Skip to main content

usermod Cheatsheet

By Dejan Panovski •Updated on • Download PDF

Quick reference for modifying Linux user accounts with usermod and managing groups with groupadd, gpasswd, and groupdel

The usermod command changes existing user accounts in Linux, from group membership and login shell to home directory, UID, and account locking. This cheatsheet also covers the group commands you use alongside it.

Basic Syntax

Core usermod command forms.

CommandDescription
sudo usermod [options] usernameGeneral syntax
sudo usermod -c "Full Name" usernameChange the GECOS/comment field
id usernameShow UID, GID, and group membership
getent passwd usernameShow the user’s account entry
usermod --helpList all available options

Supplementary Groups

Add or remove secondary group membership.

CommandDescription
sudo usermod -aG docker usernameAdd user to one group
sudo usermod -aG docker,sudo usernameAdd user to multiple groups
sudo usermod -G docker usernameReplace all supplementary groups with docker
sudo usermod -rG docker usernameRemove user from one group
sudo gpasswd -d username dockerRemove user from one group (alternative)

Primary Group

Change the group assigned to new files the user creates.

CommandDescription
sudo usermod -g developers usernameSet primary group to developers
id -gn usernameShow the user’s primary group
newgrp developersStart a shell with developers as the active group
sudo chgrp developers fileChange group ownership of a file
sudo chgrp -R developers dir/Change group ownership recursively

Home Directory and Shell

Move the home directory or change the login shell.

CommandDescription
sudo usermod -d /srv/username -m usernameChange home path and move its contents
sudo usermod -d /srv/username usernameChange home path only (old files stay in place)
sudo usermod -s /bin/zsh usernameChange login shell
sudo usermod -s /usr/sbin/nologin usernameDisable interactive login
cat /etc/shellsList valid login shells

Rename and UID

Change the login name or numeric user ID. Record the old UID before using -u, and review the find results before running chown.

CommandDescription
sudo usermod -l newname oldnameRename the user account
sudo usermod -l newname -d /home/newname -m oldnameRename user and move home directory
sudo groupmod -n newname oldnameRename the matching user private group
old_uid=$(id -u username)Record the current UID before changing it
sudo usermod -u 1050 usernameChange UID (files in home are updated)
sudo find /srv -xdev -uid "$old_uid" -printPreview files still owned by the old UID under /srv
sudo find /srv -xdev -uid "$old_uid" -exec chown -h username {} +Reassign old-UID files under /srv to the user

Replace /srv with the directory or mount point you need to repair. The -xdev option stays on that filesystem, so scan other mounts separately. Use the same shell session so $old_uid remains available.

Lock, Unlock, and Expiry

Lock or unlock password authentication and set an account expiry date.

CommandDescription
sudo usermod -L usernameLock the account password
sudo usermod -U usernameUnlock the account password
sudo usermod -e 2026-12-31 usernameExpire the account on a date
sudo usermod -e "" usernameRemove the expiry date
sudo chage -l usernameShow expiry and password aging details

The -L option blocks password authentication only; SSH keys may still work. The -U option does not remove an account expiry date; use -e "" separately when needed.

Manage Groups

Create, rename, and delete groups.

CommandDescription
sudo groupadd developersCreate a group
sudo groupadd -g 1500 developersCreate a group with a specific GID
sudo groupadd -r appgroupCreate a system group
sudo groupmod -n devs developersRename a group
sudo groupdel developersDelete a group

List Users and Groups

Check who belongs where.

CommandDescription
groups usernameList groups a user belongs to
getent group developersShow a group entry and explicitly listed members
getent groupList all groups
getent passwdList all user accounts
cut -d: -f1 /etc/groupList local group names only

Primary group membership is recorded in the passwd database, so primary members may be absent from getent group output. Use id username to check a user’s primary and supplementary groups.

Troubleshooting

Quick checks for common usermod problems.

IssueCheck
user username is currently used by processLog the user out and stop their processes before -l, -u, or -d
New group not activeLog out and back in, or run newgrp groupname
User lost other groups-G without -a replaces the list; re-add the missing groups with -aG
group 'name' does not existCreate it first with groupadd
unlocking the user's password would result in a passwordless accountSet a password with passwd instead of using -U

Use these guides for full user and group management tasks.

GuideDescription
usermod Command in LinuxFull usermod tutorial with examples
How to Add a User to a Group in LinuxManage supplementary and primary groups
How to Create Groups in LinuxCreate groups with groupadd
groupdel Command in Linux: Delete a GroupRemove groups with groupdel
How to List Groups in LinuxShow group membership
useradd CheatsheetCreate new user accounts