The config>system>security>password>authentication-order command sets the authentication, authorization and accounting order for the system, including VPRNs.
The config>system>security>profile command is used for system local user profile configuration and is used for local user authentication and authorization, including VPRNs.
Whether AAA servers are set using the system security command or the aaa remote-servers command in the VPRN, they are used as follows:
If there are servers configured under VPRN management AAA, then only the VPRN management AAAs are used.
For example, the config>system>security>password>authentication-order lists local, TACACS+, and RADIUS, while the VPRN only has a RADIUS server configured, and under system>security both TACACS+ and RADIUS are configured. In this case, if a management packet arrives on a VPRN and the destination IP matches a local interface in the VPRN, then SR OS tries local management first, and then RADIUS as configured in the VPRN. The SR OS will not try the system>security AAA servers since there is an AAA server configured in VPRN.
If there are no AAA servers configured under VPRN management AAA, then the system AAA servers configured in system>security are used.