Deleting Local User Accounts
If the
service local-user-protection command is enabled and you try to delete a user account, you will be prompted for
confirmation to proceed. On confirmation, you will be prompted to provide the existing
password. The attempt to delete a user account is successful only if correct password
is provided.
When an account is deleted, all active login sessions for that user are terminated.
- AAA configuration specific to local authentication is removed.
- The AAA
enable aaa consoleconfiguration is removed from the device. - The method "local" becomes unavailable in the AAA authentication-method list configuration. Refer to the "Authentication-method Lists" section in the Security Vulnerability chapter for more information on the authentication-method list.
In the following task, user accounts with various levels of authentication are deleted. All the steps are optional.
- Enter global configuration mode.
- Delete a user account with no password protection.
By default, a local user account can be deleted without any authentication.
- Delete a user account with encrypted password protection and local user protection
service. You are prompted for the current password after confirmation.
device(config)# no username user-mktg3 User already exists, Do you want to modify: (enter 'y' or 'n') y To modify or remove user, enter current password: ******
- Exit to Privileged EXEC mode.
- To verify that you have deleted the user accounts, display user account information
using the
show userscommand.