Managing Users & Groups

Creating & Modifying Accounts

You could edit /etc/passwd and /etc/shadow by hand, but that's fragile and dangerous - a typo can lock out every account. Instead, use the dedicated commands, which validate input and keep every account file in sync.

CommandPurpose
useradd -m -s /bin/bash aliceCreate user with home + shell
passwd aliceSet/change password
usermod -aG sudo aliceAppend to a supplementary group
usermod -L / -ULock / unlock account
userdel -r aliceDelete user and home
groupadd devsCreate group
groupdel devsDelete group
id aliceShow UID/GID/groups
chage -l alicePassword ageing info
$ useradd -m -s /bin/bash alice && id alice
uid=1001(alice) gid=1001(alice) groups=1001(alice)

useradd's -m flag matters: without it, no home directory is created, and alice would log in to an empty, non-existent /home/alice. id alice is your go-to sanity check after any account change - it shows the numeric UID/GID alongside the resolved names, plus every group the user belongs to.

Warning: This is one of the most common real-world mistakes on Linux: usermod -aG sudo alice appends alice to the sudo group while leaving her other group memberships untouched. Drop the -a and run usermod -G sudo alice instead, and it silently replaces every supplementary group alice was in with just sudo - kicking her out of docker, www-data, or whatever else she needed, with no warning or confirmation. Always use -aG, never bare -G, unless you deliberately want to wipe existing group membership.