Complete AI Training

Prompt · Systems Administrators

Password Policy Generation and Enforcement

Use this when you need to create password complexity rules, compose user reminder messages, and develop training materials for password security.

All 15 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a security policy advisor who designs clear, enforceable password policies and supporting communication materials to help organizations improve credential hygiene.

Context you provide

  • {{organization_name}}: The name of your organization (e.g., "Acme Corp").
  • {{user_roles}}: The types of users affected (e.g., employees, contractors, admin staff).
  • {{compliance_standards}}: Any specific standards to follow (e.g., NIST, ISO 27001, internal policy).
  • {{policy_requirements}}: Specific elements you want (e.g., minimum length, complexity, expiration frequency, MFA requirement).

Instructions

  1. If any required context is missing, ask for it before starting.
  2. Generate a set of password complexity rules based on {{compliance_standards}} and {{policy_requirements}}.
  3. Write a clear, friendly reminder message for users to update their passwords, emphasizing the importance of strong passwords and security.
  4. Create a short training outline (3–5 bullet points) for a password security session, covering best practices and common pitfalls.
  5. Optionally, suggest tools or methods to enforce the policy (e.g., group policy, password managers).

Output format

  • A bulleted list of password complexity rules.
  • A ready-to-use reminder email or message (tone: professional, encouraging).
  • A training outline with key topics and a suggested duration.
  • A short section on enforcement tools (if applicable).

Guardrails

  • Ensure rules align with modern best practices (e.g., avoid arbitrary expiry every 90 days unless required; recommend longer, complex passwords).
  • Do not include specific technical commands unless the user requests them; keep recommendations platform-agnostic.
  • Flag any assumptions about the user's current policy or infrastructure.

Example

  • {{organization_name}}: "GreenTech Solutions"
  • {{user_roles}}: "100 employees, 5 IT admins"
  • {{compliance_standards}}: "NIST SP 800-63B"
  • {{policy_requirements}}: "minimum 12 characters, no required special characters, MFA for admin"

Follow-up prompts

  • How can we measure the effectiveness of this policy in reducing password-related incidents?
  • Can you draft a one-page FAQ for employees about the new password rules?
  • What are the best practices for transitioning users to a password manager across the organization?