How to Create Groups in Linux: groupadd Command

By 

•

Updated on

•

7 min read

Create Groups in Linux Using the groupadd Command

In Linux, groups are used to organize and administer user accounts. The primary purpose of groups is to define a set of privileges such as reading, writing, or executing permission for a given resource that can be shared among the users within the group.

This guide explains how to create new groups in Linux using the groupadd command.

groupadd Command Syntax

The general syntax for the groupadd command is as follows:

txt
groupadd [OPTIONS] GROUPNAME

Only the root or a user with sudo privileges can create new groups.

When invoked, groupadd creates a new group using the options specified on the command line plus the default values specified in the /etc/login.defs file.

Creating a Group in Linux

To create a new group, type groupadd followed by the new group name.

For example, to create a new group named mygroup you would run:

Terminal
sudo groupadd mygroup

The command adds an entry for the new group to the /etc/group and /etc/gshadow files.

Once the group is created, you can start adding users to the group .

If the group with the same name already exists, the system will print an error message like the following:

output
groupadd: group 'mygroup' already exists

To suppress the error message if the group exists and to make the command exit successfully, use the -f (--force) option:

Terminal
sudo groupadd -f mygroup

Creating a Group with Specific GID

In Linux and Unix-like operating systems, groups are identified by their name and a unique GID (a positive integer).

By default, when a new group is created, the system assigns the next available GID from the range of group IDs specified in the login.defs file.

Use the -g (--gid) option to create a group with a specific GID.

For example, to create a group named mygroup with GID of 1010 you would type:

Terminal
sudo groupadd -g 1010 mygroup

You can verify the group’s GID by listing all groups and filtering the result with grep :

Terminal
getent group | grep mygroup
output
mygroup:x:1010:

If a group with the given GID already exists, you will get the following error:

output
groupadd: GID '1010' already exists

When used with the -o (--non-unique) option, the groupadd command allows you to create a group with a non-unique GID:

Terminal
sudo groupadd -o -g 1010 mygroup

Creating a Group with Members

If you already know which users should belong to the group, create the group first:

Terminal
sudo groupadd developers

Then add each user with usermod -aG. The -a option appends the group to the user’s existing memberships, while -G specifies the supplementary group:

Terminal
sudo usermod -aG developers alice
sudo usermod -aG developers bob

Both users must already exist. To confirm the membership, query the group with getent:

Terminal
getent group developers
output
developers:x:1011:alice,bob

The last field lists alice and bob as group members. The assigned GID may be different on your system. For more ways to manage memberships, see how to add users to a group .

Creating a System Group

There is no real technical difference between the system and regular (normal) groups. Usually, system groups are used for some special system operation purposes, like creating backups or doing system maintenance.

System group GIDs are chosen from the range of system group IDs specified in the login.defs file, which is different from the range used for regular groups.

Use the -r (--system) option to create a system group. For example, to create a new system group named mysystemgroup you would run:

Terminal
sudo groupadd -r mysystemgroup

Overriding the Default /etc/login.defs Values

The -K (--key) option followed by KEY=VAL allows you to override the default values specified in the /etc/login.defs file.

The keys you will most often override are GID_MIN and GID_MAX, which set the range used for automatic GID selection, and their system group counterparts SYS_GID_MIN and SYS_GID_MAX. You can pass -K more than once to override several keys in the same command.

To create a new group with a GID in the range between 1200 and 1500, specify the min/max values as shown below:

Terminal
sudo groupadd -K GID_MIN=1200 -K GID_MAX=1500 mygroup

Using addgroup on Debian and Ubuntu

Debian, Ubuntu, and their derivatives also ship addgroup, a friendlier wrapper around groupadd that is part of the adduser package. It reads its defaults from /etc/adduser.conf and picks the GID for you:

Terminal
sudo addgroup mygroup

To create a system group, use the --system option:

Terminal
sudo addgroup --system mysystemgroup

You can also set a specific GID with --gid:

Terminal
sudo addgroup --gid 1010 mygroup

On Ubuntu 26.04 and Debian 13, addgroup prints nothing when it succeeds. Older releases print an Adding group line with the assigned GID. Either way, you can verify the result with getent group mygroup.

Both commands create the same kind of group, so you can use whichever you prefer. Scripts that need to run on any distribution should stick with groupadd, since addgroup is not available on Fedora, RHEL, and other non-Debian systems.

Setting a Group Password

Adding a password to a group has no practical use and may cause a security problem since more than one user will need to know the password.

The -p (--password) option accepts an encrypted password hash, not plain text:

Terminal
sudo groupadd -p '$6$rounds=656000$hash...' mygroup

In most setups, you should avoid group passwords and manage access by adding users to groups with usermod -aG .

Quick Reference

CommandDescription
sudo groupadd GROUPNAMECreate a new group
sudo groupadd -g GID GROUPNAMECreate a group with a specific GID
sudo usermod -aG GROUPNAME USERNAMEAdd an existing user to a group
sudo groupadd -r GROUPNAMECreate a system group
sudo groupadd -f GROUPNAMESuppress error if group already exists
sudo groupadd -o -g GID GROUPNAMEAllow non-unique GID
sudo groupadd -K GID_MIN=N -K GID_MAX=N GROUPNAMEOverride GID range
sudo addgroup GROUPNAMECreate a group on Debian and Ubuntu
getent group GROUPNAMEVerify group was created
id USERNAMEShow a user’s group memberships

Troubleshooting

“groupadd: Permission denied” or “cannot lock /etc/group”
You must run groupadd as root or with sudo. Prefix the command with sudo groupadd GROUPNAME.

“GID already exists”
The specified GID is already in use. Choose a different GID with -g, or use the -o flag to allow a non-unique GID.

“Group already exists”
A group with that name already exists in /etc/group. Use -f to suppress the error and exit successfully, or choose a different name.

Group created but user does not see it
Run id USERNAME to check group memberships. A user must log out and back in for new group memberships to take effect.

FAQ

How do I verify that a group was created successfully?
Run getent group GROUPNAME or check /etc/group directly with grep GROUPNAME /etc/group. The output shows the group name, password placeholder, GID, and members.

What is the difference between a system group and a regular group?
System groups use a separate GID range defined in /etc/login.defs and are typically used for services and system processes. Regular groups are used for user account organization. There is no functional difference in how permissions work.

How do I add a user to a group after creating it?
Use the sudo usermod -aG GROUPNAME USERNAME command. The -a flag appends the group without removing existing memberships. See how to add a user to a group for more details.

How do I find what GID was assigned to a new group?
Run getent group GROUPNAME or grep GROUPNAME /etc/group. The third field in the output is the GID. You can also use the id command to verify a user’s group memberships.

How do I delete a group in Linux?
Use the sudo groupdel GROUPNAME command. See how to delete a group in Linux for the full guide.

Conclusion

The groupadd command works the same way on Ubuntu, Debian, Fedora, and RHEL-based systems, and Debian-based distributions also offer addgroup as a shorter alternative. Once the group exists, the next step is usually to add users to the group and set group permissions on the files they share.

Linuxize Weekly Newsletter

A quick weekly roundup of new tutorials, news, and tips.

About the authors

Dejan Panovski

Dejan Panovski

Dejan Panovski is the founder of Linuxize, an RHCSA-certified Linux system administrator and DevOps engineer based in Skopje, Macedonia. Author of 1000+ Linux tutorials with 20+ years of experience turning complex Linux tasks into clear, reliable guides.

View author page