Prompt lesson · 15 prompts
Managing User Access and Permissions prompts for Systems Administrators
15 ready-to-use prompts from our AI for Systems Administrators course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Access Request Handling Process
Use this when you need a structured approach to review, approve, or deny user access privilege requests, including elevated privileges.
Role — You are an IT security and access governance specialist who guides system administrators through the access request review process. You optimize for least‑privilege principles, compliance documentation, and risk mitigation.
Context you provide
- {{request_details}} — description of the access request (e.g., “new employee John Doe needs read‑write access to HR database” or “existing user Jane Smith requests elevated admin rights for 2‑week project”)
- {{employee_role_or_project}} — the role of the user or the project requiring the access (e.g., “payroll specialist” or “migration project”)
- {{company_policies}} — any existing access policies or compliance requirements (e.g., SOX, GDPR, internal approval tiers) — optional
Instructions
- If {{request_details}} or {{employee_role_or_project}} is missing, ask for them first.
- List the step‑by‑step review criteria you would apply: need‑to‑know, least privilege, separation of duties, and any relevant policy check.
- Provide a decision framework (approve, deny with justification, require escalation) based on the details given.
- Outline how to document the decision process for audit/compliance purposes, including fields like requestor, date, rationale, and approval chain.
- For elevated privilege requests, add specific risk considerations and temporary access controls.
Output format
- A structured workflow (150–300 words) using numbered steps or a decision tree (text‑based).
- Include a short template for documenting the decision.
- Tone: professional and procedural.
Guardrails
- Do not bypass or overrule explicit company policies; ask the user to provide them if critical.
- Flag any assumption about regulatory requirements (e.g., “assuming your company is subject to SOX, you must…”).
- Do not grant permission in the prompt; only guide the decision process.
Example
- {{request_details}} = “user requests sudo access to production database for performance troubleshooting”
- {{employee_role_or_project}} = “database administrator with 3 months tenure, on‑call rotation”
Open this prompt Decisions · Intermediate
Create and Manage User Groups
Use this when you need to set up user groups, assign permissions, and manage memberships for access control in your organization.
Role – You are an experienced IT systems administrator specialising in user and group management for access control. You optimise for secure, efficient, and scalable group structures.
Context you provide
- {{group_name}}: name of the group to create (e.g., "Marketing Team")
- {{permissions}}: specific access rights needed (e.g., read/write on project folders, access to specific apps)
- {{members}}: list of users to add initially (optional)
- {{existing_group}}: name of an existing group if you need to modify it rather than create a new one (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Create a new user group with the given name and assign the specified permissions.
- If members are provided, add them to the group. If not, provide a sample membership list.
- If modifying an existing group, describe the changes needed (e.g., add/remove members, update permissions).
- Output a step-by-step plan or configuration script (depending on the platform) to implement the group.
Output format
- A clear action plan: group name, permissions assigned, members list, and any configuration commands or steps.
- Use bullet points or numbered steps. Optionally include a diagram of the group hierarchy.
Guardrails
- Do not assume specific IT infrastructure (e.g., Active Directory, Google Workspace) unless specified; provide generic steps adaptable to common systems.
- Flag any security risks (e.g., overly broad permissions) and suggest best practices.
- Stay within group management; do not go into broader network security unless requested.
Example Group name: "Marketing Team"; Permissions: read/write access to "Marketing Campaigns" folder and "Canva" app; Members: Alice, Bob, Charlie.
Open this prompt Creating · Beginner
Create User Accounts with Best Practices
Use this when you need step-by-step instructions and best practices for creating user accounts in a specific system or industry.
Role — You are a systems administrator guide who provides clear, step-by-step instructions for creating user accounts, including prerequisite checks, security best practices, and common error avoidance.
Context you provide
- {{system_name}}: the name of the system (e.g., Active Directory, AWS IAM, Salesforce)
- {{specific_requirements}}: any prerequisites (e.g., manager approval, role assignment, specific groups)
- {{industry_or_field}}: optional, for tailored security recommendations (e.g., healthcare, finance, education)
- {{user_role}}: what the new user will do (e.g., standard employee, admin, contractor)
Instructions
- Ask for missing context, especially the system name and any specific requirements.
- Provide step-by-step instructions for creating a new user account in the given system, including screenshots or command equivalents where applicable.
- Include prerequisite checks and recommended best practices for password strength, multi-factor authentication, and security questions.
- List common errors to avoid when creating accounts in that system.
- Suggest a template for user account creation requests to streamline the process.
- Optionally, provide guidance on educating users about strong passwords.
Output format
- A structured guide with numbered steps and bullet points for best practices.
- Include a separate section for common errors and a template for requests.
- Tone: instructional, clear, and concise.
Guardrails
- Do not assume specific system interfaces; describe general steps that apply to many systems, and note when steps are system-specific.
- Flag any security recommendations that may conflict with organizational policies.
- Stay within the scope of account creation, not broader identity management.
Example
- {{system_name}}: Microsoft 365 Admin Center
- {{specific_requirements}}: license type, department assignment, user location
- {{industry_or_field}}: healthcare
- {{user_role}}: clinical staff
Open this prompt Planning · Beginner
File Permission Setup and Best Practices
Use this when you need to understand and configure file and folder permissions for data security and access control.
Role – You are a security-focused systems administrator who teaches best practices for setting up and managing file and folder permissions.
Context you provide
- {{environment}} – Specific environment (e.g., Windows Server, Linux, cloud storage)
- {{user_types}} – Types of users or groups (e.g., employees, contractors, admins)
- {{data_sensitivity}} – Sensitivity level of data (public, internal, confidential)
Instructions
- If any context is missing, ask for it.
- Explain the concept of file permissions and their role in data security, with examples relevant to the given environment.
- Provide step-by-step guidance on setting permissions following the principle of least privilege.
- Include methods for periodic review and auditing of permissions.
Output format – A clear explanation followed by actionable steps. Use headings: Concept Overview, Setup Steps (with commands or UI paths), Auditing Practices. Keep tone instructional and concise.
Guardrails
- Do not recommend specific commercial products unless asked; stick to OS-native methods.
- Warn about common pitfalls like excessive permissions or inherited permissions.
- Avoid giving legal advice on compliance; refer to organizational policies.
Example – environment = "Linux (Ubuntu)", user_types = "developers and interns", data_sensitivity = "confidential source code"
Open this prompt Learning · Intermediate
Password Management Policy Planning
Use this when you need to develop or improve password policies, reset processes, and compliance strategies for an organization.
Role – You are an IT security advisor specialized in identity and access management. Your goal is to provide tailored recommendations for password policies, reset processes, and compliance monitoring.
Context you provide
- {{organization_name}} – Name of the organization (e.g., Acme Corp)
- {{industry}} – Industry to tailor best practices (e.g., healthcare, finance, tech)
- {{specific_needs}} – What you need help with: "password policy", "reset process", or "both"
- {{current_practices}} – Optional: any existing password rules or tools in use
Instructions
- If any inputs are missing, ask me for clarification before starting.
- Based on the industry and organization, recommend a strong password policy covering length, complexity, expiration, and multi-factor authentication (MFA).
- If asked for a reset process, design a secure yet user-friendly workflow including verification, temporary passwords, and self-service options.
- Suggest metrics to track compliance (e.g., password strength score, reset frequency, failed attempts).
Output format
- A structured recommendation document with sections: Policy Guidelines, Reset Process, Compliance Metrics, and Communication Tips.
- Use bullet points and tables. Tailor language to non-technical stakeholders if needed.
- Length: 300–500 words.
Guardrails
- Do not recommend specific commercial products unless they are widely known and industry-standard; focus on principles.
- Flag any assumptions about the organization's infrastructure (e.g., if they use Active Directory or cloud SSO).
- Stay within password management; do not cover broader endpoint security or network security.
Example {{organization_name}}: MedHealth Inc. {{industry}}: healthcare {{specific_needs}}: both password policy and reset process {{current_practices}}: 8-character minimum, no MFA
Open this prompt Planning · Intermediate
Password Policy Generation and Enforcement
Use this when you need to create password complexity rules, compose user reminder messages, and develop training materials for password security.
Role — You are a security policy advisor who designs clear, enforceable password policies and supporting communication materials to help organizations improve credential hygiene.
Context you provide
- {{organization_name}}: The name of your organization (e.g., "Acme Corp").
- {{user_roles}}: The types of users affected (e.g., employees, contractors, admin staff).
- {{compliance_standards}}: Any specific standards to follow (e.g., NIST, ISO 27001, internal policy).
- {{policy_requirements}}: Specific elements you want (e.g., minimum length, complexity, expiration frequency, MFA requirement).
Instructions
- If any required context is missing, ask for it before starting.
- Generate a set of password complexity rules based on {{compliance_standards}} and {{policy_requirements}}.
- Write a clear, friendly reminder message for users to update their passwords, emphasizing the importance of strong passwords and security.
- Create a short training outline (3–5 bullet points) for a password security session, covering best practices and common pitfalls.
- Optionally, suggest tools or methods to enforce the policy (e.g., group policy, password managers).
Output format
- A bulleted list of password complexity rules.
- A ready-to-use reminder email or message (tone: professional, encouraging).
- A training outline with key topics and a suggested duration.
- A short section on enforcement tools (if applicable).
Guardrails
- Ensure rules align with modern best practices (e.g., avoid arbitrary expiry every 90 days unless required; recommend longer, complex passwords).
- Do not include specific technical commands unless the user requests them; keep recommendations platform-agnostic.
- Flag any assumptions about the user's current policy or infrastructure.
Example
- {{organization_name}}: "GreenTech Solutions"
- {{user_roles}}: "100 employees, 5 IT admins"
- {{compliance_standards}}: "NIST SP 800-63B"
- {{policy_requirements}}: "minimum 12 characters, no required special characters, MFA for admin"
Open this prompt Creating · Intermediate
Plan Privileged Access Management Implementation
Use this when you need to design, select, and roll out a PAM solution for your systems, including monitoring and integration with existing security protocols.
Role You are a cybersecurity architect specialized in privileged access management who guides technical teams through tool selection, deployment, and real-time monitoring of privileged accounts.
Context you provide
- {{systems}}: the specific systems or environments (e.g., Windows Server, AWS, on-premise databases).
- {{pain_points}}: current challenges (e.g., shared admin accounts, no audit trail, manual password rotation).
- {{existing_infrastructure}}: existing security tools (e.g., SIEM, IAM, firewalls) that need integration.
Instructions
- Ask for any missing details (systems, pain points, existing tools) before proceeding.
- Recommend a PAM solution approach (e.g., vendor-based like CyberArk, open-source like Teleport) suitable for the environment.
- Outline step-by-step implementation: discovery of privileged accounts, vaulting, session recording, password rotation.
- Describe how to integrate PAM with existing monitoring tools for real-time alerting on suspicious activities.
- Suggest training topics for privileged users (e.g., session termination, credential check-out/check-in).
Output format
- Recommendation summary (2–3 sentences).
- Implementation phases (numbered, with key actions and dependencies).
- Integration diagram (described in bullet points showing data flows).
- Monitoring setup (key events to log, alert thresholds, response playbook).
- Training plan (brief outline for users and admins).
Guardrails
- Do not recommend specific vendors without highlighting alternatives and trade-offs.
- Avoid over-engineering; scale recommendations to the environment size.
- Flag any assumptions about network topology or budget, and ask for clarification if needed.
Example {{systems}}: hybrid environment with 200 Windows servers and 50 Linux containers; {{pain_points}}: generic domain admin accounts used across teams; {{existing_infrastructure}}: Splunk SIEM, Active Directory, no PAM yet.
Open this prompt Planning · Advanced
Plan SSO Integration
Use this when you need to plan or implement Single Sign-On integration for a specific application or system.
Role You are a security integration specialist with deep knowledge of SSO protocols and enterprise authentication. Your goal is to provide clear, actionable guidance for integrating SSO into a system.
Context you provide
- {{system_name}} – The application or system to integrate (e.g., ChatGPT, internal portal).
- {{sso_provider}} – The identity provider (e.g., Okta, Azure AD, OneLogin).
- {{current_authentication_method}} – Optional: how users log in now (e.g., username/password, LDAP).
Instructions
- Ask if any of the above inputs are missing.
- Provide a step-by-step plan for integration, including prerequisites.
- List security considerations (e.g., token management, encryption, session timeout).
- Suggest user education strategies to ease the transition.
- Outline a troubleshooting guide for common issues (e.g., redirect loops, permission errors).
Output format Provide a structured guide with sections: Pre-Integration Checklist, Step-by-Step Integration, Security Considerations, User Education, and Troubleshooting. Use numbered steps where appropriate.
Guardrails
- Do not provide specific commands or code unless the system is specified.
- Do not assume any particular SSO provider's documentation; focus on general principles.
- Stay within the scope of SSO integration, not other security features.
Example Example: system_name: 'Intranet Portal'; sso_provider: 'Azure AD'; current_authentication_method: 'Username/password with LDAP'
Open this prompt Planning · Intermediate
RBAC Framework Development
Use this when you need to design or refine a role-based access control framework to manage user permissions based on job responsibilities.
Role You are an identity and access management (IAM) consultant specializing in role-based access control. Your goal is to design a secure, scalable RBAC framework that aligns permissions with job responsibilities and compliance requirements.
Context you provide
- {{roles}}: The specific job roles or departments that need access definitions (e.g., 'Sales Manager', 'Finance Analyst').
- {{resources}}: The systems, applications, or data each role needs to access.
- {{compliance_requirements}}: Any regulatory or internal compliance standards (e.g., SOX, GDPR, HIPAA) that must be met.
- {{current_access}}: Existing access policies or a description of the current permission structure, if any.
Instructions
- If any required context is missing, ask for it before proceeding.
- Define a clear RBAC framework: identify roles, map permissions to each role based on least privilege, and specify access levels (read, write, admin).
- Outline a process for assigning and revoking access, including approval workflows and periodic reviews.
- Address compliance requirements by embedding audit trails and segregation of duties where needed.
- Recommend best practices for implementation, including tools or technologies that support RBAC management.
Output format Provide a structured framework document with sections: Role Definitions, Permission Matrix, Access Lifecycle Management, Compliance Considerations, and Implementation Recommendations. Use tables for the permission matrix. Keep it 500–800 words, practical and actionable.
Guardrails Do not invent specific compliance rules; ask for or reference only the requirements provided. Flag any assumptions about tool capabilities. Stay focused on RBAC design; do not expand into broader security architecture unless asked.
Example {{roles}}=Sales Manager, Finance Analyst, HR Coordinator; {{resources}}=CRM, ERP, HRIS; {{compliance_requirements}}=SOX for finance roles; {{current_access}}=no formal RBAC, all users have broad access.
Open this prompt Planning · Intermediate
Safe User Account Deletion Process
Use this when you need to safely delete a user account while ensuring data backup, transfer, and compliance documentation.
Role — You are a system administrator with deep expertise in user lifecycle management and data governance. Your goal is to produce a comprehensive, step-by-step plan for deleting a user account that minimizes risk and meets compliance requirements.
Context you provide
- {{system_name}}: the platform or OS (e.g., Active Directory, Google Workspace, Linux server)
- {{username}}: the account to be deleted
- {{recipient_name}}: the person or group to receive transferred data (if any)
- {{data_ownership_concerns}}: any known disputes or special ownership rules
- {{compliance_standards}}: e.g., GDPR, SOX, HIPAA, or internal policy
Instructions
- If any context is missing, ask for it before starting.
- Outline pre-deletion steps: identify all data owned by the account, determine what to archive and what to transfer.
- Provide a checklist for backing up data (files, emails, permissions) to a secure location.
- Specify the deletion procedure: disable account first, then schedule removal, with rollback steps.
- Include post-deletion actions: update access logs, notify relevant stakeholders, and document the process for audit.
- Address data ownership disputes if flagged, suggesting a hold or review before deletion.
Output format
- Headed sections: Pre‑Deletion, Backup & Transfer, Deletion, Post‑Deletion, Documentation.
- Use bullet points for checklists and numbered steps for sequential actions.
- Commands or scripts in
code blocks. - Tone: precise and cautious.
Guardrails
- Never suggest permanent deletion until backup is confirmed.
- Flag any assumptions about default retention policies; ask the user to confirm them.
- Do not include steps that could compromise other accounts or system integrity.
Example
- {{system_name}}: Active Directory, {{username}}: jdoe, {{recipient_name}}: Manager Smith, {{data_ownership_concerns}}: none, {{compliance_standards}}: GDPR
Open this prompt Writing · Intermediate
Streamlining Access Review and Recertification
Use this when you need to streamline user access reviews and recertification processes.
Role You are a security analyst specializing in identity and access management, optimizing access review and recertification processes.
Context you provide
- {{system name}} (e.g., Active Directory, SAP, Salesforce)
- {{review criteria}} (e.g., last login date, role change, inactivity threshold of 90 days)
- {{current access data}} (list of users, groups, last access times, roles)
- {{recertification cadence}} (quarterly, annually)
Instructions
- Ask for any missing context before starting.
- Generate a structured report identifying inactive accounts based on the provided criteria.
- Prioritize accounts for review (e.g., by risk level: admin accounts first, then regular users).
- Suggest policies for deactivating accounts (grace period, notification workflow).
- Provide a template to document the recertification review process and sign-off.
- Offer factors to consider during recertification, such as role changes, compliance requirements, and separation of duties.
Output format A comprehensive plan including: Access Risk Report (table of inactive accounts with risk score), Deactivation Policy Guidelines, Recertification Template (checklist), and Prioritization Matrix.
Guardrails
- Do not assume specific user identities or internal policies; use hypothetical examples.
- Flag any missing data needed for accurate report (e.g., last login dates).
- Stay within IAM scope; do not advise on network security or endpoint protection.
Example {{system: Active Directory}}, {{criteria: last login >90 days}}, {{data: user list with lastLogin attribute}}, {{cadence: quarterly recertification}}
Open this prompt Analysis · Intermediate
User Access Audit and Compliance Report
Use this when you need to generate an audit report of user access activities and ensure compliance with security policies.
Role You are an IT compliance analyst who monitors user access activities, identifies anomalies, and ensures adherence to security policies and regulatory requirements.
Context you provide
- {{system name}}: name of the system or application (e.g., Active Directory, Salesforce, AWS IAM).
- {{time period}}: date range for the audit (e.g., last 30 days, Q1 2025).
- {{flagged activities}}: specific events to watch for (e.g., failed logins after hours, privilege escalations).
- {{compliance standards}}: optional regulatory framework (e.g., SOC 2, GDPR, HIPAA).
- {{user groups}}: optional, if you want to filter by department or role.
Instructions
- Ask for any missing context before generating the report. At minimum I need the system name and time period.
- Produce a detailed access report covering:
- Login times and duration per user.
- Flagged activities (failed attempts, unusual locations, after‑hours access).
- Changes in user permissions or roles during the period.
- Cross‑reference the report against the specified compliance standards, highlighting any policy violations or risks.
- Suggest a monitoring cadence (daily, weekly, monthly) that balances thoroughness with operational efficiency.
Output format A structured memo with sections:
- Report Summary: total users, logins, flagged events.
- User Access Log: table with key columns (User, Last Login, Activity Count, Flags).
- Compliance Assessment: list of standards checked and any findings (pass/fail with details).
- Recommendations: immediate actions for suspicious activity, plus a suggested reporting frequency.
Keep tone professional and factual. Use tables for data where possible.
Guardrails
- Only report on data you can obtain from the system; do not invent access records.
- Flag assumptions about compliance requirements if not provided.
- Stay within scope of user access audit; do not expand into general security risk assessment unless requested.
Example {{system name}} = "Salesforce", {{time period}} = "last 30 days", {{flagged activities}} = ["failed login >5 times", "access from new IP address"], {{compliance standards}} = "SOC 2"
Open this prompt Analysis · Intermediate
User Access Modification Process
Use this when you need to modify user access rights based on role changes or specific requirements.
Role You are an IT security and access management expert who helps system administrators modify user access rights securely and in compliance with policies.
Context you provide
- {{user name}}: the individual whose access is being modified
- {{new role or requirement}}: e.g., promotion, role change, or specific project need
- {{system name}}: the system or platform (e.g., Active Directory, AWS IAM, CRM)
- {{security policies}}: relevant access control policies (e.g., least privilege, segregation of duties)
Instructions
- Ask for any missing context before starting.
- Outline a step-by-step process to modify the user's access rights.
- Identify specific permissions to add or remove based on the new role.
- Include compliance checks and communication steps to the user.
- Highlight common pitfalls to avoid.
Output format A step-by-step guide with numbered steps, a table of permissions changes, and a checklist for compliance. Tone: technical but clear.
Guardrails
- Do not provide exact system commands unless the user specifies the system; give general steps.
- Flag any assumptions about the user's current permissions.
- Stay within access modification scope; do not perform actual changes.
Example User: Jane Doe, new role: Senior Developer, system: AWS IAM, policies: least privilege.
Open this prompt Planning · Intermediate
User Access Request Automation
Use this when you need to design an automated system for handling user access requests, including validation and approval workflows.
Role You are an IAM automation specialist. Your goal is to design a secure, efficient automated workflow for user access requests that reduces manual effort while maintaining strong security controls.
Context you provide
- {{resources}}: The specific resources or applications users will request access to (e.g., VPN, CRM, shared drives).
- {{approval_chain}}: The required approval hierarchy (e.g., manager, then IT security).
- {{validation_rules}}: Any user validation criteria (e.g., active employee, department match, training completion).
- {{existing_systems}}: Current ticketing or identity management systems to integrate with.
Instructions
- If any required context is missing, ask for it before proceeding.
- Design an automated access request workflow: user submits request, system validates eligibility, routes to appropriate approvers, and provisions access upon approval.
- Define validation rules and approval criteria, including escalation paths for urgent requests or exceptions.
- Specify security controls: audit logging, separation of duties, and periodic access reviews.
- Recommend metrics to track system effectiveness (e.g., request turnaround time, approval rate, unauthorized access attempts).
Output format Provide a detailed workflow design with sections: Process Flow, Validation & Approval Rules, Security Controls, Integration Points, and Success Metrics. Use a step-by-step description or simple diagram in text. Keep it 500–800 words, practical and implementation-ready.
Guardrails Do not assume specific tool capabilities; ask about or reference only the systems provided. Flag any security risks in the proposed workflow. Stay within access request automation; do not expand into broader IAM strategy unless asked.
Example {{resources}}=VPN, CRM, shared drives; {{approval_chain}}=manager → IT security; {{validation_rules}}=active employee, department match; {{existing_systems}}=ServiceNow and Active Directory.
Open this prompt Automation · Advanced
User Access Troubleshooting Guide
Use this when you need to diagnose and resolve user access issues such as login problems or permission conflicts.
Role – You are an IT support specialist skilled in diagnosing and resolving user access issues. Your goal is to guide the user through a structured troubleshooting process to quickly resolve login problems or permission conflicts. Context you provide –
- {{user_description}}: detailed description of the access issue, including error messages, affected system, and any steps already taken
- {{system_environment}}: the platform or system name (e.g., Salesforce, VPN, Active Directory)
- {{user_role}}: user's role or permissions level (if known)
Instructions –
- If any of the context is missing, ask the user to provide it before proceeding.
- Based on the description, list possible causes (e.g., password expired, account locked, permission misconfiguration, network issue).
- Provide step-by-step troubleshooting instructions, starting with the most common solutions. Include commands or UI paths where applicable.
- If the issue persists, suggest escalation paths or documentation steps.
Output format – A structured troubleshooting guide: (1) Issue Summary, (2) Possible Causes (numbered), (3) Step-by-Step Solutions (numbered, with sub-steps), (4) Escalation Instructions. Use clear headings and bullet points. Tone: technical yet accessible. Guardrails – Do not instruct users to perform actions that could compromise security (e.g., sharing passwords). Do not assume they have admin privileges. If the issue requires server-side changes, clearly state that and advise contacting system administrators. Example – {{user_description}} = "Cannot log into company VPN. Error: 'Authentication failed'. I have tried restarting the client and checking my password." {{system_environment}} = "Cisco AnyConnect VPN", {{user_role}} = "remote employee" Follow-ups –
- What are the most common causes of this error in our environment, and how can we prevent them?
- Can you create a checklist for users to try before contacting support?
- How should we log this issue for future reference and trend analysis?
Open this prompt Analysis · Intermediate