Creating and Managing Accounts

useradd, usermod, userdel and groupadd exist everywhere and do only what you ask: useradd bob creates no home and no password. Debian 319 's adduser wrapper adds a home, /etc/skel, a private group and a password prompt; use it by hand, and useradd in scripts. A server needs a deploy account that owns the code and logs in only with an SSH key; service accounts get useradd -r -s /usr/sbin/nologin.

Creating a deploy account, and how usermod -G loses a groupShell
sudo useradd --create-home --shell /bin/bash --comment "Deploy account" deploy
sudo groupadd --system webdev               # shared group for people who edit site files
sudo usermod -aG webdev,www-data deploy     # -a APPENDS to the supplementary list
sudo passwd -l deploy                       # lock the password: SSH keys only
id deploy
sudo usermod -G webdev deploy               # no -a: the list is REPLACED
id deploy                                   # www-data is gone
Output
passwd: password changed.
uid=1001(deploy) gid=1001(deploy) groups=1001(deploy),33(www-data),986(webdev)
uid=1001(deploy) gid=1001(deploy) groups=1001(deploy),986(webdev)

Do that to the only administrator's sudo membership and the machine has no administrator; gpasswd -a user group cannot drop other groups. Membership changes apply at the next login. After userdel -r, run sudo find / -xdev -nouser: files outside the home survive, and the freed UID can pass them to the next account.