A rule created with the no-operation command does not enforce any authorization rules. Instead, you can use the no-operation instance as a placeholder for a valid command that is added later, as shown in the following example.
device# configure terminal
device(config)# rule 75 action reject operation read-write role NetworkAdmin command no-operation
device(config)# rule 75 role NetworkAdmin command firmware