Debian disable su to root user

auth sufficient pam_rootok.so
auth sufficient pam_succeed_if.so use_uid user = privileged
auth requisite  pam_succeed_if.so uid > 0
auth requisite  pam_unix.so

You could do this with sudo in an easier way:

privileged    ALL=(ALL:ALL) ALL
public        ALL=(privileged) ALL