Stop wondering who is hiding in your secondary groups

User & Group Management

Stop wondering who is hiding in your secondary groups

🧩 The Challenge

Trying to figure out why a user has access to a production database they shouldn’t be touching is a nightmare when you’re just looking at their primary group. You’ll spend an hour checking file permissions before realizing they’re lurking in a group they joined three years ago for a temporary task.

💡 The Fix

Use the groups command to list every single group association a user currently holds. It’s the fastest way to spot hidden privileges before you start ripping out ssh keys or resetting passwords.

groups <username>

⚙️ Why It Works

This utility pulls the list of group memberships directly from the system databases, meaning it respects whatever NSS source you’ve got configured. It’s much more reliable than trying to parse /etc/group manually, especially if you’re using LDAP or SSSD for authentication.

🚀 Pro-Tip: Pipe it into grep to check if a specific user is in the sudo or docker group without scrolling through a wall of text.

Linux Tips & Tricks | © ngelinux.com | 7/24/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted