Modifying Local User Account Passwords or Privileges
If the
service local-user-protection command is enabled and you try to modify a user account, you will be prompted for
confirmation to proceed. On confirmation, you will be prompted to provide the existing
password. The attempt to modify a user account is successful only if correct password
is provided.
By default, a local user account can be modified without any authentication.
In the following task, user accounts are modified to change a password or a privilege level. You can modify both password and privilege level in the same step.
- Enter global configuration mode.
- Change the password for a user account with local user protection service. You are
prompted for the current password after confirmation.
device(config)# username user-mktg3 password newxpassx User already exists, Do you want to modify: (enter 'y' or 'n') y To modify or remove user, enter current password: ******
The new password can be up to 48 characters long and must be different from the current and previous two passwords. - Change the privilege level for a user account without local user protection service.
In the example, user account user-mktg4 now has a privilege level of 4 that allows port configuration.
- Exit global configuration mode.
- To verify that you have modified
the user accounts, display user account information using the
show userscommand in Privileged EXEC mode.