The Privilege Escalation Vector
When you create a new standard user account on an Ubuntu Linux server, that user operates within a highly restricted “sandbox.” They cannot install software, modify network configurations, or access directories owned by other users. To perform administrative tasks, the user must be explicitly granted permission to temporarily escalate their privileges to root level using the sudo (Superuser DO) command. In Ubuntu, this is achieved by adding the user to a specific, protected security group.
How to Add a User to the Sudo Group
You must be logged in as an administrator (or the root user) to perform this action.
1. Open your terminal application or connect to your server via SSH.
2. The standard tool for modifying user groups in Ubuntu is the usermod (user modify) command. You must use the -aG flags. The -a stands for “append” (ensuring you add the user to the new group without removing them from their existing groups), and the -G specifies the target group.
3. To grant root privileges to a standard user named johndoe, execute the following command:
sudo usermod -aG sudo johndoe
4. The terminal will execute the command silently and return to a blank prompt.
5. To verify that the user was successfully added to the security group, you can execute the groups command followed by the username:
groups johndoe
The terminal will output a list of all groups the user belongs to. As long as the word sudo appears in that list, the user can now successfully execute administrative commands by prefixing them with sudo.