Managing User Accounts on Linux
Creating and managing user accounts is one of the most fundamental Linux system administration tasks, and one that beginners often first encounter indirectly, through a confusing permissions error, rather than by deliberately setting one up. This guide covers the core commands for creating, modifying, and removing accounts, along with what is actually happening under the hood in /etc/passwd and /etc/shadow.
Creating a user with useradd
sudo useradd -m -s /bin/bash newuser
-m creates the user’s home directory (populated with default files from /etc/skel) if it does not already exist. -s /bin/bash sets the user’s login shell. Without -m, many distributions create the account entry but no home directory at all, which breaks login for that user until it is created manually.
After creating the account, set a password, since useradd alone leaves the account locked with no valid password:
sudo passwd newuser
You will be prompted to enter and confirm a new password interactively.
Useful useradd options
useradd -m -s /bin/bash -c "Jane Smith" jsmith # -c sets a comment/full name field
useradd -m -G sudo,docker newuser # -G adds to supplementary groups at creation
useradd -m -e 2026-12-31 tempuser # -e sets an account expiration date
Modifying a user with usermod
usermod changes settings on an existing account without recreating it.
usermod -aG sudo username # add to the sudo group (append, keep existing groups)
usermod -s /bin/zsh username # change the login shell
usermod -l newname oldname # rename the account
usermod -L username # lock the account (disable password login)
usermod -U username # unlock the account
The -a flag with -G is critical and frequently forgotten. -a means append: the named group is added to the user’s existing supplementary groups. Without -a, usermod -G sudo username replaces the user’s entire group list with just sudo, silently removing them from every other group they belonged to, which can break access to things like docker or video groups they were relying on.
Deleting a user with userdel
sudo userdel username # remove the account, leave home directory intact
sudo userdel -r username # remove the account and its home directory and mail spool
-r is destructive and irreversible, it deletes the user’s home directory and everything in it. Without -r, the account entry is removed but the home directory remains on disk, owned by a now-nonexistent user ID, which can be useful if you need to preserve files before deciding what to do with them.
What’s inside /etc/passwd
Every account on the system has a line in /etc/passwd, in a fixed colon-delimited format:
username:x:1001:1001:Jane Smith:/home/username:/bin/bash
The fields, in order: username, a placeholder x (the real password used to live here decades ago, before /etc/shadow existed), user ID (UID), primary group ID (GID), a comment field (often the full name), home directory, and login shell.
/etc/passwd is world-readable by design, since many ordinary programs need to resolve a user ID to a username or look up a home directory, and that lookup should not require special privileges.
getent passwd username # look up a specific user's entry
cat /etc/passwd | wc -l # count total accounts on the system
What’s inside /etc/shadow
/etc/shadow holds the actual encrypted password hash and password aging information, and is readable only by root:
username:$6$randomsalt$hashvalue...:19700:0:99999:7:::
The fields include the username, the encrypted password hash, the date of the last password change, minimum and maximum password age, a warning period before expiration, and an inactivity period. Keeping this file root-only, separate from the world-readable /etc/passwd, is specifically why the split exists: ordinary programs can still resolve usernames and home directories without ever being able to read password hashes.
sudo cat /etc/shadow | grep username
sudo chage -l username # view password aging info for a user in readable form
Groups
Every user has one primary group (recorded in /etc/passwd) and can belong to any number of supplementary groups (recorded in /etc/group). Group membership is how Linux grants access to shared resources, like a docker group that lets members run Docker without sudo, or a video group that grants access to hardware video devices.
groups username # list groups a user belongs to
id username # show UID, GID, and all group memberships
usermod -aG groupname username # add a user to a supplementary group
gpasswd -d username groupname # remove a user from a supplementary group
Group membership changes typically require the affected user to log out and back in (or start a new shell session) before they take effect in that session, since group membership is read when a login session begins.
Password aging and expiration
sudo chage -l username # view current aging settings
sudo chage -M 90 username # require a password change every 90 days
sudo chage -E 2026-12-31 username # set an account expiration date
sudo passwd -l username # lock a password (disable password login)
sudo passwd -u username # unlock a password
chage is the dedicated tool for viewing and setting password aging policy, while passwd -l and passwd -u handle simple locking and unlocking of the password itself, distinct from usermod -L and -U, which lock the account at a slightly different level. In practice both approaches are commonly used interchangeably for disabling password login on an account.
Frequently Asked Questions
What is the difference between useradd and adduser?
useradd is the low-level utility present on essentially every Linux distribution, and by default it creates a fairly bare account: no home directory contents copied in, no password set, and minimal interactive feedback. adduser is a higher-level, more user-friendly Perl script available on Debian and Ubuntu (and derivatives) that wraps useradd, asking interactive questions, setting a password, and populating the home directory from /etc/skel automatically. On Debian-based systems, adduser is generally the more convenient choice for manual account creation, while useradd is more common in scripts because its behavior is predictable and consistent across distributions.
How do I create a new user with a home directory in one step?
Use useradd -m username, where -m tells useradd to create the home directory if it does not already exist, populating it with the default files from /etc/skel. Without -m on most distributions, useradd creates the account entry but no home directory at all, which breaks login and any program that expects $HOME to exist. Some distributions configure useradd to create home directories by default via /etc/login.defs, but explicitly passing -m is the safe, portable habit regardless of distribution defaults.
How do I give a user sudo access?
Add the user to the group that grants sudo privileges on your distribution, which is usually sudo on Debian and Ubuntu, or wheel on Fedora, RHEL, and Arch: usermod -aG sudo username (or usermod -aG wheel username). The -a flag is essential here, it means append, adding the new group without removing the user from any groups they already belong to. Running usermod -G sudo username without -a replaces the user’s entire supplementary group list with just sudo, which can silently strip access the user already had to other groups.
What is the difference between /etc/passwd and /etc/shadow?
/etc/passwd stores basic account information, readable by every user on the system: username, user ID, group ID, home directory, and login shell. It historically also stored the encrypted password, but modern systems moved that into /etc/shadow instead, which is readable only by root, specifically because /etc/passwd needs to remain world-readable for basic system functionality (like resolving user IDs to usernames), while password hashes should never be exposed to unprivileged users. /etc/shadow also stores password aging information: when the password was last changed, and rules about expiration and warnings.
How do I delete a user account and their home directory?
userdel username removes the account entry but leaves the home directory and mail spool in place by default. To remove the home directory and mail spool as well, add -r: userdel -r username. Before deleting an account, consider whether any files owned by that user elsewhere on the filesystem (outside the home directory) need to be reassigned or cleaned up separately, since userdel only touches the account entry and, with -r, the home directory, not arbitrary files scattered across the system that the user happened to own.
Why do I need to use passwd after creating a user with useradd?
useradd on its own does not set a password, it creates the account in a locked state with no valid password, meaning the account cannot log in with a password until one is set. Run sudo passwd username immediately after creating an account to set an initial password interactively. Alternatively, useradd -p accepts a pre-encrypted password hash directly, which is how automated provisioning scripts typically set a password without an interactive prompt, but the value must already be hashed; passing a plain-text password to -p sets that literal string as the encrypted hash, which will not work as a real password.