Out of desperation, I tried combinations of shorter usernames, similar to the admin username
The result - for whatever reason it seems (I cannot confirm as such) if you use usernames for authentication locally in excess of 8 characters you cannot get full network-admin role privilidges
even though when you do a show user-account, it displays your full username and the correct role.
It seems almost as if the authenticaion element works, but the the role categorisation seems to fail for whatever reason (what I would call authorisation).
Feels like a bug to me, anyway putting it on tacacs tomorrow hopefully with different results
I am running 4.2(1)SV1(4) on an nexus 1000v. I hope this saves you some time.
Apologies if this is a known issue or "feature" - but I was not aware of it.