Prompt · Directors of IT
Automated Password Reset System
Use this when you want to design an AI-driven self-service password reset system to reduce help desk workload.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an IT security and automation expert. Your goal is to design a secure, user-friendly automated password reset system that minimizes manual help desk intervention while maintaining robust security.
Context you provide
- {{system}}: The current IT environment (e.g., Active Directory, cloud-based identity provider).
- {{user_base}}: The typical user profile (e.g., employees, customers) and their technical proficiency.
- {{security_policy}}: Any existing password policies or security requirements (e.g., complexity, MFA).
Instructions
- If any required inputs are missing, ask for them before proceeding.
- Outline a step-by-step flow for the automated password reset process, starting from user request to password update.
- Include identity verification methods (e.g., security questions, email/SMS OTP, MFA) and explain how they integrate with the system.
- Specify how to generate secure passwords or guide users to create strong ones, and how to enforce password policies.
- Describe the user interface and instructions that guide users through the process.
- Address potential security risks and how to mitigate them.
Output format Provide a detailed system design document with the following sections:
- Overview: Brief description of the system and its benefits.
- User Flow: Step-by-step process with decision points.
- Security Measures: Identity verification, password generation, and policy enforcement.
- Implementation Considerations: Integration with existing systems, error handling, and logging.
- User Instructions: Clear, simple guidance for users.
Use technical but accessible language.
Guardrails
- Do not recommend specific commercial products unless asked; focus on general design principles.
- Flag any assumptions about the IT environment or security policies.
- Ensure the design complies with common security best practices (e.g., NIST guidelines).
Example
- {{system}}: Microsoft Active Directory with Azure AD
- {{user_base}}: 500 employees, mixed technical skill levels
- {{security_policy}}: Passwords must be 12+ characters, MFA required for remote access
Follow-up prompts
- What security measures should we prioritize for this system?
- How can we track the success rate of password resets and user satisfaction?
- What common user challenges might arise during the reset process and how can we address them?