service local-user-protection

Prevents unauthorized deletion or modification of a user account.
Syntax
service local-user-protection
no service local-user-protection
Command Default

The user account can be deleted or modified without any authentication; that is, user account security is disabled.

Modes

Global configuration mode

Usage Guidelines

This command allows for the deletion of user accounts or changing the password or privilege level of the user (using the username command) only upon successful validation of the existing user password.

If the command is enabled and you try to delete or modify a user account using the username, you will be prompted for confirmation to proceed. Upon confirmation, you will be prompted to provide the existing password. The attempt to modify or delete a user account is successful only if the correct password is entered.

The no form of the command disables user account security; the deletion or modification of the user account without any authentication is allowed.

Examples

The following example permits the modification of the user account password only after providing the existing password.

device(config)# username user1 password xpassx
device(config)# service local-user-protection
device(config)# username user1 password ypasswordy
User already exists. Do you want to modify: (enter 'y' or 'n'): y
To modify or remove user, enter current password: ******

The following example prevents unauthorized modification of the user account password.

device(config)# username user1 password ypasswordy
device(config)# service local-user-protection
device(config)# username user1 password zpassz
User already exists. Do you want to modify: (enter 'y' or 'n'): y
To modify or remove user, enter current password: ****
Error: Current password doesn't match. Access denied
History
Release version Command history
08.0.40 This command was introduced.