Managing Users & Groups
Creating & Modifying Accounts
You could edit /etc/passwd and /etc/shadow by hand, but that's fragile and dangerous - a typo can lock out every account. Instead, use the dedicated commands, which validate input and keep every account file in sync.
| Command | Purpose |
|---|---|
useradd -m -s /bin/bash alice | Create user with home + shell |
passwd alice | Set/change password |
usermod -aG sudo alice | Append to a supplementary group |
usermod -L / -U | Lock / unlock account |
userdel -r alice | Delete user and home |
groupadd devs | Create group |
groupdel devs | Delete group |
id alice | Show UID/GID/groups |
chage -l alice | Password ageing info |
$ useradd -m -s /bin/bash alice && id alice
uid=1001(alice) gid=1001(alice) groups=1001(alice)
useradd's -m flag matters: without it, no home directory is created, and alice would log in to an empty, non-existent /home/alice. id alice is your go-to sanity check after any account change - it shows the numeric UID/GID alongside the resolved names, plus every group the user belongs to.
Warning: This is one of the most common real-world mistakes on Linux:usermod -aG sudo aliceappends alice to thesudogroup while leaving her other group memberships untouched. Drop the-aand runusermod -G sudo aliceinstead, and it silently replaces every supplementary group alice was in with justsudo- kicking her out ofdocker,www-data, or whatever else she needed, with no warning or confirmation. Always use-aG, never bare-G, unless you deliberately want to wipe existing group membership.