Use this command to specify the default local user account that the user logs in to if the user does not have a local account and is authenticated by RADIUS, TACACS+, or Active Directory via LDAP.
This command does not apply to users logging into the system using a local account.
Syntax
[no] aaa authorization map default-user <username>
Parameters
noRemoves the user account set as the default user. If no default user is specified, the system uses the admin account as default. This will allow any partially or incorrectly configured user to have admin privileges.
userThe user account to be mapped as the default user.
Examples
The following example sets the default user account to monitor.
hostname (config) # aaa authorization map default-user monitor
The following example removes the specified default local user account and then sets it to admin.
hostname (config) # no aaa authorization map default-user
User role
Admin
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Malware Analysis: Before Release 6.4
Central Management System: Before Release 6.4
Email Security — Server: Before Release 6.4
File Protect: Before Release 6.4
Network Security: Before Release 6.4
Intelligent Virtual Execution - Server: Release 7.9