useradd, usermod, userdel and groupadd exist everywhere and do only what you ask: useradd bob creates no home and no password. Debian 319 's adduser wrapper adds a home, /etc/skel, a private group and a password prompt; use it by hand, and useradd in scripts. A server needs a deploy account that owns the code and logs in only with an SSH key; service accounts get useradd -r -s /usr/sbin/nologin.
sudo useradd --create-home --shell /bin/bash --comment "Deploy account" deploy
sudo groupadd --system webdev # shared group for people who edit site files
sudo usermod -aG webdev,www-data deploy # -a APPENDS to the supplementary list
sudo passwd -l deploy # lock the password: SSH keys only
id deploy
sudo usermod -G webdev deploy # no -a: the list is REPLACED
id deploy # www-data is goneOutput
passwd: password changed. uid=1001(deploy) gid=1001(deploy) groups=1001(deploy),33(www-data),986(webdev) uid=1001(deploy) gid=1001(deploy) groups=1001(deploy),986(webdev)
Do that to the only administrator's sudo membership and the machine has no administrator; gpasswd -a user group cannot drop other groups. Membership changes apply at the next login. After userdel -r, run sudo find / -xdev -nouser: files outside the home survive, and the freed UID can pass them to the next account.