sudo gpasswd -d user sudo Removing the user from group sudo gpasswd: the user is not a member of 'sudo' After that, I checked . sudo -l -U user User may run the following commands on the server: (ALL) NOPASSWD: ALL User is still able to run sudo su and get root access. EDIT 02: @Panki, The snippet

