to maintain over time.
The commands in this guide are the same ones used daily by professional system administrators. Practice them on a virtual machine or a cloud instance, break things safely, and rebuild your understanding from the ground up. The more comfortable you become with user management, the more confident you will feel running production servers.
If you found this guide helpful, consider saving it for reference and sharing it with others who are learning Linux administration.
Thank you for reading.
Top comments (0)