Enable Privileged Mode Password

Configure a password that will be required for transitioning from User EXEC mode to Privileged EXEC mode after logging in to the device through the console or SSH.
Configure the following steps to enable a password for the Privileged EXEC mode:
  1. Enter global configuration mode.
    device# configure terminal
  2. Enable the privileged mode password using the enable privilege-mode password command.
    device(config)# enable privilege-mode password Testing@123

The following example configures the password for the Privileged EXEC mode which requires additional authentication after logging in to the device through the console or SSH. Although optional, enabling password masking before configuring the password for privilege mode provides optimum security.

device(config)# enable user password-masking
Password masking is enabled
device(config)# enable privilege-mode password 
Password:

If you do not press Enter after password, the following error mesaage is dispalyed:

device(config)# enable privilege-mode password test
Error - password masking enabled: <cr> required before entering password.

After exiting global configuration mode, you would normally be placed in Privileged EXEC mode; however, because the privileged-mode password is enabled, for security purposes the system places you in User EXEC mode. From now on, when you enter the enable command to access Privileged EXEC mode, you will be prompted to enter the Privileged EXEC mode password (which is different from all user-specific passwords). If password-masking was also enabled, the password will be masked on the CLI.
device(config)# exit
device#
SYSLOG: <14>1 2025-04-15T11:14:39+05:30 ICX7650-48F Router ICX7650_Router - General [meta sequenceId=26] 
BOM Security: running-config was potentially changed by cli from CONSOLE
 
SYSLOG: <14>1 2025-04-15T11:14:40+05:30 ICX7650-48F Router ICX7650_Router - General [meta sequenceId=27] 
BOM Security: console logout by cli from PRIVILEGED EXEC mode
ICX7650-48F Router>enable
Password:
Privilege mode authentication successful.
 
SYSLOG: <14>1 2025-04-15T11:14:49+05:30 ICX7650-48F Router ICX7650_Router - General [meta sequenceId=29] 
BOM Security: console login by cli to PRIVILEGED EXEC mode

In global configuration mode, you can use the show running-config command, filtered to include all configuration entries containing the word "enable" (as per the previous example, the output will display password-masking and privilege-mode password as enabled).
device(config)# show running-config | include enable
fips enable common-criteria
enable user disable-on-login-failure 7 login-recovery-time in-secs 30
enable privilege-mode password 1 
$6$b5e6c667$wu8qq1F9jZdvjelDwvH0Afi6wQaoIfb3ewLzuO7CXmwaF6Oor57BvutO02vjkn
enable user password-masking
logging enable rfc5424
Note: When aaa authentication enable default command is used to configure the default authentication method list, or when aaa authentication login privilege-mode command is set up on the device to enter the privileged EXEC mode after a successful login through SSH, these methods will take priority over the enable privilege-mode password command .