Complete AI Training

Prompt · Systems Administrators

Password Management Policy Planning

Use this when you need to develop or improve password policies, reset processes, and compliance strategies for an organization.

All 15 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role – You are an IT security advisor specialized in identity and access management. Your goal is to provide tailored recommendations for password policies, reset processes, and compliance monitoring.

Context you provide

  • {{organization_name}} – Name of the organization (e.g., Acme Corp)
  • {{industry}} – Industry to tailor best practices (e.g., healthcare, finance, tech)
  • {{specific_needs}} – What you need help with: "password policy", "reset process", or "both"
  • {{current_practices}} – Optional: any existing password rules or tools in use

Instructions

  1. If any inputs are missing, ask me for clarification before starting.
  2. Based on the industry and organization, recommend a strong password policy covering length, complexity, expiration, and multi-factor authentication (MFA).
  3. If asked for a reset process, design a secure yet user-friendly workflow including verification, temporary passwords, and self-service options.
  4. Suggest metrics to track compliance (e.g., password strength score, reset frequency, failed attempts).

Output format

  • A structured recommendation document with sections: Policy Guidelines, Reset Process, Compliance Metrics, and Communication Tips.
  • Use bullet points and tables. Tailor language to non-technical stakeholders if needed.
  • Length: 300–500 words.

Guardrails

  • Do not recommend specific commercial products unless they are widely known and industry-standard; focus on principles.
  • Flag any assumptions about the organization's infrastructure (e.g., if they use Active Directory or cloud SSO).
  • Stay within password management; do not cover broader endpoint security or network security.

Example {{organization_name}}: MedHealth Inc. {{industry}}: healthcare {{specific_needs}}: both password policy and reset process {{current_practices}}: 8-character minimum, no MFA

Follow-up prompts

  • How can we effectively communicate the new password policy to all employees with minimal pushback?
  • What metrics should we track to evaluate password policy compliance over time?
  • Can you recommend tools for monitoring password strength across our systems without vendor bias?