Users & Permissions
Ubuntu is a multi-user operating system, and proper user management and permission configuration are the cornerstones of system security. This article explains how to create and manage users, configure groups, and understand the file permission system in Ubuntu 26.04.
User Management
Creating Users
Use useradd to create a new user:
# Create a user with a home directory
sudo useradd -m -s /bin/bash username
# Set the password
sudo passwd usernameThe adduser command is preferred, as it is an interactive wrapper script that guides you through the setup:
sudo adduser usernameModifying User Attributes
Use usermod to modify an existing user’s attributes:
# Change the default shell
sudo usermod -s /bin/zsh username
# Change home directory (and move files)
sudo usermod -d /home/newdir -m username
# Lock a user account
sudo usermod -L username
# Unlock a user account
sudo usermod -U username
# Rename a user
sudo usermod -l newname oldnameDeleting Users
# Delete a user but keep the home directory
sudo userdel username
# Delete a user and their home directory
sudo userdel -r usernameViewing User Information
# Check the current user
whoami
# View user ID and group information
id username
# List all users
cat /etc/passwd
# View currently logged-in users
who
wGroup Management
Creating and Managing Groups
# Create a new group
sudo groupadd developers
# Add a user to a group (preserving existing groups)
sudo usermod -aG developers username
# Add a user to multiple groups
sudo usermod -aG docker,sudo,developers username
# View the groups a user belongs to
groups username
# View all members of a group
getent group developers
# Delete a group
sudo groupdel developersPrimary Group vs. Supplementary Groups
Each user has a primary group and zero or more supplementary groups:
# Change a user's primary group
sudo usermod -g newgroup username
# Modify supplementary groups (-a means append; without -a, all supplementary groups are replaced)
sudo usermod -aG extragroup usernamesudo Configuration
Ubuntu 26.04 ships sudo-rs, a Rust rewrite, as the default replacement for the traditional C sudo. It is compatible with the vast majority of common sudoers syntax (user/group rules, NOPASSWD, ALL, /etc/sudoers.d/, etc.), so day-to-day usage is unchanged. However, some obscure directives and third-party plugins are not yet implemented. If a sudo-dependent script errors out or behaves unexpectedly, first run sudo --version to confirm the current implementation, and if needed temporarily install the traditional version with sudo apt install sudo to troubleshoot, then switch back to sudo-rs once the issue is pinned down.
Basic Usage
# Execute a command with root privileges
sudo apt update
# Switch to the root user
sudo -i
# Execute a command as another user
sudo -u www-data commandAdding a User to the sudo Group
# In Ubuntu, members of the sudo group have administrator privileges
sudo usermod -aG sudo usernameEditing the sudoers File
Always use visudo to edit the sudoers configuration, as it performs syntax checking before saving:
sudo visudoCommon configuration examples:
# Allow a user to execute all commands without a password
username ALL=(ALL) NOPASSWD: ALL
# Allow a user to execute only specific commands
username ALL=(ALL) /usr/bin/systemctl restart nginx, /usr/bin/systemctl status nginx
# Allow group members to execute apt without a password
%developers ALL=(ALL) NOPASSWD: /usr/bin/aptYou can also create standalone configuration files in /etc/sudoers.d/:
sudo visudo -f /etc/sudoers.d/developersFile Permission Basics
Understanding Permission Notation
Linux file permissions consist of three sets: owner, group, and others. Each set includes read (r=4), write (w=2), and execute (x=1) permissions.
# View file permissions
ls -la
# Example output:
# -rwxr-xr-- 1 user group 4096 Jan 1 12:00 script.sh
# │├─┤├─┤├─┤
# │ │ │ └── Others: r-- (read only)
# │ │ └── Group: r-x (read and execute)
# │ └── Owner: rwx (read, write, execute)
# └── File type: - regular file, d directory, l symlinkchmod - Changing Permissions
# Numeric mode
chmod 755 script.sh # rwxr-xr-x
chmod 644 config.txt # rw-r--r--
chmod 600 secret.key # rw-------
# Symbolic mode
chmod u+x script.sh # Add execute permission for the owner
chmod g+w file.txt # Add write permission for the group
chmod o-r file.txt # Remove read permission for others
chmod a+r file.txt # Add read permission for everyone
# Recursively change directory permissions
chmod -R 755 /var/www/htmlchown - Changing Ownership
# Change the file owner
sudo chown newuser file.txt
# Change both owner and group
sudo chown newuser:newgroup file.txt
# Change only the group
sudo chgrp newgroup file.txt
# Recursively change directory ownership
sudo chown -R www-data:www-data /var/wwwSpecial Permissions
# SUID - Execute as the file owner
chmod u+s executable
chmod 4755 executable
# SGID - Execute as the file group / new files in directory inherit the group
chmod g+s directory
chmod 2755 directory
# Sticky Bit - Only the file owner can delete files (commonly used on /tmp)
chmod +t directory
chmod 1777 directoryumask - Default Permission Mask
# View current umask
umask
# Set umask (new file default = 0666 - umask, new directory = 0777 - umask)
umask 022 # New files 644, new directories 755
umask 077 # New files 600, new directories 700To permanently change the umask, edit ~/.bashrc or /etc/login.defs.
ACL Extended Permissions
When standard permissions are not flexible enough, you can use ACLs (Access Control Lists):
# Install ACL tools
sudo apt install acl
# Grant permissions to a specific user
setfacl -m u:username:rwx /path/to/file
# Grant permissions to a specific group
setfacl -m g:groupname:rx /path/to/dir
# View ACL settings
getfacl /path/to/file
# Recursively set ACL
setfacl -R -m u:username:rwx /path/to/dir
# Set default ACL (newly created files inherit automatically)
setfacl -d -m u:username:rwx /path/to/dir
# Remove ACL
setfacl -x u:username /path/to/fileBest Practices
- Principle of least privilege: Only grant users the minimum permissions needed to do their work.
- Avoid using root directly: Use
sudoto execute administrative commands rather than staying logged in as root. - Use groups wisely: Managing permissions through groups is more efficient than configuring each user individually.
- Audit regularly: Periodically review
/etc/passwdand/etc/groupto clean up users and groups that are no longer needed. - Protect sensitive files: Ensure files like
/etc/shadowand SSH keys have correct permissions (600 or stricter).