How do I create a new user on a Linux server?

Updated October 2026 · How we answer

Short answerUse sudo adduser username (Debian/Ubuntu) or sudo useradd -m username (RHEL-based), then set a password with sudo passwd username and add sudo privileges if needed.

Creating the user

On Debian and Ubuntu, the friendly command is sudo adduser username. It prompts for a password and optional details, creates a home directory, and sets up a default shell. On RHEL, CentOS, and Fedora, use sudo useradd -m username followed by sudo passwd username to set the password.

The -m flag tells useradd to create a home directory. Without it, the user gets no home directory and may have trouble logging in. You can also specify a shell with -s /bin/bash and add the user to groups with -G group1,group2.

Granting sudo access

To let the new user run administrative commands, add them to the sudo group (Debian/Ubuntu) or the wheel group (RHEL-based). Run sudo usermod -aG sudo username or sudo usermod -aG wheel username. The -a flag is important: it appends to existing groups instead of replacing them.

The user must log out and back in for group changes to take effect. You can verify group membership with the groups username command.

  • adduser username (Debian/Ubuntu)
  • useradd -m username (RHEL-based)
  • passwd username to set password
  • usermod -aG sudo username (Debian/Ubuntu)
  • usermod -aG wheel username (RHEL-based)
  • groups username to check

SSH keys and cleanup

For key-based login, create the ~/.ssh directory in the user's home, add their public key to ~/.ssh/authorized_keys, and set correct permissions: 700 for .ssh and 600 for authorized_keys, owned by the user. Otherwise SSH will refuse the key.

To remove a user later, use sudo deluser username (Debian/Ubuntu) or sudo userdel -r username (RHEL-based). The -r flag removes the home directory and mail spool.

Common mistakes

  • Forgetting -m with useradd, leaving the new user without a home directory.
  • Using usermod -G sudo without -a, which removes the user from all other groups.
  • Setting world-readable permissions on ~/.ssh or authorized_keys, causing SSH to ignore the key.
From our shopsTitan Case: Premium MagSafe iPhone cases with a precision fit.