Types of Users in Linux
Linux categorizes users into three main types:
- Root (UID 0) — The superuser with unrestricted access to every file and command on the system. Root can create or delete any user, modify any configuration, and install or remove any software. Direct root login is discouraged in favor of using
sudo. - System Users (UID 1-999) — Service accounts created automatically for running daemons and system services (e.g.,
www-datafor web servers,mysqlfor databases). These accounts typically cannot log in interactively and have restricted shell access. - Regular Users (UID 1000+) — Human users who log in to the system. Each gets a home directory under
/home/, a default shell, and a personal group. These accounts have limited system-level access.
Key User Configuration Files
/etc/passwd
Contains basic information about every user account, one line per user. Despite the name, it no longer stores passwords. Each field is separated by colons:
alice:x:1001:1001:Alice Johnson:/home/alice:/bin/bash
│ │ │ │ │ │ └── Login shell
│ │ │ │ │ └── Home directory
│ │ │ │ └── Full name / comment (GECOS)
│ │ │ └── Primary group ID (GID)
│ │ └── User ID (UID)
│ └── Password placeholder (actual password in /etc/shadow)
└── Username
/etc/shadow
Stores encrypted password hashes and password aging information. Only readable by root for security. Fields include the username, hashed password, last change date, minimum/maximum password age, and expiration settings.
# View shadow file (root only)
sudo cat /etc/shadow
# Example entry
alice:$6$rounds=5000$salt$hash...:19500:0:99999:7:::
/etc/group
Defines all groups on the system. Each line contains the group name, password placeholder, GID, and a comma-separated list of member usernames:
developers:x:1010:alice,bob,charlie
Creating User Accounts
# Create a new user with default settings
sudo useradd alice
# Create user with home directory, shell, and comment
sudo useradd -m -s /bin/bash -c "Alice Johnson" alice
# Create user and assign to supplementary groups
sudo useradd -m -s /bin/bash -G sudo,developers alice
# Set password for the new user
sudo passwd alice
# Alternative: adduser (interactive, Debian/Ubuntu)
sudo adduser alice
useradd vs adduser
On Debian-based systems, adduser is a higher-level wrapper that interactively prompts for a password, full name, and other details, and automatically creates the home directory. useradd is the low-level command available on all distributions but requires explicit flags (like -m) for home directory creation.
Modifying User Accounts
# Change username
sudo usermod -l newname oldname
# Change user's home directory (and move files)
sudo usermod -d /home/newhome -m alice
# Change default shell
sudo usermod -s /bin/zsh alice
# Add user to supplementary group (without removing existing groups)
sudo usermod -aG docker alice
# Lock a user account (disable login)
sudo usermod -L alice
# or
sudo passwd -l alice
# Unlock a user account
sudo usermod -U alice
# or
sudo passwd -u alice
# Set account expiration date
sudo usermod -e 2025-12-31 contractor
# Change user's comment/full name
sudo usermod -c "Alice M. Johnson" alice
Important: Always Use -aG Together
When adding a user to a group with usermod -G, always include the -a (append) flag. Without it, usermod -G groupname user replaces all supplementary groups with only the specified group, which can lock the user out of sudo and other essential groups.
Deleting User Accounts
# Delete user (keeps home directory)
sudo userdel alice
# Delete user and their home directory
sudo userdel -r alice
# Alternative on Debian/Ubuntu (interactive)
sudo deluser --remove-home alice
Managing Groups
Groups allow you to organize users and assign shared permissions to files and directories.
# Create a new group
sudo groupadd developers
# Create group with specific GID
sudo groupadd -g 2000 engineering
# Add existing user to a group
sudo usermod -aG developers alice
# Remove user from a group
sudo gpasswd -d alice developers
# Delete a group
sudo groupdel oldgroup
# View groups a user belongs to
groups alice
id alice
# View all members of a group
getent group developers
# Change a user's primary group
sudo usermod -g developers alice
Understanding sudo
The sudo (superuser do) command allows authorized users to execute commands with root privileges. This is the recommended way to perform administrative tasks instead of logging in as root directly.
How sudo Works
- A user types
sudo commandin the terminal. - The system checks
/etc/sudoersto verify the user is authorized. - The user enters their own password (not the root password).
- If authorized, the command runs with root privileges.
- The password is cached for a short period (typically 15 minutes) so subsequent sudo commands do not require re-authentication.
Configuring sudo Access
# Add user to the sudo group (Debian/Ubuntu)
sudo usermod -aG sudo alice
# Add user to the wheel group (Fedora/RHEL/Arch)
sudo usermod -aG wheel alice
# Edit sudoers file safely (ALWAYS use visudo)
sudo visudo
Common sudoers Configuration
# Allow user full sudo access
alice ALL=(ALL:ALL) ALL
# Allow user to run specific commands without password
alice ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart nginx
# Allow group to use sudo
%developers ALL=(ALL:ALL) ALL
# Allow user to run commands as a specific user
alice ALL=(www-data) /usr/bin/php
Never Edit /etc/sudoers Directly
Always use sudo visudo to edit the sudoers file. The visudo command validates the syntax before saving, preventing you from locking yourself out of sudo access with a typo. A broken sudoers file can make the system unmanageable.
Password Policies
# View password aging information
sudo chage -l alice
# Set maximum password age (90 days)
sudo chage -M 90 alice
# Set minimum password age (7 days between changes)
sudo chage -m 7 alice
# Force password change on next login
sudo chage -d 0 alice
# Set account expiration date
sudo chage -E 2025-12-31 alice
# Set warning days before password expiry
sudo chage -W 14 alice
Useful User Information Commands
# Show current user
whoami
# Show current user's UID, GID, and groups
id
# Show detailed info for a specific user
id alice
# Show who is currently logged in
who
w
# Show last login times
last
lastlog
# Show failed login attempts
sudo lastb
# Switch to another user
su - alice
# Run a single command as another user
sudo -u alice command
Next Step
Now that you can manage users and groups, learn how to install and manage software with our Package Management guide.