Linux Command #39 – usermod (Linux OS)

Linux lesson 39: usermod modifies an existing account and can append a supplementary group.

usermod changes an existing Linux user account. Its most useful beginner task is adding a user to a group while keeping that user’s other group memberships.

The previous lesson, Linux Command #38 – useradd, created an account. This lesson continues from there: the account already exists, and you need to change one of its settings.

By the end: you will be able to read a usermod command, add supplementary group membership, verify the result, and recognize options for changing a shell, home directory, or login name.

Start with the smallest useful command

sudo usermod -aG lab_ops labtech

Read it as: “Add the existing user labtech to the existing group lab_ops, and keep the user’s other supplementary groups.” These are sample lab names. They must exist before this command can work.

PartPlain-English meaning
sudoRun with administrative privileges, if your account is authorized.
usermodModify an existing local account.
-aAppend: keep existing supplementary memberships.
-GSpecify supplementary groups. The uppercase letter matters.
lab_opsThe group to add.
labtechThe account to change. The username goes last.

-aG combines two options. You can also write -a -G; the meaning is the same. The distinction between appending and replacing is documented in the Debian usermod manual. Check man usermod on your own machine for the installed version.

What is a group?

A group brings accounts together so access can be assigned to a team or role. For example, a mining lab might use lab_readers for people who read reports and lab_ops for people who perform approved operations. The names alone grant nothing: files, applications, or other policies must actually use those groups.

TermWhat it means
User accountA named identity on the system, such as labtech.
Primary groupThe account’s main group. It is recorded with the account’s numeric group ID.
Supplementary groupsAdditional memberships the account can use for access.
UID / GIDNumeric user ID / group ID. Linux uses these numbers to track ownership and identity.

If you want a refresher on viewing memberships, see Linux Command #35 – groups. A user’s primary group and supplementary groups can appear together in the output, so do not mistake every displayed group for a supplementary membership.

The important difference: -aG adds; -G replaces

Imagine that labtech already belongs to the supplementary groups lab_readers and video. You want to add lab_ops.

Comparison: usermod -aG adds lab_ops while retaining lab_readers and video; usermod -G replaces the supplementary list with lab_ops. The primary group is unchanged.
Tap the diagram to open the full-size image. Original BitcoinVersus.Tech diagram: -aG retains existing supplementary groups and adds lab_ops; -G alone replaces that list. The primary group is unchanged. Colors distinguish the two paths; this is a concept diagram.
CommandResult in this example
sudo usermod -aG lab_ops labtechSupplementary groups: lab_readers, video, lab_ops.
sudo usermod -G lab_ops labtechSupplementary groups: lab_ops only. The two other memberships are removed.

Use -aG when the goal is to add membership. Use -G alone only when you deliberately intend to replace the complete supplementary list. Removing a group used for administration can cause an access problem after the user starts a new session.

Video 1: See usermod in action

Learn Linux TV — Linux Crash Course: usermod. Watch how account settings are changed, then compare the options with the examples in this lesson.

A small practice lab: inspect, change, verify

Use a disposable Linux VM or training machine that you administer. Keep your administrator session separate from the test account. The exercise changes only the test user’s membership; it does not require changing your own account.

Step 1: Check whether the practice names already exist.

getent passwd labtech
getent group lab_readers
getent group lab_ops

A matching record means that name already exists. If any name belongs to an account or group you did not create for this exercise, choose different unused names and substitute them throughout. If all three names are unused, create the practice objects:

sudo groupadd lab_readers
sudo groupadd lab_ops
sudo useradd -m -U labtech

groupadd creates a group. useradd -m creates the account and its home directory; -U explicitly requests a primary group with the same name. This exercise does not need an interactive login password.

Step 2: Give the test user one existing supplementary membership.

sudo usermod -aG lab_readers labtech
id -nG labtech

For this fresh lab account, a typical result is:

labtech lab_readers

The group labtech is the primary group; lab_readers is supplementary. Group order and additional memberships can vary with system configuration. Focus on which names are present.

Step 3: Add the second group.

sudo usermod -aG lab_ops labtech
id -nG labtech

A typical result is:

labtech lab_readers lab_ops

The important result is that both lab_readers and lab_ops remain. You added access without dropping the first supplementary membership.

Step 4: Check from another view.

groups labtech
getent group lab_ops

The first command lists the account’s memberships. The second should show labtech in the member list for lab_ops. Neither command needs sudo for this ordinary lookup.

Optional: Undo just the membership you added in Step 3.

sudo gpasswd -d labtech lab_ops
id -nG labtech

After that change, lab_readers should still be present and lab_ops should be absent. This step removes a membership, not the user account or either group.

Why can the database and current session disagree?

A running process carries its own group list. Changing the account database does not rewrite that list in processes already running. A fresh login normally picks up the new memberships.

CommandWhat you are checking
id -nG labtechLook up the named account’s groups from the user and group databases.
id -nGInspect the groups of the process running this command.

For an interactive account, save your work, fully log out, and log back in before testing the new access. Opening another terminal inside the same desktop session may inherit the old group list. A service running under that account may need to be restarted through the normal maintenance process.

Video 2: Understand group membership

Learn Linux TV — Linux Crash Course: Managing Groups. This reinforces primary and supplementary groups, usermod -aG, and why a new login can be necessary.

Adding more than one group

List the group names with commas and no spaces between them. All the groups must already exist.

sudo usermod -aG lab_ops,lab_readers labtech
id -nG labtech

Use only the memberships required for the task. Adding a person to a group is meaningful only when the system’s access rules use that group. Red Hat’s user and group administration guide provides a broader view of account management.

Other usermod options worth recognizing

The table below is a reference, not a sequence to run. Check the account and target values before using an option.

OptionPurposeExample
-cChange the account comment.sudo usermod -c "Mining lab operator" labtech
-sChange the login shell.sudo usermod -s /bin/bash labtech
-gChange the primary group. Lowercase g.sudo usermod -g lab_ops labtech
-d with -mChange the recorded home path and move the existing home contents.sudo usermod -d /home/labtech-new -m labtech
-lChange the login name.sudo usermod -l labtech2 labtech
-L / -ULock / unlock the password.sudo usermod -L labtech

For a shell change, first check cat /etc/shells and confirm the chosen executable exists. /bin/bash is an example, not a promise about every Linux installation.

For a login-name or home-directory change, the affected user must have no running processes. Work from a separate administrator account. -l does not automatically rename the home directory. -d without -m changes the recorded path without moving the existing files. Review ownership, application paths, and configuration after a move.

A password lock is not a complete account shutdown. -L blocks password authentication; SSH keys or other methods may still work, and existing sessions are not ended. Likewise, -U does not undo every other access restriction.

To set or change a password, use the interactive command covered in Linux Command #37 – passwd. Do not pass a plain-text password to usermod -p: that option expects an encrypted hash, and command-line arguments can be exposed.

Video 3: Connect the options to practical maintenance

Akamai Developers — How to Utilize the Usermod Utility in Linux to Perform User Maintenance with a Linode Cloud Server. Revisit group changes, home directories, and login names. Keep the lesson’s distinction between locking a password and disabling all access in mind.

Troubleshooting without guessing

What you seeWhat to check
The user does not exist.Check the spelling with getent passwd labtech. usermod modifies an account; it does not create one.
The group does not exist.Check getent group lab_ops. Create a lab group only when that is your intended task.
Permission denied or cannot lock account files.Confirm your administrative authorization and whether another account-management operation is running. Do not delete lock files casually.
The new group is listed, but access still fails.Test in a fresh login. Then check the resource’s permissions and policy; membership alone does not configure the resource.
The user is used by a process.For a rename, UID change, or home move, arrange for that account’s processes to stop before retrying.

This lesson covers local accounts managed by the Linux shadow utilities. If an identity comes from Active Directory, LDAP, or another central service, use that service’s administration workflow. A name returned by getent is not proof that it is a local account.

Check your understanding

  1. What is the difference between useradd and usermod?
  2. Why do we use -aG rather than -G when adding one group?
  3. Does -g use the same meaning as -G?
  4. Why can id -nG labtech show a new membership while labtech’s existing session cannot use it?
  5. Does changing the login name automatically move the home directory?
  6. Does locking the password block every possible login method?

Answers: useradd creates; usermod modifies. -aG appends; -G alone replaces the supplementary list. -g changes the primary group. Existing processes retain their group lists. A login-name change does not automatically move the home directory. A password lock does not block every authentication method.

What to remember

Inspect the account, change only the intended setting, and verify the result. For adding supplementary membership, the pattern is sudo usermod -aG group user. Remember the lowercase a; it keeps the existing supplementary groups.

Presentation note: commands and sample output are plain text, with no simulated terminal colors. Terminal palettes depend on the application, profile, and theme. The comparison diagram uses labeled paths rather than claiming to reproduce a terminal.

BitcoinVersus.Tech

Advertisement

BitcoinVersus.Tech advertisement.

Editor’s Note:

We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb

BitcoinVersus.tech is not a financial advisor. This media platform reports on financial subjects purely for informational purposes.

Leave a comment