Enable Privileged Mode Password

Configure a password that will be required for transitioning from User EXEC mode to Privileged EXEC mode after logging in to the device through the console or SSH.
Configure the following steps to enable a password for the Privileged EXEC mode:
  1. Enter global configuration mode.
    device# configure terminal
  2. Enable the privileged mode password using the enable privilege-mode password command.
    device(config)# enable privilege-mode password Testing@123
    Syntax: enable privilege-mode password password

The following example configures the password for the Privileged EXEC mode which requires additional authentication after logging in to the device through the console or SSH. Although optional, enabling password masking before configuring the password for privilege mode provides optimum security.

device# configure terminal
device(config)# enable user password-masking
Password masking is enabled
device(config)# enable privilege-mode password 
Password:

If you do not press Enter after password, the following error mesaage is dispalyed:

device(config)# enable privilege-mode password test
Error - password masking enabled: <cr> required before entering password.
After exiting global configuration mode, you would normally be placed in Privileged EXEC mode. From now on, when you enter the enable command to access Privileged EXEC mode, you will be prompted to enter the Privileged EXEC mode password (which is different from all user-specific passwords).
device(config)# exit
device(config)#
SYSLOG: <14>1 2025-04-15T11:14:39+05:30 ICX7550 ICX7550 - General [meta sequenceId=26] 
BOM Security: running-config was potentially changed by cli from CONSOLE
 
SYSLOG: <14>1 2025-04-15T11:14:40+05:30 ICX7550 ICX7550 - General [meta sequenceId=27] 
BOM Security: console logout by cli from PRIVILEGED EXEC mode
ICX7550>enable
Password:
Privilege mode authentication successful.
 
SYSLOG: <14>1 2025-04-15T11:14:49+05:30 ICX7550 ICX7550 - General [meta sequenceId=29] 
BOM Security: console login by cli to PRIVILEGED EXEC mode

In global configuration mode, you can use the show running-config command, filtered to include all configuration entries containing the word "enable" (as per the previous example, the output will display password-masking and privilege-mode password as enabled).

device(config)# show running-config | include enable
fips enable common-criteria
enable user disable-on-login-failure 7 login-recovery-time in-secs 30
enable privilege-mode password 1 
$6$b5e6c667$wu8qq1F9jZdvjelDwvH0Afi6wQaoIfb3ewLzuO7CXmwaF6Oor57BvutO02vjkn
enable user password-masking
logging enable rfc5424

Note: When aaa authentication enable default command is used to configure the default authentication method list, or when aaa authentication login privilege-mode command is set up on the device to enter the Privileged EXEC mode after a successful login through SSH, these methods will take priority over the enable privilege-mode password command.