How to Configure Sudo Access and the Sudoers File for Granular Privilege Management on Ubuntu Server
Learning how to configure sudo access and the sudoers file for granular privilege management on Ubuntu Server is one of the most important skills for any Linux administrator. Without proper privilege controls, a single compromised user account can bring down your entire server. Sudo lets you grant specific users elevated permissions without sharing the root password. You can restrict exactly what commands each user or group can run. This tutorial walks you through editing the sudoers file safely, creating user-specific rules, setting up sudo groups, and locking down access to only what each user truly needs. By the end, you’ll have a tightly controlled permission system that follows the principle of least privilege.
Prerequisites and Requirements for Sudo and Sudoers Configuration
Before you start configuring sudo access on your Ubuntu Server, make sure you have the following in place.
What you need:
- An Ubuntu Server 20.04 or 22.04 installation
- Root access or an existing sudo-enabled user account
- Basic familiarity with the Linux command line
- SSH access to your server (for remote setups)
- A text editor installed (nano is fine for beginners)
Assumed knowledge: You should know how to open a terminal, run basic Linux commands, and understand what a user account is. You don’t need advanced Linux experience.
Estimated time: 30 to 45 minutes, depending on how many custom rules you create.
It’s also a good idea to take a snapshot or backup of your server before editing system files. A misconfigured sudoers file can lock you out of administrative access. Always use visudo to edit the file. It validates syntax before saving, which prevents you from breaking your sudo configuration.
How to Configure Sudo Access and the Sudoers File Step by Step
For a related walkthrough, see: How to Configure Tls 1.3 with Strong Ciphers on Nginx for Production
Follow these steps carefully. Each one builds on the last.
Step 1: Verify that sudo is installed
On most Ubuntu Server installations, sudo comes pre-installed. Confirm this by running:
sudo --version
You should see a version number. If the command isn’t found, install sudo with:
apt install sudo -y
Step 2: Add a user to the sudo group
The easiest way to grant full sudo access is to add a user to the sudo group. Replace username with the actual account name:
usermod -aG sudo username
Verify the change with:
groups username
You should see sudo listed in the output. This user can now run any command with sudo.
Step 3: Open the sudoers file with visudo
Never edit /etc/sudoers directly with a regular text editor. Always use visudo:
sudo visudo
This opens the file in your default editor and checks for syntax errors on save. A syntax error in this file can completely lock you out of sudo access.
Step 4: Understand the sudoers file structure
The sudoers file uses this basic syntax:
username ALL=(ALL:ALL) ALL
Here’s what each part means:
username, the user the rule applies to- First
ALL, applies to all hosts (ALL:ALL), can run commands as any user and group- Last
ALL, can run all commands
Step 5: Create a granular rule for a specific user
This is where granular privilege management becomes powerful. Say you have a user called deploy who only needs to restart Nginx. Add this line:
deploy ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart nginx
The NOPASSWD flag means the user won’t be prompted for a password. You can remove it if you want password confirmation. This user can only run that one command with elevated privileges. Nothing else.
Step 6: Use sudoers drop-in files for cleaner management
Instead of editing the main sudoers file, use the /etc/sudoers.d/ directory. This keeps your custom rules separate and easier to manage.
Create a new file for your deploy user:
sudo visudo -f /etc/sudoers.d/deploy
Add your rule inside:
deploy ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart nginx
deploy ALL=(ALL) NOPASSWD: /usr/bin/systemctl reload nginx
Save and exit. Ubuntu automatically includes files from this directory. You can reference the Ubuntu Sudoers documentation for more syntax examples.
Step 7: Restrict a group instead of individual users
Managing individual users gets messy fast. Use groups instead. Create a new group called webadmins:
sudo groupadd webadmins
Add users to the group:
sudo usermod -aG webadmins username
Create a sudoers drop-in file for the group:
sudo visudo -f /etc/sudoers.d/webadmins
Add the group rule using the % prefix:
%webadmins ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart nginx, /usr/bin/systemctl reload apache2
Every member of webadmins now shares these exact permissions.
Step 8: Test your configuration
Switch to the restricted user and test their sudo access:
su - deploy
sudo systemctl restart nginx
It should work without a password prompt. Now try a command that isn’t allowed:
sudo apt update
You should see a permission denied message. That confirms your granular rules are working correctly.
Troubleshooting Sudo Access and Sudoers File Errors
Even careful administrators run into problems. Here are the most common issues and how to fix them.
Problem: “sudo: command not found”
This means sudo isn’t installed. Boot into single-user mode or use root to install it: apt install sudo -y
Problem: User still can’t run sudo after being added to the group
The user needs to log out and log back in. Group membership changes don’t apply to active sessions. Run newgrp sudo as a quick workaround without logging out.
Problem: Syntax error in sudoers file
If you edited the file directly and broke it, you’ll see an error on every sudo command. Boot into recovery mode and open a root shell. Then run:
visudo -c -f /etc/sudoers
This checks the file for errors without applying changes. Fix the issue and save again.
Problem: Drop-in file not being read
Check that the file has the correct permissions. Drop-in files must be owned by root and not world-writable:
sudo chmod 440 /etc/sudoers.d/deploy
sudo chown root:root /etc/sudoers.d/deploy
Also check that /etc/sudoers includes this line at the bottom:
@includedir /etc/sudoers.d
For deeper reading on Linux privilege management, the official sudo documentation covers every available directive in detail.
Warning: Never give a user NOPASSWD: ALL unless absolutely necessary. It effectively gives them full root access without any friction.
Conclusion: Tighten Server Security with Granular Sudo Control
You now know how to configure sudo access and the sudoers file for granular privilege management on Ubuntu Server. You’ve added users to the sudo group, created targeted permission rules, used drop-in files for clean organization, and tested everything to confirm it works. These steps put you in full control of who can do what on your server. Nobody gets more access than they need. That’s exactly how a secure Linux environment should work.
From here, you can explore setting up Ubuntu user management policies for larger teams, or look into PAM (Pluggable Authentication Modules) for even more advanced access controls. Audit your sudoers rules regularly. Remove permissions that are no longer needed. A clean, minimal privilege setup is one of the best defenses against unauthorized access on any Ubuntu Server.
