4 min read Sep 26, 2026

How to Create a Sudo User and Disable Root Login on Your VPS

Create an everyday admin user with sudo rights on Ubuntu, Debian or AlmaLinux, test it safely, then stop direct root logins over SSH to cut off the most common attack.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

Every server on the internet receives constant login attempts for the username root, because attackers know it exists everywhere. If you log in with your own username instead and turn off direct root logins, those attempts become useless.

You keep full control: your new user can run any admin command by putting sudo in front of it.

Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.

Before you start

  • Log in as root (see How to Connect to Your VPS as Root with SSH).
  • Choose a username. We use deploy in the examples; pick your own, but avoid obvious ones like admin or user.
  • Keep your root session open until the very end. It is your safety net if something goes wrong.

Step 1: Create the user

Ubuntu and Debian

adduser deploy
usermod -aG sudo deploy

adduser asks for a password (use a strong one) and some optional details you can skip with Enter. The sudo group gives admin rights.

AlmaLinux and Rocky Linux

adduser deploy
passwd deploy
usermod -aG wheel deploy

On these systems the admin group is called wheel.

Step 2: Give the user your SSH key (if root uses one)

If you already log in as root with an SSH key, copy it to the new user so the same key works:

rsync --archive --chown=deploy:deploy ~/.ssh /home/deploy

No key yet? That's fine: follow How to Set Up SSH Key Login and Change the SSH Port after this guide.

Step 3: Test the new user

Open a second terminal window on your computer (leave the root one alone) and log in as the new user:

ssh [email protected]
sudo whoami

After entering your user's password, sudo whoami must print root. If it says deploy is not in the sudoers file, go back to your root window and repeat the usermod command for your distribution, then log out and back in.

Step 4: Turn off root login over SSH

In your root session, create a small settings file:

nano /etc/ssh/sshd_config.d/00-hardening.conf

Add this line, then save with Ctrl+O, Enter, and exit with Ctrl+X:

PermitRootLogin no

Why a separate file starting with 00? On current Ubuntu, Debian and AlmaLinux, the main /etc/ssh/sshd_config reads every file in /etc/ssh/sshd_config.d/ first, in alphabetical order, and SSH uses the first value it finds for each setting. Cloud images often ship files such as 50-cloud-init.conf or 01-permitrootlogin.conf that switch passwords or root login back on. A file named 00-hardening.conf is read before them, so your settings win.

Check the file and apply it:

# check the configuration for mistakes first
sudo sshd -t

# Ubuntu / Debian
sudo systemctl reload ssh

# AlmaLinux / Rocky
sudo systemctl reload sshd

Confirm that the setting SSH actually uses is no:

sudo sshd -T | grep -i permitrootlogin

Step 5: Test before you log out

  1. In a new window, try ssh [email protected]. It should now be refused with Permission denied.
  2. Try ssh [email protected] again. It should still work.
  3. Only then close the original root window.

From now on, become root when you need to with sudo -i, or prefix single commands with sudo.

A middle ground: root with keys only

Some tools (for example certain backup scripts) must connect as root. Instead of no, you can use:

PermitRootLogin prohibit-password

This allows root only with an SSH key and blocks every password guess against root.

Good habits with sudo

  • Don't give the user password-free sudo (NOPASSWD). If someone steals your SSH key, the sudo password is one more barrier.
  • Create one user per person who needs access, rather than sharing a login, so you can remove someone later without changing everyone's password.
  • Remove a user and their home folder with sudo deluser --remove-home name (Ubuntu/Debian) or sudo userdel -r name (AlmaLinux/Rocky).

Common problems

  • Root can still log in: run sudo sshd -T | grep -i permitrootlogin. If it still says yes, another file is overriding yours; check ls /etc/ssh/sshd_config.d/ and make sure your file sorts first.
  • You locked yourself out: use the VPS console to log in and undo the change. See What to Do If Your VPS Is Unreachable or You Are Locked Out.

Need help?

If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer