The Security Revocation Vector
If an employee in your organization transfers from the accounting department to the marketing department, their Linux system privileges must be immediately updated to reflect their new role. If they remain a member of the “accounting” user group, they will retain unauthorized read and write access to sensitive financial databases. You must surgically extract their user profile from the specific permission group without deleting their actual account from the server.
How to Remove a User from a Group
You must utilize the gpasswd utility, which was specifically engineered to administer the hidden `/etc/group` file and modify group memberships.
1. Open your terminal application or connect to your server via SSH.
2. Because modifying group membership alters the security posture of the operating system, you must execute the command with superuser privileges.
3. The syntax requires the utility name, the deletion flag (`-d`), the name of the user, and finally, the name of the group. Type the following command carefully, replacing `johndoe` and `accounting` with your actual targets:
sudo gpasswd -d johndoe accounting
4. Press Enter.
5. The system will prompt you for your administrative password. Type it blindly and press Enter.
6. The Confirmation: If the syntax was correct, the terminal will explicitly confirm the action by printing: `Removing user johndoe from group accounting`.
7. Crucial Final Step: The permission revocation is immediate at the kernel level, but it will not affect any active terminal sessions. If `johndoe` is currently logged into the server via SSH while you execute this command, he will retain his accounting privileges until he explicitly logs out and logs back in. You must force the user to terminate their session to enforce the new security posture.