ACS v5.1
I want to stop NON-ADMIN staff(service desk) from being able to execute the enable command on a router once authenticated.
TACACS authenticates users against AD.
Shell profile set for NON-ADMIN set to Default privilege Level 1.
Command Set for NON-ADMIN set to deny enable.
User ssh to device, gets authenticated.
Is able to execute enable command and use the enable secret to gain Priv15.
What am i doing wrong?What have i missed?
Regards