Debian disable su to root user
auth sufficient pam_rootok.so auth sufficient pam_succeed_if.so use_uid user = privileged auth requisite pam_succeed_if.so uid > 0 auth requisite pam_unix.so
You could do this with sudo
in an easier way:
privileged ALL=(ALL:ALL) ALL public ALL=(privileged) ALL