Linux user and permission management: accounts, groups and sudo
For support technicians and junior system administrators who can already run basic Linux commands, create a first admin user and read ls -l output (see 'Linux administration basics' and 'File and share permissions') and now handle access requests on their own. You'll create accounts and groups with the right home directory, shell and group membership, change, lock, expire and remove accounts when people move or leave (including why a locked password doesn't stop SSH key logins), write sudoers rules that give a role only the commands it needs and validate them with visudo, set ownership, modes, umask and the setgid bit for a shared team directory, and verify effective access before closing a request. Grounded in the man7.org manual pages for useradd, usermod, userdel, passwd, chage, sudoers, visudo, chmod, chown and umask, GNU coreutils and Ubuntu Server's user management guide. Practise on lab systems; make changes on real servers only through your change process. Ends with a supervisor-graded access request.
- Level
- Intermediate
- Length
- About 100 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Create Linux user accounts and groups with the right home directory, shell, primary group and supplementary groups
- Choose the correct way to change, lock, expire or remove a Linux account when someone moves role or leaves
- Write sudoers rules that grant only the commands a role needs and validate them with visudo
- Set ownership, modes, umask and the setgid bit so a team directory stays shared and private
- Verify a user's effective access with id, ls -ld, sudo -l and a fresh login before closing an access request
Course outline
- 1.Create Linux user accounts and groups with the right home, shell and groupsLesson · 18 min
- 2.Choose the correct way to change, lock, expire or remove an accountLesson · 20 min
- 3.Write sudoers rules that grant only the commands a role needs, and validate them with visudoLesson · 22 min
- 4.Set ownership, modes, umask and the setgid bit for a shared team directoryLesson · 16 min
- 5.Verify a user's effective access before closing an access requestLesson · 12 min
- 6.Linux user and permission management: accounts, groups and sudo: knowledge checkKnowledge check · 14 questions
- 7.Linux user and permission management: accounts, groups and sudo: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- useradd(8) manual page (man7.org)
- usermod(8) manual page (man7.org)
- userdel(8) manual page (man7.org)
- passwd(1) manual page (man7.org)
- chage(1) manual page (man7.org)
- sudoers(5) manual page (man7.org)
- visudo(8) manual page (man7.org)
- sudo(8) manual page (man7.org)
- chmod(1) manual page (man7.org, GNU coreutils)
- chown(1) manual page (man7.org, GNU coreutils)
- umask(2) manual page (man7.org)
- login.defs(5) manual page (man7.org)
- credentials(7) manual page (man7.org): process user and group IDs
- GNU Coreutils manual: Directories and the Set-User-ID and Set-Group-ID Bits
- Ubuntu Server documentation: User management
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.