Courseiva
LPIC-1Chapter 8 of 17Objective 104.2

User and Group Administration

Exam objective 104.2 covers managing local user and group accounts, passwords, and configuration files—the backbone of Linux security and resource sharing. Without this system, every person using a Linux computer would have the same powers and access, leading to chaos and accidental file deletions. For LPIC-1, you must master how to create, modify, and delete users and groups because controlling who can do what on a system is the first step toward being a competent Linux administrator.

12 min read
Intermediate
Updated Jul 23, 2026
Editorial oversight: Johnson Ajibi· Senior Network & Security Engineer · MSc IT Security · IEEE Senior Member

A simple way to picture User and Group Administration

The Apartment Building Analogy

Have you ever lived in a building with a shared mailbox area? If you have, you know it's a system that works well until someone starts getting your mail. In user and group administration, every person using a Linux system is like a tenant in an apartment building. Each tenant (user) has their own flat (home directory) with a key (password) that only they should possess. The building manager (the root user) can access every flat for maintenance but gives each tenant a unique key to their own space.

Now, what about groups? Think of them as the building's social clubs: the 'Book Club' or the 'Running Group'. Belonging to the 'Running Group' means you get access to the communal running track behind the building, regardless of which individual flat you live in. A user can be a member of multiple clubs, and the club permissions (group permissions) allow them to read or write in certain shared folders (like the club noticeboard).

Finally, the configuration files like /etc/passwd and /etc/group are the building's master ledger—a list of all tenants, their flat numbers, and which clubs they've joined. If the ledger gets corrupted, tenants can't get into their flats or the club room. This is why managing these files with commands like useradd, usermod, and groupmod is crucial: you are updating the building's records so that everyone has exactly the right access to the right spaces, and no one accidentally gets into the wrong flat.

How It Actually Works

In Linux, every process and every file is owned by a user. This ownership is what enforces security and privacy. If you log in as user 'alice', you can read Alice's files, but you cannot read Bob's files unless Bob explicitly grants you permission. This is the fundamental concept of user administration.

At the heart of this system lies the file /etc/passwd. Despite its name, this file stores a list of all user accounts on the system along with key details. Each line represents one user, with fields separated by colons. For example: alice:x:1001:1001:Alice Smith:/home/alice:/bin/bash. Let's break that down. The first field is the username ('alice'). The second field used to hold the encrypted password, but today it holds just an 'x', meaning the real password is stored in a separate, locked-down file called /etc/shadow. The third field is the User ID (UID), a numeric identifier. The fourth field is the Group ID (GID), which specifies the user's primary group. Next comes a comment field (often the user's full name), then the path to the user's home directory, and finally the user's default shell (the program that starts when they log in).

The file /etc/shadow is more sensitive. It contains the actual password hash (a scrambled version of the password), plus password expiry information. Only the root user can read this file, preventing regular users from grabbing password hashes and trying to crack them.

Similarly, group information lives in /etc/group. A line might look like: developers:x:3000:alice,bob,charlie. This shows the group name ('developers'), a placeholder for the group password (again, usually 'x'), the Group ID (3000), and a comma-separated list of members who belong to this group. Groups allow you to assign permissions to multiple users at once. For instance, instead of giving read permission to every single employee, you create a 'sales' group, assign the sales folder's group ownership to that group, and then add the relevant users to it.

How do you create these accounts? Using the command useradd. To create a new user named 'carol' with a home directory: useradd -m carol. The -m flag creates the /home/carol directory. To set her password, you run passwd carol and enter it twice. The passwd command writes the hash to /etc/shadow.

To modify an existing user, you use usermod. Want to add 'carol' to the 'developers' group? usermod -a -G developers carol. The -a flag means 'append', so you don't remove her from any groups she might already be in. The -G flag specifies the supplementary group (not her primary group).

To delete a user, use userdel. userdel -r carol removes the user and also deletes their home directory and mail spool. Without -r, the home directory remains orphaned.

For groups, the commands are groupadd, groupmod, and groupdel. groupadd finance creates a new group. groupmod -n accounting finance renames 'finance' to 'accounting'. groupdel accounting removes the group (as long as it's not any user's primary group).

Why does all this matter? Because without this structure, there is no access control. Every user could read every file, change every configuration, and delete critical system files. By assigning users and groups, you enforce the principle of least privilege—giving each person only the access they need to do their job. For LPIC-1, you need to know these commands inside out, understand the format of the three key files (passwd, shadow, group), and be able to troubleshoot common issues like 'user not in sudoers file' or 'group not found'.

This diagram shows the relationships between user accounts, groups, and configuration files, along with the commands used to manage them.

Walk-Through

1

Create a new user with a home directory

Run useradd -m newusername. The -m flag tells the system to create the home directory /home/newusername. Without this flag, the user account exists but has no home directory, which can cause login issues.

2

Set the user's password

Run passwd newusername. You will be prompted to enter the password twice for confirmation. The system hashes the password and stores it in /etc/shadow. The password must be set before the user can log in.

3

Add the user to supplementary groups

Run usermod -a -G group1,group2 newusername. The -a flag is critical: it appends the user to the listed groups without removing them from groups they are already a member of. The -G flag specifies the supplementary groups.

4

Verify the user's information

Check the user's details by reading the relevant files: grep newusername /etc/passwd shows UID, GID, home directory, and shell. grep newusername /etc/group shows which groups they belong to. This step ensures the account was created correctly.

5

Lock or delete the user when they leave

To immediately revoke access without deleting data, run usermod -L newusername to lock the password. To fully remove the account later, run userdel -r newusername to delete the user and their home directory and mail spool.

What This Looks Like on the Job

Imagine you are the sole IT administrator for a small marketing agency called 'Pixel & Page'. The company has 20 employees: designers, copywriters, and account managers. Your boss asks you to set up a Linux file server so everyone can share project files but with strict access controls.

Here is what you actually do, step by step.

First, you create groups for each team. You run: - groupadd designers - groupadd copywriters - groupadd account_managers

Next, you create the user accounts. For a new designer named 'Diana', you run useradd -m -G designers diana. This creates her home directory and puts her in the 'designers' group as a supplementary member. Then you set her password with passwd diana. You repeat this for every employee.

Now you create the shared directories. You make a folder /projects/designs and change its group to 'designers': chown root:designers /projects/designs. You set the permissions so that members of the 'designers' group can read and write files inside it, but others cannot: chmod 2770 /projects/designs. The 2 in front sets the setgid bit, meaning new files created inside that directory will automatically inherit the 'designers' group, not the creator's primary group—this is crucial so that Diana can edit a file created by another designer without permission errors.

But a problem arises. An account manager named 'Mike' needs to read some design files for a client presentation. You add him to the 'designers' group temporarily: usermod -a -G designers mike. Now he can access the files. When the presentation is over, you remove him: gpasswd -d mike designers. This is the daily reality of user and group administration: constantly adjusting memberships to reflect changing project roles.

Eventually, a copywriter named 'Sarah' leaves the company. You need to disable her account so she can't log in, but you might need to keep her files for audits. You run usermod -L sarah to lock her password (the -L flag puts a '!' at the start of the password hash in /etc/shadow, invalidating it). After the audit period, you run userdel -r sarah to remove her completely.

You also regularly audit the /etc/passwd and /etc/group files to look for unused accounts. A quick command like awk -F: '($3 > 999) {print $1}' /etc/passwd lists all user accounts (UIDs above 999 are typically regular users, not system accounts). You cross-reference with the company's HR list to ensure no unauthorised accounts exist.

This scenario shows that user and group administration is not a one-time setup; it is an ongoing process of granting and revoking access as people join, move between teams, and leave the organisation. For the LPIC-1 exam, you need to be able to perform all these actions from the command line without a graphical interface, because real servers often have no GUI.

How LPIC-1 Actually Tests This

The LPIC-1 exam 104.2 focuses heavily on command syntax and the content of configuration files. You will get questions that test your ability to predict the outcome of a specific command. Here is what you must know cold.

First, you must memorise the structure of /etc/passwd, /etc/shadow, and /etc/group. Expect questions like: 'Which field in /etc/passwd contains the user's home directory?' (the 6th field) or 'What does the 'x' in the password field mean?' (the real password is in /etc/shadow).

The exam loves to test the difference between a user's primary group (defined in /etc/passwd) and their supplementary groups (defined in /etc/group). A common trap: they ask, 'If user alice is in group 'staff' in /etc/passwd, and also in group 'admin' in /etc/group, which group is her primary group?' The answer is her primary group is the one from /etc/passwd.

Key commands to memorise: - useradd: options include -m, -d, -s, -g, -G, -u, -c. - usermod: options include -aG (append to supplementary groups), -l (change login name), -L (lock account), -U (unlock). - userdel: option -r (remove home directory and mail spool). - groupadd: option -g to specify the GID. - groupmod: option -n (rename group). - gpasswd: used to manage group membership list (e.g., gpasswd -a user group adds, gpasswd -d user group removes). - passwd: to change a password. The root user can set any user's password without knowing the old one.

Trap patterns to watch for:

They often ask what happens if you run useradd without the -m flag: the home directory is not created.

They test that usermod without the -a flag will replace the supplementary groups, not add to them. For example, if alice is in groups A, B, C, and you run usermod -G D alice, she will only be in group D. To add D without losing A, B, C, you must use usermod -a -G D alice.

They test that deleting a group with groupdel fails if it is still the primary group of any user. You must first change those users' primary groups using usermod -g newgroup user.

They test password ageing using the chage command (e.g., chage -M 30 user sets max days before password must change). Questions may ask which field in /etc/shadow corresponds to the max days (field 5).

Also, expect a question about the /etc/default/useradd file, which holds default values for new users (like the default home directory base path or default shell). Modifying this file changes the behaviour of useradd without needing to specify options each time.

Finally, the exam asks about 'user quotas' (objective 104.4), but in 104.2, they focus purely on account management. Questions will not mix quotas into this objective.

To summarise: if you can write out the syntax of useradd, usermod, userdel, groupadd, groupmod, groupdel, and gpasswd from memory, and explain every field in passwd, shadow, and group, you will pass this section easily.

Key Takeaways

The three critical files for local user management are /etc/passwd (user accounts), /etc/shadow (password hashes and expiry), and /etc/group (group definitions and memberships).

The useradd -m flag is essential for creating a home directory for a new user; without it, the directory is not created automatically.

When adding a user to supplementary groups with usermod, always use the -a flag together with -G to avoid accidentally removing the user from existing groups.

Locking a user account with usermod -L places an exclamation mark in the password hash field of /etc/shadow, making the password invalid.

You cannot delete a group with groupdel if it is any user's primary group; you must first change those users' primary groups to another group.

The /etc/shadow file is readable only by the root user, which is why passwords are stored there instead of in the world-readable /etc/passwd.

Easy to Mix Up

These come up on the exam all the time. Here's how to tell them apart.

Primary Group

Defined in /etc/passwd in the GID field

A user can have only one primary group

New files created by the user belong to this group

Supplementary Group

Defined in /etc/group in the member list

A user can belong to many supplementary groups

Used to grant access to shared resources like project directories

useradd

Creates a new user account

Does not modify existing users

Commonly used with -m to create home directory

usermod

Modifies an existing user account

Can change username, groups, home directory, shell

Commonly used with -aG to add groups

/etc/passwd

World-readable

Contains username, UID, GID, home directory, shell

Password field stores 'x' placeholder

/etc/shadow

Readable only by root

Contains password hash and expiry data

Fields include last change date, max days, warn days

Locking an account (usermod -L)

Preserves user's files and home directory

User cannot log in but account still exists

Easily reversible with usermod -U

Deleting an account (userdel -r)

Removes user and optionally home directory and mail spool

Cannot be easily reversed

Used when employee leaves permanently

Watch Out for These

Mistake

The /etc/passwd file stores encrypted passwords.

Correct

The /etc/passwd file stores only a placeholder 'x' in the password field; actual password hashes are in /etc/shadow, which is only readable by root.

This misconception dates back to older Unix systems where passwords were indeed stored in /etc/passwd. Beginners see the file name and assume it still holds passwords.

Mistake

Deleting a user with userdel without any flags also deletes their home directory.

Correct

By default, userdel does not remove the home directory or mail spool. You must use the -r flag to remove those directories.

Beginners think 'delete user' means remove everything, but Linux intentionally leaves the data behind in case an administrator wants to archive or transfer files.

Mistake

A user can only belong to one group at a time.

Correct

A user has one primary group (defined in /etc/passwd) and can belong to many supplementary groups (defined in /etc/group).

This confusion arises because in some simple scenarios (e.g., a single-user laptop), you only see one group. But in enterprise systems, users belong to multiple groups to access different shared resources.

Mistake

The /etc/group file lists only the group name and GID.

Correct

The /etc/group file also contains a group password field (usually empty or 'x') and a comma-separated list of group members.

Beginners often read shortened explanations online that omit the group password and members fields, leading to an incomplete understanding of the file format.

Mistake

Using usermod -g newgroup user changes only the supplementary groups.

Correct

The -g option changes the user's primary group. To change supplementary groups, use -G (with -a to append).

The lowercase 'g' and uppercase 'G' are confusingly similar, and new users often mix them up, especially when reading man pages quickly.

Do You Actually Know This?

Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.

Frequently Asked Questions

What is the difference between /etc/passwd and /etc/shadow?

/etc/passwd stores user account information (username, UID, GID, home directory, shell) and is world-readable. /etc/shadow stores the encrypted password hash and password expiry data and is only readable by root.

Why can't I delete a group with groupdel?

If the group is set as any existing user's primary group (the GID field in /etc/passwd), groupdel will refuse to delete it. You must first change those users' primary groups using usermod -g newgroup user.

What does the -a flag do in usermod -a -G?

The -a flag stands for 'append'. It ensures that the user is added to the groups listed with -G without losing membership in any other supplementary groups they already belong to.

How do I create a user without a home directory?

Simply omit the -m flag when running useradd. For example, useradd tempuser creates the account but does not create /home/tempuser. This is useful for system accounts that don't need a home directory.

What command do I use to rename a user?

Use usermod -l newname oldname. For example, usermod -l jane john renames the user from 'john' to 'jane'. You may also need to rename the home directory manually with mv.

How do I see what groups a user is in?

Use the groups command followed by the username, e.g., groups alice. This shows all groups (primary and supplementary) that the user belongs to.

Terms Worth Knowing

Keep going

You've finished User and Group Administration. Continue through the LPIC-1 study guide to build a complete picture of the exam.

Done with this chapter?