The two ways to add a user to sudoers

A user with sudo access can run commands as the root (administrator) user without logging in as root itself. There are two standard ways to grant this access: add the user to the sudoers file directly using the visudo command, or add them to the sudo group. The sudoers file method gives you more control over what commands a user can run. The group method is simpler and works for users who need full administrator privileges.

Both methods require you to be logged in as root or as a user who already has sudo access. If you are setting up the first administrator account on a fresh system, you will need to log in as root directly.

Key Takeaways

  • Use visudo to edit the sudoers file safely — it checks for syntax errors before saving, preventing you from locking yourself out.
  • Adding a user to the sudo group (or wheel group on some systems) grants full sudo access in one command: usermod -aG sudo username.
  • The sudoers file lets you restrict what commands a specific user can run, useful when you want to give limited administrator powers.
  • Never edit the sudoers file directly with a text editor — always use visudo, which prevents syntax errors from breaking sudo access.

Adding a user to the sudo group (the simpler method)

If you want to give a user full sudo access quickly, add them to the sudo group. On Debian-based systems (Ubuntu, Linux Mint), the group is called sudo. On Red Hat-based systems (CentOS, Fedora), it is called wheel. Log in as root or as a user with sudo access, then run:

sudo usermod -aG sudo username

Replace username with the actual login name. The -a flag adds the user to the group without removing them from other groups. The -G flag specifies which group to add them to. The user will have full sudo access the next time they log in.

To verify the change worked, have the user open a terminal and type sudo -v. If they are prompted for their password and it accepts it, they now have sudo access.

Editing the sudoers file for fine-grained control

If you need to restrict what commands a user can run, edit the sudoers file directly. Always use the visudo command, which opens the sudoers file in a text editor and checks for errors before saving. If you make a syntax mistake, visudo will refuse to save and warn you, preventing you from breaking sudo access for everyone.

Log in as root or as a user with sudo access, then type:

sudo visudo

This opens the sudoers file in your default text editor (usually nano or vi). Scroll to the bottom of the file and add a line like this:

username ALL=(ALL:ALL) ALL

This grants the user full sudo access. Replace username with the actual login name. The format breaks down as: username, host (ALL means any host), user to run as (ALL:ALL means any user and group), and commands allowed (ALL means any command).

To save in nano, press Ctrl+O, then Enter, then Ctrl+X. To save in vi, press Escape, type :wq, then Enter. If visudo detects a syntax error, it will ask whether you want to re-edit the file or discard your changes. Choose to re-edit and fix the mistake.

Restricting a user to specific commands

You can limit a user to run only certain commands with sudo. This is useful for giving someone the ability to restart a service or manage backups without granting full administrator access.

Open visudo and add a line like:

username ALL=(ALL:ALL) /usr/bin/systemctl restart apache2

This allows the user to run only systemctl restart apache2 with sudo. They cannot use sudo for any other command. You can add multiple commands by separating them with commas:

username ALL=(ALL:ALL) /usr/bin/systemctl restart apache2, /usr/bin/systemctl status apache2

If you want to allow a user to run a command without entering their password, add NOPASSWD: before the command list:

username ALL=(ALL:ALL) NOPASSWD: /usr/bin/systemctl restart apache2

Be cautious with NOPASSWD — it means anyone with access to that user account can run that command as root without a password prompt.

Removing sudo access from a user

To remove sudo access, use the delgroup or gpasswd command if the user is in the sudo group:

sudo delgroup username sudo

On Red Hat systems, use:

sudo gpasswd -d username wheel

If you added the user directly to the sudoers file, open visudo and delete the line you added for that user. Save and exit the same way as before.

Troubleshooting common problems

If a user reports that sudo is not working, first check whether they are in the correct group. Log in as root and run groups username to see which groups the user belongs to. If sudo or wheel is not listed, they were not added successfully or the change has not taken effect yet. Ask them to log out completely and log back in — group membership changes do not take effect until the next login.

If you accidentally break the sudoers file and cannot use sudo anymore, you will need to log in as root directly to fix it. If you do not have root access, you may need to boot into single-user mode or use a live USB to repair the system. This is why visudo is so important — it prevents this situation by catching errors before they are saved.

If a user can run some sudo commands but not others, check the sudoers file to see whether their access is restricted to specific commands. Open visudo and look for their username to see what rules apply to them.

Frequently Asked Questions

What is the difference between sudo and su?

Su switches you to a different user account entirely — usually root — and you stay logged in as that user. Sudo runs a single command as a different user (usually root) and then returns you to your own account. Sudo is safer because it logs what commands were run and by whom, and you do not need to share the root password.

Can I give sudo access to a user who does not have a login account yet?

No. The user must have a system account first. Create one with sudo useradd -m username (which creates a home directory with -m), then add them to the sudo group or sudoers file. On some systems, use adduser instead, which prompts you for a password and other details.

What happens if I delete the sudo group by mistake?

If you delete the group but users are still listed in the sudoers file, they will retain sudo access. If you delete the group and want to recreate it, log in as root and run groupadd sudo, then add users back to it with usermod -aG sudo username.

Can I give sudo access to a service account or automated script?

Yes, but be very careful. Add the account to the sudoers file with NOPASSWD and restrict it to only the commands it needs. For example: backupuser ALL=(ALL:ALL) NOPASSWD: /usr/bin/rsync. If the script is compromised, an attacker gains only the privileges you explicitly granted, not full root access.