Linux is a multi-user system. That means many people (and many programs) can use the same computer at the same time — but each one gets its own separate identity and its own limits.
Every person who logs in, and every service that runs in the background, has its own user account. This is how Linux decides:
- Which files you can open
- Which programs you can run
- Who is allowed to use
sudo - Which service can touch which files
If you want to manage a Linux server — or even just understand your own system better — users and groups are the first thing you need to learn.
In this guide, we will go step by step: what users and groups are, where Linux stores this information, and how to create, change, and delete them safely.
What Is a User in Linux?
When you create a user, Linux gives that user two important numbers:
- UID (User ID) — a unique number for the user
- GID (Group ID) — a unique number for the user's main group
Your username is just a friendly label. Deep inside, Linux only cares about the numbers.
For example, when the system checks if you can open a file, it looks at your UID — not your name.
Linux has three main types of users:
| Type | UID | Example |
|---|---|---|
| Root user | 0 |
root — the superuser, can do anything |
| System users | 1–999 |
www-data, mysql, sshd — used by services |
| Normal users | 1000+ |
yeasin, rahim — real humans |
Note: On Debian and Ubuntu, the first normal user you create during installation gets UID 1000.
What Is a Group?
A group is a collection of users. It makes sharing easy.
Example: you have a folder that only the "developers" team should edit. Instead of giving permission to each person one by one, you put them all in one group and give permission to that group.
Every user has:
- One primary group — usually a group with the same name as the user. New files you create belong to this group.
-
Zero or more secondary groups — extra groups you join, like
sudoordocker.
Where Linux Stores User Information
All user and group information lives in simple text files inside the /etc directory:
| File | What it contains |
|---|---|
/etc/passwd |
All users: name, UID, home folder, shell |
/etc/shadow |
Encrypted passwords (only root can read it) |
/etc/group |
All groups and their members |
Let's look at one line from /etc/passwd:
cat /etc/passwd
yeasin\:x:1000:1000\:MD Yeasin Ali:/home/yeasin:/bin/bash
Each part has a meaning, separated by :
-
yeasin— username -
x— password is stored in/etc/shadow -
1000— UID -
1000— GID of the primary group -
MD Yeasin Ali— full name / comment -
/home/yeasin— home directory -
/bin/bash— the shell used at login
Warning: Never edit these files by hand with a normal editor. One small mistake can lock you out of your whole system. Always use the commands shown below.
Creating a New User
Debian and Ubuntu have two commands for this, and mixing them up is very common.
Option 1: adduser — the easy way (recommended for beginners)
sudo adduser rahim
The command will ask you a few questions:
Adding user 'rahim' ...
Adding new group 'rahim' (1001) ...
Creating home directory '/home/rahim' ...
Copying files from '/etc/skel' ...
New password:
Retype new password:
passwd: password updated successfully
Changing the user information for rahim
Enter the new value, or press ENTER for the default
Full Name []: Rahim Uddin
That's it. adduser does everything for you:
- Creates the user
- Creates a private group with the same name
- Creates the home directory
- Copies default files from
/etc/skel(like.bashrc) - Sets the password
Tip:
/etc/skelis the "skeleton" folder. Anything you put there is automatically copied into every new user's home directory. Great for default configs.
Option 2: useradd — the manual way
useradd is the basic, low-level command. By default it does very little — no home directory, no password. You have to ask for everything yourself:
sudo useradd -m -s /bin/bash -c "Rahim Uddin" rahim
sudo passwd rahim
| Flag | Meaning |
|---|---|
-m |
Create the home directory |
-s |
Set the login shell |
-c |
Add a full name / comment |
-u |
Use a specific UID |
-e |
Set an expiry date for the account |
Note: On Debian and Ubuntu,
adduseris friendly and interactive. On other distros (like Fedora),adduserbehaves likeuseradd. So it's good to know both commands.
Creating a user for a service (not a human)
When you deploy your own app, never run it as root. Create a special system user for it:
sudo adduser --system --group --no-create-home --shell /usr/sbin/nologin myapp
Now your app can run as myapp, with the minimum possible permissions. If an attacker ever compromises the app, they only get the myapp account — not root.
Changing an Existing User
Use usermod to change a user's settings:
# Add user to a group (secondary group)
sudo usermod -aG docker rahim
# Change the username
sudo usermod -l newname oldname
# Change the home directory and move the files
sudo usermod -d /home/newname -m newname
# Lock the account (user cannot log in)
sudo usermod -L rahim
# Unlock the account
sudo usermod -U rahim
Warning: With
-G, always include-a(append).sudo usermod -G docker rahimwithout-aremoves rahim from all his other groups — includingsudo. That can lock you out of admin access on your own machine. Write it as-aG, always.
Deleting a User
# Delete the user, keep the home directory
sudo userdel rahim
# Delete the user AND the home directory
sudo userdel -r rahim
Before deleting, it's smart to check what files the user still owns:
sudo find / -user rahim 2>/dev/null
If you delete a user but keep their files, those files will show a number instead of a name:
-rw-r--r-- 1 1001 1001 1024 Oct 10 12:00 notes.txt
That 1001 is the old UID. If a new user gets UID 1001 later, they suddenly own those files. So either delete the files or give them to someone else first.
Managing Groups
Create a group
sudo groupadd developers
Delete a group
sudo groupdel developers
Add a user to a group
sudo usermod -aG developers rahim
Or with gpasswd:
sudo gpasswd -a rahim developers
Remove a user from a group
sudo gpasswd -d rahim developers
Check which groups a user belongs to
groups rahim
Or get full details:
id rahim
uid=1002(rahim) gid=1002(rahim) groups=1002(rahim),27(sudo),1001(developers)
Important: Group changes apply on the next login. If you just added yourself to a group in your current session, log out and log back in for it to take effect.
The sudo group is special
On Debian and Ubuntu, anyone in the sudo group can use sudo. That's the whole mechanism. Want to make someone an admin? Just:
sudo usermod -aG sudo rahim
Real-World Example: A Shared Project Folder
Let's put it all together with a common real situation.
Your team has a folder, and three people need to edit the same files. Here's how to set it up cleanly.
Step 1 — Create a shared group:
sudo groupadd webteam
Step 2 — Add the users to the group:
sudo usermod -aG webteam yeasin
sudo usermod -aG webteam rahim
sudo usermod -aG webteam karim
Step 3 — Create the folder and give it to the group:
sudo mkdir -p /srv/webproject
sudo chown -R \:webteam /srv/webproject
sudo chmod -R 2775 /srv/webproject
What does 2775 mean?
-
2775= special bit2+ normal permissions775 - The
2is the setgid bit. It makes every new file inside this folder automatically belong towebteam, no matter who creates it. -
775means: owner can do everything, group members can do everything, others can only read and open the folder.
Step 4 — Verify:
ls -ld /srv/webproject
drwxrwsr-x 2 root webteam 4096 Oct 10 12:00 /srv/webproject
Now when rahim creates a file, karim can edit it too — automatically. No manual permission fixing needed.
Common Mistakes and Fixes
1. Using usermod -G without -a
This removes the user from all their other groups. Fix it by adding them back:
sudo usermod -aG sudo rahim
2. Editing /etc/passwd by hand
One typo and you may not be able to log in anymore. If you must edit it, use the safe tools:
sudo vipw
vipw checks the file for mistakes before saving.
3. "I'm in the group, but I still get permission denied"
Group changes need a new login. Log out and back in — or use this for a quick fix:
newgrp docker
4. A deleted user's files show numbers instead of names
The UID no longer matches any user. Delete those files, or give them a new owner:
sudo chown -R yeasin\:yeasin /var/oldstuff
5. Checking why a user cannot log in
getent passwd rahim # is the shell set to nologin?
sudo passwd -S rahim # is the account locked?
sudo chage -l rahim # any expiry date?
Summary
Here are the key points from this guide:
- Linux identifies every user by a UID, and permissions are always checked against numbers, not names.
- User data lives in
/etc/passwd,/etc/shadow, and/etc/group— never edit them by hand. - Use
adduserfor easy, interactive user creation on Debian/Ubuntu. - Use
usermod -aGto add users to groups — never forget the-a. - The
sudogroup is what gives someone admin power. - Create a separate system user for every service you deploy.
- Use the setgid bit (
2775) on shared folders so group permissions flow automatically to new files.
Once you understand users and groups, everything else in Linux security starts to make sense — because almost every permission question comes down to one simple thing: who is asking, and are they allowed?
Top comments (1)
tr.ee/dev-to