How to Configure Sudo Access and the Sudoers File for Granular Privilege Management on Ubuntu Server

Learning how to configure sudo access and the sudoers file for granular privilege management on Ubuntu Server is one of the most important skills for any Linux administrator. Without proper privilege controls, a single compromised user account can bring down your entire server. Sudo lets you grant specific users elevated permissions without sharing the root password. You can restrict exactly what commands each user or group can run. This tutorial walks you through editing the sudoers file safely, creating user-specific rules, setting up sudo groups, and locking down access to only what each user truly needs. By the end, you’ll have a tightly controlled permission system that follows the principle of least privilege.

Prerequisites and Requirements for Sudo and Sudoers Configuration

Before you start configuring sudo access on your Ubuntu Server, make sure you have the following in place.

What you need:

  • An Ubuntu Server 20.04 or 22.04 installation
  • Root access or an existing sudo-enabled user account
  • Basic familiarity with the Linux command line
  • SSH access to your server (for remote setups)
  • A text editor installed (nano is fine for beginners)

Assumed knowledge: You should know how to open a terminal, run basic Linux commands, and understand what a user account is. You don’t need advanced Linux experience.

Estimated time: 30 to 45 minutes, depending on how many custom rules you create.

It’s also a good idea to take a snapshot or backup of your server before editing system files. A misconfigured sudoers file can lock you out of administrative access. Always use visudo to edit the file. It validates syntax before saving, which prevents you from breaking your sudo configuration.

How to Configure Sudo Access and the Sudoers File Step by Step

For a related walkthrough, see: How to Configure Tls 1.3 with Strong Ciphers on Nginx for Production

Follow these steps carefully. Each one builds on the last.

Step 1: Verify that sudo is installed

On most Ubuntu Server installations, sudo comes pre-installed. Confirm this by running:

sudo --version

You should see a version number. If the command isn’t found, install sudo with:

apt install sudo -y

Step 2: Add a user to the sudo group

The easiest way to grant full sudo access is to add a user to the sudo group. Replace username with the actual account name:

usermod -aG sudo username

Verify the change with:

groups username

You should see sudo listed in the output. This user can now run any command with sudo.

Step 3: Open the sudoers file with visudo

Never edit /etc/sudoers directly with a regular text editor. Always use visudo:

sudo visudo

This opens the file in your default editor and checks for syntax errors on save. A syntax error in this file can completely lock you out of sudo access.

Step 4: Understand the sudoers file structure

The sudoers file uses this basic syntax:

username  ALL=(ALL:ALL) ALL

Here’s what each part means:

  • username , the user the rule applies to
  • First ALL , applies to all hosts
  • (ALL:ALL) , can run commands as any user and group
  • Last ALL , can run all commands

Step 5: Create a granular rule for a specific user

This is where granular privilege management becomes powerful. Say you have a user called deploy who only needs to restart Nginx. Add this line:

deploy  ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart nginx

The NOPASSWD flag means the user won’t be prompted for a password. You can remove it if you want password confirmation. This user can only run that one command with elevated privileges. Nothing else.

Step 6: Use sudoers drop-in files for cleaner management

Instead of editing the main sudoers file, use the /etc/sudoers.d/ directory. This keeps your custom rules separate and easier to manage.

Create a new file for your deploy user:

sudo visudo -f /etc/sudoers.d/deploy

Add your rule inside:

deploy  ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart nginx
deploy  ALL=(ALL) NOPASSWD: /usr/bin/systemctl reload nginx

Save and exit. Ubuntu automatically includes files from this directory. You can reference the Ubuntu Sudoers documentation for more syntax examples.

Step 7: Restrict a group instead of individual users

Managing individual users gets messy fast. Use groups instead. Create a new group called webadmins:

sudo groupadd webadmins

Add users to the group:

sudo usermod -aG webadmins username

Create a sudoers drop-in file for the group:

sudo visudo -f /etc/sudoers.d/webadmins

Add the group rule using the % prefix:

%webadmins  ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart nginx, /usr/bin/systemctl reload apache2

Every member of webadmins now shares these exact permissions.

Step 8: Test your configuration

Switch to the restricted user and test their sudo access:

su - deploy
sudo systemctl restart nginx

It should work without a password prompt. Now try a command that isn’t allowed:

sudo apt update

You should see a permission denied message. That confirms your granular rules are working correctly.

Troubleshooting Sudo Access and Sudoers File Errors

Even careful administrators run into problems. Here are the most common issues and how to fix them.

Problem: “sudo: command not found”
This means sudo isn’t installed. Boot into single-user mode or use root to install it: apt install sudo -y

Problem: User still can’t run sudo after being added to the group
The user needs to log out and log back in. Group membership changes don’t apply to active sessions. Run newgrp sudo as a quick workaround without logging out.

Problem: Syntax error in sudoers file
If you edited the file directly and broke it, you’ll see an error on every sudo command. Boot into recovery mode and open a root shell. Then run:

visudo -c -f /etc/sudoers

This checks the file for errors without applying changes. Fix the issue and save again.

Problem: Drop-in file not being read
Check that the file has the correct permissions. Drop-in files must be owned by root and not world-writable:

sudo chmod 440 /etc/sudoers.d/deploy
sudo chown root:root /etc/sudoers.d/deploy

Also check that /etc/sudoers includes this line at the bottom:

@includedir /etc/sudoers.d

For deeper reading on Linux privilege management, the official sudo documentation covers every available directive in detail.

Warning: Never give a user NOPASSWD: ALL unless absolutely necessary. It effectively gives them full root access without any friction.

Conclusion: Tighten Server Security with Granular Sudo Control

You now know how to configure sudo access and the sudoers file for granular privilege management on Ubuntu Server. You’ve added users to the sudo group, created targeted permission rules, used drop-in files for clean organization, and tested everything to confirm it works. These steps put you in full control of who can do what on your server. Nobody gets more access than they need. That’s exactly how a secure Linux environment should work.

From here, you can explore setting up Ubuntu user management policies for larger teams, or look into PAM (Pluggable Authentication Modules) for even more advanced access controls. Audit your sudoers rules regularly. Remove permissions that are no longer needed. A clean, minimal privilege setup is one of the best defenses against unauthorized access on any Ubuntu Server.

Similar Posts