Skip to content

User and Group Management

Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x

Linux is a multi-user operating system. Properly managing users and groups is the foundation of system security. This article explains how to create, modify, and delete users and groups on EL systems, as well as the structure of the related configuration files.

  • Create, modify, and delete users
  • Manage user groups
  • Understand the structure of /etc/passwd, /etc/shadow, and /etc/group
  • Use the id command to view user information
  • Configure password expiration policies
  • A system with EL 9.x installed
  • A user account with sudo privileges
View the current user's UID, GID, and group memberships
$ id
uid=1000(admin) gid=1000(admin) groups=1000(admin),10(wheel)
View information about a specific user
$ id username
View the currently logged-in username
$ whoami
admin
Create a new user
$ sudo useradd webuser

This automatically performs the following actions:

  • Adds a user record to /etc/passwd
  • Adds a password record to /etc/shadow
  • Creates a group with the same name
  • Creates the home directory /home/webuser
  • Copies default configuration files from /etc/skel to the home directory
Set a password for the new user
$ sudo passwd webuser
Changing password for user webuser.
New password:
Retype new password:
passwd: all authentication tokens updated successfully.
Create a user with a custom home directory
$ sudo useradd -d /opt/appuser appuser
Create a user with a specific login shell
$ sudo useradd -s /bin/zsh devuser
Create a user with a specific UID
$ sudo useradd -u 1500 customuser
Create a user and add to supplementary groups
$ sudo useradd -G wheel,docker deploy
Create a system user (no home directory, no login shell)
$ sudo useradd -r -s /sbin/nologin appservice

Options summary:

OptionDescription
-d <directory>Specify the home directory
-s <shell>Specify the login shell
-u <UID>Specify the UID
-g <primary group>Specify the primary group
-G <supplementary groups>Specify supplementary groups (comma-separated)
-mForce creation of the home directory (default behavior)
-MDo not create a home directory
-rCreate a system user
-e <date>Set the account expiration date (YYYY-MM-DD)
-c <comment>Set the user comment (full name, etc.)
Change a user's login shell
$ sudo usermod -s /bin/zsh webuser
Add a user to a supplementary group (preserving existing groups)
$ sudo usermod -aG wheel webuser
Rename a user
$ sudo usermod -l newname oldname
Lock a user account (prevent login)
$ sudo usermod -L webuser
Unlock a user account
$ sudo usermod -U webuser
Set an account expiration date
$ sudo usermod -e 2026-12-31 tempuser
Delete a user (keep the home directory)
$ sudo userdel webuser
Delete a user along with their home directory and mailbox
$ sudo userdel -r webuser
View all groups the current user belongs to
$ groups
admin wheel
View groups for a specific user
$ groups webuser
View the members of a group
$ getent group wheel
wheel:x:10:admin,deploy
Create a new group
$ sudo groupadd developers
Create a group with a specific GID
$ sudo groupadd -g 2000 dbadmin
Add a user to a group
$ sudo usermod -aG developers webuser
Add a user to a group using gpasswd
$ sudo gpasswd -a webuser developers
Remove a user from a group using gpasswd
$ sudo gpasswd -d webuser developers
Rename a group
$ sudo groupmod -n newname oldname
Delete a group
$ sudo groupdel developers

Stores basic user account information, one user per line, with 7 fields:

username:password-placeholder:UID:GID:comment:home-directory:shell
View a user record in /etc/passwd
$ grep webuser /etc/passwd
webuser:x:1001:1001::/home/webuser:/bin/bash

Field descriptions:

FieldExampleDescription
1webuserUsername
2xPassword placeholder (actual password stored in /etc/shadow)
31001UID (User ID)
41001GID (Primary Group ID)
5(empty)GECOS comment field (typically the full name)
6/home/webuserHome directory path
7/bin/bashLogin shell

Stores encrypted passwords and password policy information. Only root can read this file.

View a record in the shadow file (requires root privileges)
$ sudo grep webuser /etc/shadow
webuser:$6$xxxx...hash...:19807:0:99999:7:::

The file has 9 colon-separated fields:

FieldDescription
1Username
2Encrypted password (! or !! means the account is locked/has no password)
3Date of last password change (days since 1970-01-01)
4Minimum password age in days (0 means no restriction)
5Maximum password age in days (99999 means never expires)
6Number of warning days before password expiration
7Number of days after password expiration before the account is disabled
8Account expiration date
9Reserved field

Stores group information, one group per line, with 4 fields:

group-name:password:GID:member-list
View the wheel group information
$ grep wheel /etc/group
wheel:x:10:admin,deploy
FieldExampleDescription
1wheelGroup name
2xGroup password (rarely used)
310GID
4admin,deployGroup members (comma-separated)

Password Policies and Expiration Management

Section titled “Password Policies and Expiration Management”
View a user's password expiration details
$ sudo chage -l webuser

Example output:

Last password change : Mar 24, 2026
Password expires : never
Password inactive : never
Account expires : never
Minimum number of days between password change : 0
Maximum number of days between password change : 99999
Number of days of warning before password expires : 7
Set the maximum password validity to 90 days
$ sudo chage -M 90 webuser
Set the minimum password change interval to 7 days
$ sudo chage -m 7 webuser
Set warning to begin 14 days before expiration
$ sudo chage -W 14 webuser
Set an account expiration date
$ sudo chage -E 2026-12-31 tempuser
Force the user to change password at next login
$ sudo chage -d 0 webuser

Configure Global Default Password Policies

Section titled “Configure Global Default Password Policies”

Global defaults are stored in /etc/login.defs:

View default password policy settings
$ grep -E "^PASS_" /etc/login.defs
PASS_MAX_DAYS 99999
PASS_MIN_DAYS 0
PASS_MIN_LEN 5
PASS_WARN_AGE 7

Practical Example: Creating a Project Team

Section titled “Practical Example: Creating a Project Team”

The following is a complete example demonstrating how to create users and groups for a project team.

  1. Create the project group

    Create the project group
    $ sudo groupadd project
  2. Create team members

    Create users and add them to the project group
    $ sudo useradd -G project -c "Zhang San" zhangsan
    $ sudo useradd -G project -c "Li Si" lisi
  3. Set passwords for the users

    Set passwords
    $ sudo passwd zhangsan
    $ sudo passwd lisi
  4. Configure password policies

    Set 90-day password expiration
    $ sudo chage -M 90 zhangsan
    $ sudo chage -M 90 lisi
  5. Verify the configuration

    Confirm user and group configuration is correct
    $ id zhangsan
    uid=1002(zhangsan) gid=1002(zhangsan) groups=1002(zhangsan),2001(project)
    $ getent group project
    project:x:2001:zhangsan,lisi

What is the Difference Between useradd and adduser

Section titled “What is the Difference Between useradd and adduser”

On EL systems, adduser is a symbolic link to useradd, and the two are identical:

Verify that adduser points to useradd
$ ls -la /usr/sbin/adduser
lrwxrwxrwx 1 root root 7 ... /usr/sbin/adduser -> useradd

Check the following:

Confirm the account is not locked
$ sudo passwd -S webuser
webuser PS 2026-03-24 0 99999 7 -1 (Password set, SHA512 crypt.)

Status field meanings: PS = Password set, LK = Locked, NP = No password.

Check whether the shell allows login
$ grep webuser /etc/passwd | cut -d: -f7
/bin/bash

If the shell is /sbin/nologin or /bin/false, the user cannot log in interactively.

List regular users with UID >= 1000
$ awk -F: '$3 >= 1000 && $3 < 65534 {print $1}' /etc/passwd