Home › Linux root and sudo security

Linux root and sudo security

13 video lessons · about 85 minutes of video · practice questions on every step

This path is for Linux administrators and learners on RHEL-family systems such as RHEL, CentOS Stream, Rocky Linux or AlmaLinux who want root access handled properly. Across 13 short hands-on lessons, each a few minutes long, the root account is locked, administration moves onto sudo, and sudoers rules give each user or role only the commands it needs, with logging, environment protection and session timeouts added on top.

Afterwards you should be able to audit who holds sudo rights, build and test drop-in files in /etc/sudoers.d, and debug a policy that does not behave as expected. Before starting, have a RHEL-family virtual machine you can break safely, an account with sudo rights, and basic command-line habits: editing a file, reading output and filtering it with grep.

After this path you can

Start with step 1

The steps

  1. Step 1 · 10:22

    Lesson 1: Linux root access security

    Read the root password state with getent shadow

  2. Step 2 · 7:22

    Lesson 2: Securing the root account and configuring sudo

    Lock the root password and recognise the lock in /etc/shadow

  3. Step 3 · 6:39

    Lesson 3: Sudoers mastery: reading the sudoers file

    Validate all sudoers files with visudo -c

  4. Step 4 · 5:00

    Lesson 4: Sudo privileges: limiting a user to specific commands

    Create a drop-in rule file with visudo -f

  5. Step 5 · 8:48

    Lesson 5: Role-based access control with groups

    Create role groups and users with groupadd and useradd

  6. Step 6 · 6:39

    Lesson 6: Sudoers and RBAC: fixing permissions and testing roles

    Set sudoers.d files to root:root ownership and mode 0440

  7. Step 7 · 10:32

    Lesson 7: Advanced sudoers configuration: logging, aliases and denials

    Record sudo sessions with log_input and log_output

  8. Step 8 · 7:08

    Lesson 8: Sudoers environment security

    Why env_reset matters for every sudo rule

  9. Step 9 · 5:01

    Lesson 9: Testing sudo security with environment variables

    Plant test variables and see what sudo passes on

  10. Step 10 · 5:09

    Lesson 10: Sudo session management and timestamp timeouts

    Check and refresh cached sudo credentials with sudo -v

  11. Step 11 · 3:24

    Lesson 11: Debugging and troubleshooting sudo policies

    List another user's effective rights with sudo -U user -l

  12. Step 12 · 4:10

    Lesson 12: Cleaning up sudoers and removing test users

    Remove test accounts with userdel -r

  13. Step 13 · 4:27

    Lesson 13: Keeping sudoers configuration in a Git repository

    Four core sudoers best practices

Courses for this path

The videos are short lessons from these courses. The courses add the demonstrations, labs and the rest of the topic.

Main course

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99

Take it further

Administration of Red Hat Enterprise Linux

4.5★ · 10,209 students on Udemy

See the course on Udemy

What next

Move on to SELinux and auditd, so that what root and sudo users do is both confined and recorded.

Free lab guides by email

Step-by-step guides to building your own Active Directory and Linux lab as they come out - the first, "Build your AD lab in an evening", is being written now and goes to subscribers first - plus new lessons and the month's coupons by email - about twice a month. No spam; unsubscribe with one click.