Deleting Local User Accounts

You must be logged in with Super User access to delete user accounts. Some user accounts require authentication before deletion.

If the service local-user-protection command is enabled and you try to delete a user account, you will be prompted for confirmation to proceed. On confirmation, you will be prompted to provide the existing password. The attempt to delete a user account is successful only if the correct password is provided.

When an account is deleted, all active login sessions for that user are terminated.

Note: You will not be able to remove the last user account if the authentication method for login or web-server is "local." Deletion of the last available local user is allowed only if login and web-server authentication methods are tacacs+ or radius.
Note: If the last user is removed from the device, the following configuration changes occur:
  • AAA configuration specific to local authentication is removed.
  • Unless at least one local user is present, the method "local" is unavailable in the AAA authentication-method list configuration. Refer to Authentication-Method Lists for more information on the authentication-method list.

In the following task, user accounts with various levels of authentication are deleted. All the steps are optional.

  1. Enter global configuration mode.
    device# configure terminal
  2. Delete a user account with no password protection.
    device(config)# no username user-mktg4
    By default, a local user account can be deleted without any authentication.
  3. Delete a user account with encrypted password protection and local user protection service. You are prompted for the current password after confirmation.
    device(config)# no username user-mktg3
    User already exists, Do you want to modify: (enter 'y' or 'n') y
    To modify or remove user, enter current password: ******  
    Note: The service user-local-protection command enforces verification for any changes to the user account.
  4. Exit to Privileged EXEC mode.
    device(config)# exit
  5. To verify that you have deleted the user accounts, display user account information using the show users command.
    device# show users