The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect current identity | id | View examples |
| Inspect one user | id -- deploy | View examples |
| Resolve a passwd entry | getent passwd deploy | View examples |
| Resolve a group | getent group appops | View examples |
| Create a local group | sudo groupadd -- appops | View examples |
| Create a home-backed user | sudo useradd --create-home --shell /bin/bash -- deploy | View examples |
| Set a password interactively | sudo passwd deploy | View examples |
| Append a supplementary group | sudo usermod --append --groups appops -- deploy | View examples |
| Inspect password aging | sudo chage --list deploy | View examples |
| Lock password authentication | sudo usermod --lock -- deploy | View examples |
| Expire immediately | sudo usermod --expiredate 1 -- deploy | View examples |
| Delete after review | sudo userdel --remove -- deploy | View examples |
Linux authorization uses numeric UIDs and GIDs; names are resolved through configured identity services. Inspect with getent and id before changes, preserve the existing supplementary-group list when appropriate, and lock or expire an account while ownership and service dependencies are investigated before deletion.
Step by step
Detailed examples
Resolve names through the configured identity stack
getent respects NSS configuration and may return local, directory, or other identities; direct parsing of /etc/passwd misses those sources. Numeric ownership remains after an identity is removed, so record UID/GID and source. Group membership may require a new login session to appear.
getent passwd deploy
getent group appops
id -- deploy
getent initgroups deploy Review defaults before creating local identities
useradd behavior depends on login.defs and distribution defaults. Choose home, primary group, supplementary groups, shell, and expiry explicitly. passwd reads interactively; never place plaintext passwords on the command line or in process-visible scripts.
sudo useradd --defaults
getent group appops || sudo groupadd -- appops
sudo useradd --create-home --shell /bin/bash --gid appops -- deploy
sudo passwd deploy Note: These commands change the local identity database; verify the target host and policy first.
Append memberships and inspect the result
usermod -G replaces the entire supplementary list unless combined with -a, a common source of accidental privilege loss. Primary and supplementary groups serve different purposes. Password aging does not necessarily govern SSH keys or external identity providers.
id -- deploy
sudo usermod --append --groups appops -- deploy
id -- deploy
sudo chage --list deploy Contain access before irreversible deletion
Password locking alone does not stop SSH keys, tokens, cron jobs, services, or active sessions. Expire or lock according to policy, stop dependent work, locate files by numeric UID, transfer authorized ownership, and only then delete. Reusing the same name later creates a different UID.
id -- deploy
sudo find / -xdev -uid "$(id -u deploy)" -print
sudo usermod --lock -- deploy
sudo usermod --expiredate 1 -- deploy Note: The filesystem scan can be expensive; narrow it to relevant filesystems in production.
Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



