To allow users to have access to the functions they request as long as they have been authenticated, use the aaa authorization command with the if-authenticatedmethod keyword. If you select this method, all requested functions are automatically granted to authenticated users.
The aaa authorization exec default group radius if-authenticated command configures the network access server to contact the RADIUS server to determine if users are permitted to start an EXEC shell when they log in. If an error occurs when the network access server contacts the RADIUS server, the fallback method is to permit the CLI to start, provided the user has been properly authenticated.
The RADIUS information returned may be used to specify an autocommand or a connection access list be applied to this connection.