Unlike a personal laptop which typically only has one or two accounts, a Linux server is inherently a multi-user environment. As a system administrator, you must routinely audit the accounts on your server to ensure former employees have been removed, identify rogue accounts created by malicious scripts, or simply confirm the spelling of a username before granting them specific folder permissions.
Because Linux is heavily reliant on text-based configuration files rather than graphical user interfaces, there is no simple “User Management” control panel on a headless server. Instead, you must use the command line to extract this information directly from the system files.
Understanding the /etc/passwd File
In Linux, every single user account—whether it belongs to a human being, a system service, or a software application—is recorded in a single, plain-text file located at /etc/passwd.
Despite its historical name, this file does not contain any actual passwords (passwords are encrypted and hidden in a separate, highly secure file called /etc/shadow). The passwd file is completely safe to view, and any standard user can read it without requiring root or sudo privileges.
If you simply want to dump the entire contents of the file onto your screen, you can use the cat (concatenate) command:
cat /etc/passwd
While this command is technically correct, the output is a chaotic, unreadable mess of colons and system paths that looks like this:
root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin johndoe:x:1000:1000:John Doe,,,:/home/johndoe:/bin/bash
Method 1: The Clean List (Using the ‘cut’ Command)
If you only want to see a clean, alphabetical list of the usernames without all the extra system data cluttering your screen, you can pipe the output of the file through the cut command.
Type the following command into your terminal and press Enter:
cut -d: -f1 /etc/passwd
How this command works:
cut: Instructs the terminal to extract specific sections of text from the file.-d:: Tells the command that the “delimiter” (the character separating the data) is a colon (:).-f1: Tells the command to only print “Field 1” (the text located before the very first colon), which happens to be the username.
This will output a perfectly clean list of names.
Method 2: Identifying Real Humans vs. System Accounts
When you run the cut command above, you will likely see dozens of bizarre usernames you did not create, such as syslog, www-data, or systemd-timesync. These are system accounts automatically generated by Linux to run background services securely. You should never delete them.
If you only want to list actual human beings who have standard login accounts, you must filter the list based on their User ID (UID) numbers. In modern Linux distributions, human accounts are assigned a UID of 1000 or higher.
To filter the list, you can use the powerful awk command:
awk -F: '$3 >= 1000 {print $1}' /etc/passwd
How this command works:
-F:: Sets the field separator to a colon.$3 >= 1000: Instructs the command to only look at lines where Field 3 (the UID number) is greater than or equal to 1000.{print $1}: Instructs the command to only print the username (Field 1) of those specific lines.
This command strips away the noise and provides a concise list of the actual people who have access to your server.
Method 3: Using the ‘getent’ Command
While the /etc/passwd file is the standard method for standalone servers, it is not flawless. If your Linux server is connected to a corporate network using a centralized directory service (like LDAP or Active Directory), the network users will not be listed in the local passwd file.
To view a comprehensive list of all users, including both local accounts and network accounts, use the getent (get entries) command:
getent passwd
This command queries all configured user databases on the system simultaneously. You can then pair it with the cut command from Method 1 to clean up the output:
getent passwd | cut -d: -f1
By mastering these commands, you can instantly audit the user base of any Linux system you manage.