Use RADIUS CLI profiling to grant or deny CLI command access to users being authenticated by way of the RADIUS server. You can add a set of CLI commands to the configuration file on the radius server, and you can specify the command-access mode for these commands. The default is false.
enable
configure terminal
radius cli-profile
Switch:1> enable Switch:1# configure terminal Switch:1(config)# radius cli-profile