A network administrator is configuring AAA authorization on a Cisco IOS router to restrict which commands a TACACS+ authenticated user can execute. The administrator wants to ensure that users in the 'helpdesk' group can only run show commands, while users in the 'admin' group can run all commands. The administrator has configured the TACACS+ server with the appropriate command sets and applied the following configuration on the router:
aaa new-model
aaa authentication login default group tacacs+ local
aaa authorization exec default group tacacs+ local
aaa authorization commands 15 default group tacacs+ local
tacacs server TAC1
address ipv4 10.1.1.100
key MyKey
line vty 0 4
login authentication default
authorization exec default
authorization commands 15 default
However, when a helpdesk user logs in, they can execute all commands, including configuration commands. Which action should the administrator take to enforce the command restrictions?