Modifying Local User Account Passwords or Privileges
If the service
local-user-protection command is enabled and you try to modify a user
account, you will be prompted for confirmation to proceed. On confirmation, you
will
be prompted to provide the existing password. The attempt to modify a user account
is successful only if the correct password is provided.
By default, a local user account can be modified without any authentication.
In the following task, user accounts are modified to change a password or a privilege level. You can modify both password and privilege level in the same step.
- Enter global configuration mode.
- Change the password for a user account with
local user protection service. You are prompted for the current password after
confirmation.
device(config)# username user-mktg3 create-password newxpassx User already exists, Do you want to modify: (enter 'y' or 'n') y To modify or remove user, enter current password: ******
The new password can be up to 48 characters long and must be different from the current and previous two passwords. - Change the privilege level for a user account without local user protection service.
In the example, user account user-mktg4 now has a privilege level of 4, which allows port configuration.
- Exit global configuration mode.
- (Optional) To verify that you have modified the
user accounts, display user account information using the
show userscommand in Privileged EXEC mode.