/sbin/useradd,/usr/sbin/userdel
###user group sa allow to run commands anywhere
yuw ALL=/usr/sbin*,.../sbin*
sa ALL= /usr/sbin*,/sbin*,!.../sbin/fdisk ,/usr/sbin*,/sbin*
[sa@linux ~]$ sudo -l
User sa may run the following commands on this...host:
(root) /usr/bin*, (root) /sbin*, (root) !.../sbin/fdisk ,/usr/sbin*,/sbin*命令执行的匹配规则是从后到前的,所以后面执行sudo fdisk不会提示权限不足的现像