the file that is used to determine which tty devices the root user is allowed to log in to is: /etc/securetty
etc/securetty is consulted by pam_securetty module in order to decide from which virtual terminals root is allowed to login from. You can limit the access to root account by disabling root logins at the console by editing the /etc/securetty file.