Radius authenticates all log users. When Radius server is not reachable, confgured 3-level authority local users has only one-level authority.
authentication-mode radius local
Change configuration and authority is not configured. The system authorize users with Local configured authority.
When log users do not contain domain name, the system has authentication and authority with default domain. Radius server is unreachable, authenticate users with Local. After local authentication succeeds, (Configured authority is if-authenticed and it is invalid for Local) so the system returns successful authentication users as VTY default authority (1 level) and it is not configured 3-level authority. Under authentication mode, use local to authorize or authority does not match (under default it is Local), the system will authorize users with Local configured authority.
authorization-mode if-authenticated local
Understand the meaning of command line.