Skip to Content
DocsOperationsSystem AdministrationUsers & Permissions

Users & Permissions

Ubuntu is a multi-user operating system, and proper user management and permission configuration are the cornerstones of system security. This article explains how to create and manage users, configure groups, and understand the file permission system in Ubuntu 26.04.

User Management

Creating Users

Use useradd to create a new user:

# Create a user with a home directory sudo useradd -m -s /bin/bash username # Set the password sudo passwd username

The adduser command is preferred, as it is an interactive wrapper script that guides you through the setup:

sudo adduser username

Modifying User Attributes

Use usermod to modify an existing user’s attributes:

# Change the default shell sudo usermod -s /bin/zsh username # Change home directory (and move files) sudo usermod -d /home/newdir -m username # Lock a user account sudo usermod -L username # Unlock a user account sudo usermod -U username # Rename a user sudo usermod -l newname oldname

Deleting Users

# Delete a user but keep the home directory sudo userdel username # Delete a user and their home directory sudo userdel -r username

Viewing User Information

# Check the current user whoami # View user ID and group information id username # List all users cat /etc/passwd # View currently logged-in users who w

Group Management

Creating and Managing Groups

# Create a new group sudo groupadd developers # Add a user to a group (preserving existing groups) sudo usermod -aG developers username # Add a user to multiple groups sudo usermod -aG docker,sudo,developers username # View the groups a user belongs to groups username # View all members of a group getent group developers # Delete a group sudo groupdel developers

Primary Group vs. Supplementary Groups

Each user has a primary group and zero or more supplementary groups:

# Change a user's primary group sudo usermod -g newgroup username # Modify supplementary groups (-a means append; without -a, all supplementary groups are replaced) sudo usermod -aG extragroup username

sudo Configuration

Note

Ubuntu 26.04 ships sudo-rs, a Rust rewrite, as the default replacement for the traditional C sudo. It is compatible with the vast majority of common sudoers syntax (user/group rules, NOPASSWD, ALL, /etc/sudoers.d/, etc.), so day-to-day usage is unchanged. However, some obscure directives and third-party plugins are not yet implemented. If a sudo-dependent script errors out or behaves unexpectedly, first run sudo --version to confirm the current implementation, and if needed temporarily install the traditional version with sudo apt install sudo to troubleshoot, then switch back to sudo-rs once the issue is pinned down.

Basic Usage

# Execute a command with root privileges sudo apt update # Switch to the root user sudo -i # Execute a command as another user sudo -u www-data command

Adding a User to the sudo Group

# In Ubuntu, members of the sudo group have administrator privileges sudo usermod -aG sudo username

Editing the sudoers File

Always use visudo to edit the sudoers configuration, as it performs syntax checking before saving:

sudo visudo

Common configuration examples:

# Allow a user to execute all commands without a password username ALL=(ALL) NOPASSWD: ALL # Allow a user to execute only specific commands username ALL=(ALL) /usr/bin/systemctl restart nginx, /usr/bin/systemctl status nginx # Allow group members to execute apt without a password %developers ALL=(ALL) NOPASSWD: /usr/bin/apt

You can also create standalone configuration files in /etc/sudoers.d/:

sudo visudo -f /etc/sudoers.d/developers

File Permission Basics

Understanding Permission Notation

Linux file permissions consist of three sets: owner, group, and others. Each set includes read (r=4), write (w=2), and execute (x=1) permissions.

# View file permissions ls -la # Example output: # -rwxr-xr-- 1 user group 4096 Jan 1 12:00 script.sh # │├─┤├─┤├─┤ # │ │ │ └── Others: r-- (read only) # │ │ └── Group: r-x (read and execute) # │ └── Owner: rwx (read, write, execute) # └── File type: - regular file, d directory, l symlink

chmod - Changing Permissions

# Numeric mode chmod 755 script.sh # rwxr-xr-x chmod 644 config.txt # rw-r--r-- chmod 600 secret.key # rw------- # Symbolic mode chmod u+x script.sh # Add execute permission for the owner chmod g+w file.txt # Add write permission for the group chmod o-r file.txt # Remove read permission for others chmod a+r file.txt # Add read permission for everyone # Recursively change directory permissions chmod -R 755 /var/www/html

chown - Changing Ownership

# Change the file owner sudo chown newuser file.txt # Change both owner and group sudo chown newuser:newgroup file.txt # Change only the group sudo chgrp newgroup file.txt # Recursively change directory ownership sudo chown -R www-data:www-data /var/www

Special Permissions

# SUID - Execute as the file owner chmod u+s executable chmod 4755 executable # SGID - Execute as the file group / new files in directory inherit the group chmod g+s directory chmod 2755 directory # Sticky Bit - Only the file owner can delete files (commonly used on /tmp) chmod +t directory chmod 1777 directory

umask - Default Permission Mask

# View current umask umask # Set umask (new file default = 0666 - umask, new directory = 0777 - umask) umask 022 # New files 644, new directories 755 umask 077 # New files 600, new directories 700

To permanently change the umask, edit ~/.bashrc or /etc/login.defs.

ACL Extended Permissions

When standard permissions are not flexible enough, you can use ACLs (Access Control Lists):

# Install ACL tools sudo apt install acl # Grant permissions to a specific user setfacl -m u:username:rwx /path/to/file # Grant permissions to a specific group setfacl -m g:groupname:rx /path/to/dir # View ACL settings getfacl /path/to/file # Recursively set ACL setfacl -R -m u:username:rwx /path/to/dir # Set default ACL (newly created files inherit automatically) setfacl -d -m u:username:rwx /path/to/dir # Remove ACL setfacl -x u:username /path/to/file

Best Practices

  1. Principle of least privilege: Only grant users the minimum permissions needed to do their work.
  2. Avoid using root directly: Use sudo to execute administrative commands rather than staying logged in as root.
  3. Use groups wisely: Managing permissions through groups is more efficient than configuring each user individually.
  4. Audit regularly: Periodically review /etc/passwd and /etc/group to clean up users and groups that are no longer needed.
  5. Protect sensitive files: Ensure files like /etc/shadow and SSH keys have correct permissions (600 or stricter).
Last updated on