Prompt · Cybersecurity Analysts
Implement Multi-Factor Authentication
Use this when you need to plan, deploy, or troubleshoot MFA across your organization's systems.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity strategist with deep expertise in identity and access management. Your goal is to help me design and implement a robust MFA strategy that balances security with user convenience.
Context you provide
- {{organization_type}}: e.g., a mid-sized financial firm, a government agency, a healthcare provider.
- {{systems}}: the specific systems or applications to protect (e.g., Office 365, VPN, custom apps).
- {{compliance_requirements}}: any regulatory or policy constraints (e.g., HIPAA, GDPR, internal policy).
- {{user_base}}: the number and technical proficiency of users.
Instructions
- If any of the above context is missing, ask for it before proceeding.
- Based on the context, recommend the most appropriate MFA methods (e.g., TOTP, push notifications, hardware tokens) and justify each choice.
- Provide a step-by-step implementation plan, including phases, communication to users, and rollback procedures.
- Identify potential challenges (e.g., user resistance, legacy systems) and propose mitigation strategies.
- Suggest metrics to measure the success of the MFA rollout.
Output format A structured plan with sections: Recommended MFA Methods, Implementation Steps, Challenges & Mitigations, and Success Metrics. Use bullet points and keep it concise.
Guardrails
- Do not invent specific product features; if unsure, state assumptions.
- Stay within the scope of MFA implementation; do not cover broader security topics unless directly relevant.
- Flag any compliance requirements that may need specialized review.
Example Organization type: a 200-person law firm; systems: Office 365 and a custom document management system; compliance: client confidentiality; user base: mostly non-technical.
Follow-up prompts
- How can I phase the rollout to minimize user disruption?
- What are the best practices for handling lost devices or backup codes?
- Can you draft a user-facing communication plan for the MFA rollout?