Home › Linux root and sudo security › Step 12

Lesson 12: Cleaning up sudoers and removing test users

Step 12 of 13 in Linux root and sudo security · video 4:10

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Lab rules and test accounts left on a server become someone else's security problem, so this lesson removes them. The test users are deleted with userdel -r and id quickuser confirms they are gone. The test groups are removed with groupdel, and here the lesson makes a useful point: with errors sent to /dev/null the command seemed to work, yet getent group webadmins showed the group was still there. Running it again without the redirection revealed the reason: the group was still the primary group of a forgotten user, webuser2, who had to be deleted first. The sudoers drop-in files are not simply deleted but moved into an archive directory created with mkdir -p, so they stay available for reference, and sudo visudo -c confirms that the remaining configuration still parses cleanly after the clean-up.

Check yourself

Answer in your head first, then open each question to see the answer.

1. sudo groupdel webadmins 2>/dev/null prints nothing, but getent group webadmins still lists the group. What went wrong?

groupdel failed and the redirection hid its error message. Running it again without 2>/dev/null shows the reason, and checking the result afterwards is what exposed the failure in the first place.

2. groupdel says it cannot remove the primary group of user webuser2. How do you get the group removed?

Every user needs a primary group, so groupdel will not leave webuser2 without one. Delete that user first with sudo userdel -r webuser2 (or give them another primary group), then run groupdel again.

3. How does the lesson keep old sudoers drop-in files for reference without leaving them active?

It creates /etc/sudoers.d/archive with sudo mkdir -p and moves the files into it with sudo mv. sudo reads only the files directly inside /etc/sudoers.d, not subdirectories, so the archived rules no longer apply.

4. Which command confirms, after the clean-up, that the remaining sudoers configuration is still valid?

sudo visudo -c, which parses /etc/sudoers and every included file and reports either that they parsed OK or the errors found. It is the final check after any sudoers change, removals included.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 11: Debugging and troubleshooting sudo policiesNext: Lesson 13: Keeping sudoers configuration in a Git repository →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.