DEV Community

Cover image for Managing Users and Groups in Linux: A Beginner-Friendly Guide
Yeasin's
Yeasin's

Posted on

Managing Users and Groups in Linux: A Beginner-Friendly Guide

Linux is a multi-user system. That means many people (and many programs) can use the same computer at the same time — but each one gets its own separate identity and its own limits.

Every person who logs in, and every service that runs in the background, has its own user account. This is how Linux decides:

  • Which files you can open
  • Which programs you can run
  • Who is allowed to use sudo
  • Which service can touch which files

If you want to manage a Linux server — or even just understand your own system better — users and groups are the first thing you need to learn.

In this guide, we will go step by step: what users and groups are, where Linux stores this information, and how to create, change, and delete them safely.


What Is a User in Linux?

When you create a user, Linux gives that user two important numbers:

  • UID (User ID) — a unique number for the user
  • GID (Group ID) — a unique number for the user's main group

Your username is just a friendly label. Deep inside, Linux only cares about the numbers.

For example, when the system checks if you can open a file, it looks at your UID — not your name.

Linux has three main types of users:

Type UID Example
Root user 0 root — the superuser, can do anything
System users 1–999 www-data, mysql, sshd — used by services
Normal users 1000+ yeasin, rahim — real humans

Note: On Debian and Ubuntu, the first normal user you create during installation gets UID 1000.


What Is a Group?

A group is a collection of users. It makes sharing easy.

Example: you have a folder that only the "developers" team should edit. Instead of giving permission to each person one by one, you put them all in one group and give permission to that group.

Every user has:

  • One primary group — usually a group with the same name as the user. New files you create belong to this group.
  • Zero or more secondary groups — extra groups you join, like sudo or docker.

Where Linux Stores User Information

All user and group information lives in simple text files inside the /etc directory:

File What it contains
/etc/passwd All users: name, UID, home folder, shell
/etc/shadow Encrypted passwords (only root can read it)
/etc/group All groups and their members

Let's look at one line from /etc/passwd:

cat /etc/passwd
Enter fullscreen mode Exit fullscreen mode
yeasin\:x:1000:1000\:MD Yeasin Ali:/home/yeasin:/bin/bash
Enter fullscreen mode Exit fullscreen mode

Each part has a meaning, separated by :

  1. yeasin — username
  2. x — password is stored in /etc/shadow
  3. 1000 — UID
  4. 1000 — GID of the primary group
  5. MD Yeasin Ali — full name / comment
  6. /home/yeasin — home directory
  7. /bin/bash — the shell used at login

Warning: Never edit these files by hand with a normal editor. One small mistake can lock you out of your whole system. Always use the commands shown below.


Creating a New User

Debian and Ubuntu have two commands for this, and mixing them up is very common.

Option 1: adduser — the easy way (recommended for beginners)

sudo adduser rahim
Enter fullscreen mode Exit fullscreen mode

The command will ask you a few questions:

Adding user 'rahim' ...
Adding new group 'rahim' (1001) ...
Creating home directory '/home/rahim' ...
Copying files from '/etc/skel' ...
New password:
Retype new password:
passwd: password updated successfully
Changing the user information for rahim
Enter the new value, or press ENTER for the default
  Full Name []: Rahim Uddin
Enter fullscreen mode Exit fullscreen mode

That's it. adduser does everything for you:

  • Creates the user
  • Creates a private group with the same name
  • Creates the home directory
  • Copies default files from /etc/skel (like .bashrc)
  • Sets the password

Tip: /etc/skel is the "skeleton" folder. Anything you put there is automatically copied into every new user's home directory. Great for default configs.

Option 2: useradd — the manual way

useradd is the basic, low-level command. By default it does very little — no home directory, no password. You have to ask for everything yourself:

sudo useradd -m -s /bin/bash -c "Rahim Uddin" rahim
sudo passwd rahim
Enter fullscreen mode Exit fullscreen mode
Flag Meaning
-m Create the home directory
-s Set the login shell
-c Add a full name / comment
-u Use a specific UID
-e Set an expiry date for the account

Note: On Debian and Ubuntu, adduser is friendly and interactive. On other distros (like Fedora), adduser behaves like useradd. So it's good to know both commands.

Creating a user for a service (not a human)

When you deploy your own app, never run it as root. Create a special system user for it:

sudo adduser --system --group --no-create-home --shell /usr/sbin/nologin myapp
Enter fullscreen mode Exit fullscreen mode

Now your app can run as myapp, with the minimum possible permissions. If an attacker ever compromises the app, they only get the myapp account — not root.


Changing an Existing User

Use usermod to change a user's settings:

# Add user to a group (secondary group)
sudo usermod -aG docker rahim

# Change the username
sudo usermod -l newname oldname

# Change the home directory and move the files
sudo usermod -d /home/newname -m newname

# Lock the account (user cannot log in)
sudo usermod -L rahim

# Unlock the account
sudo usermod -U rahim
Enter fullscreen mode Exit fullscreen mode

Warning: With -G, always include -a (append). sudo usermod -G docker rahim without -a removes rahim from all his other groups — including sudo. That can lock you out of admin access on your own machine. Write it as -aG, always.


Deleting a User

# Delete the user, keep the home directory
sudo userdel rahim

# Delete the user AND the home directory
sudo userdel -r rahim
Enter fullscreen mode Exit fullscreen mode

Before deleting, it's smart to check what files the user still owns:

sudo find / -user rahim 2>/dev/null
Enter fullscreen mode Exit fullscreen mode

If you delete a user but keep their files, those files will show a number instead of a name:

-rw-r--r-- 1 1001 1001 1024 Oct 10 12:00 notes.txt
Enter fullscreen mode Exit fullscreen mode

That 1001 is the old UID. If a new user gets UID 1001 later, they suddenly own those files. So either delete the files or give them to someone else first.


Managing Groups

Create a group

sudo groupadd developers
Enter fullscreen mode Exit fullscreen mode

Delete a group

sudo groupdel developers
Enter fullscreen mode Exit fullscreen mode

Add a user to a group

sudo usermod -aG developers rahim
Enter fullscreen mode Exit fullscreen mode

Or with gpasswd:

sudo gpasswd -a rahim developers
Enter fullscreen mode Exit fullscreen mode

Remove a user from a group

sudo gpasswd -d rahim developers
Enter fullscreen mode Exit fullscreen mode

Check which groups a user belongs to

groups rahim
Enter fullscreen mode Exit fullscreen mode

Or get full details:

id rahim
Enter fullscreen mode Exit fullscreen mode
uid=1002(rahim) gid=1002(rahim) groups=1002(rahim),27(sudo),1001(developers)
Enter fullscreen mode Exit fullscreen mode

Important: Group changes apply on the next login. If you just added yourself to a group in your current session, log out and log back in for it to take effect.

The sudo group is special

On Debian and Ubuntu, anyone in the sudo group can use sudo. That's the whole mechanism. Want to make someone an admin? Just:

sudo usermod -aG sudo rahim
Enter fullscreen mode Exit fullscreen mode

Real-World Example: A Shared Project Folder

Let's put it all together with a common real situation.

Your team has a folder, and three people need to edit the same files. Here's how to set it up cleanly.

Step 1 — Create a shared group:

sudo groupadd webteam
Enter fullscreen mode Exit fullscreen mode

Step 2 — Add the users to the group:

sudo usermod -aG webteam yeasin
sudo usermod -aG webteam rahim
sudo usermod -aG webteam karim
Enter fullscreen mode Exit fullscreen mode

Step 3 — Create the folder and give it to the group:

sudo mkdir -p /srv/webproject
sudo chown -R \:webteam /srv/webproject
sudo chmod -R 2775 /srv/webproject
Enter fullscreen mode Exit fullscreen mode

What does 2775 mean?

  • 2775 = special bit 2 + normal permissions 775
  • The 2 is the setgid bit. It makes every new file inside this folder automatically belong to webteam, no matter who creates it.
  • 775 means: owner can do everything, group members can do everything, others can only read and open the folder.

Step 4 — Verify:

ls -ld /srv/webproject
Enter fullscreen mode Exit fullscreen mode
drwxrwsr-x 2 root webteam 4096 Oct 10 12:00 /srv/webproject
Enter fullscreen mode Exit fullscreen mode

Now when rahim creates a file, karim can edit it too — automatically. No manual permission fixing needed.


Common Mistakes and Fixes

1. Using usermod -G without -a

This removes the user from all their other groups. Fix it by adding them back:

sudo usermod -aG sudo rahim
Enter fullscreen mode Exit fullscreen mode

2. Editing /etc/passwd by hand

One typo and you may not be able to log in anymore. If you must edit it, use the safe tools:

sudo vipw
Enter fullscreen mode Exit fullscreen mode

vipw checks the file for mistakes before saving.

3. "I'm in the group, but I still get permission denied"

Group changes need a new login. Log out and back in — or use this for a quick fix:

newgrp docker
Enter fullscreen mode Exit fullscreen mode

4. A deleted user's files show numbers instead of names

The UID no longer matches any user. Delete those files, or give them a new owner:

sudo chown -R yeasin\:yeasin /var/oldstuff
Enter fullscreen mode Exit fullscreen mode

5. Checking why a user cannot log in

getent passwd rahim     # is the shell set to nologin?
sudo passwd -S rahim    # is the account locked?
sudo chage -l rahim     # any expiry date?
Enter fullscreen mode Exit fullscreen mode

Summary

Here are the key points from this guide:

  • Linux identifies every user by a UID, and permissions are always checked against numbers, not names.
  • User data lives in /etc/passwd, /etc/shadow, and /etc/group — never edit them by hand.
  • Use adduser for easy, interactive user creation on Debian/Ubuntu.
  • Use usermod -aG to add users to groups — never forget the -a.
  • The sudo group is what gives someone admin power.
  • Create a separate system user for every service you deploy.
  • Use the setgid bit (2775) on shared folders so group permissions flow automatically to new files.

Once you understand users and groups, everything else in Linux security starts to make sense — because almost every permission question comes down to one simple thing: who is asking, and are they allowed?

Top comments (1)

Collapse
 
suppdevbot profile image
DEV SUPPORTS •

You need to verify your account.

Enter fullscreen mode Exit fullscreen mode

tr.ee/dev-to