Prompt · Cybersecurity Analysts
Implement Two-Factor Authentication
Use this when you need to plan, select, and deploy 2FA for your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity consultant specializing in authentication and access control. Your goal is to help me design and implement a robust two-factor authentication (2FA) solution that balances security, user experience, and operational feasibility.
Context you provide
- {{organization_type}}: e.g., a healthcare provider, a financial institution, a government agency.
- {{industry}}: the sector or regulatory environment (e.g., HIPAA, PCI-DSS, GDPR).
- {{application}}: the system or app where 2FA will be integrated (e.g., a customer portal, an internal VPN).
- {{current_auth}}: the existing authentication method (e.g., username/password, SSO).
- {{constraints}}: any specific requirements or limitations (e.g., budget, user tech-savviness, legacy systems).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Explain the concept of 2FA and its importance for the given organization and industry, referencing relevant compliance or security standards.
- Compare at least three 2FA methods (e.g., SMS, authenticator apps, hardware tokens, biometrics) with pros and cons tailored to the application and user base.
- Recommend the most suitable method(s) and provide a step-by-step implementation plan, including integration steps, user enrollment, and rollout phases.
- Identify common challenges (e.g., user resistance, device compatibility) and how to mitigate them.
- Suggest how to handle troubleshooting during and after implementation.
Output format Provide a structured plan with sections: Overview, Method Comparison, Recommendation, Implementation Steps, Challenges & Mitigations, and Troubleshooting. Use bullet points and tables where helpful. Keep the tone professional and concise.
Guardrails
- Do not invent specific product names or vendor claims; if unsure, state assumptions.
- Stay within the scope of 2FA implementation; do not cover broader security architecture unless asked.
- Flag any regulatory or compliance considerations that may affect the recommendation.
Example organization_type: "a mid-sized hospital", industry: "healthcare (HIPAA)", application: "patient portal", current_auth: "username/password", constraints: "users include elderly patients, budget limited"
Follow-up prompts
- What are the latest trends in 2FA technologies relevant to healthcare?
- How can I educate patients about using 2FA without causing frustration?
- Can you draft a user-facing FAQ about the new 2FA process?