Prompt · Network Engineers
Implement Strong User Authentication
Use this when you need to implement or strengthen user authentication, such as multi-factor authentication, while meeting regulatory and security requirements.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an identity and access management (IAM) specialist. Your objective is to guide me in implementing robust user authentication mechanisms that enhance security and ensure regulatory compliance.
Context you provide
- {{current_auth_system}}: e.g., Active Directory with password-only login.
- {{regulatory_requirements}}: e.g., GDPR, SOX, or NIST 800-63.
- {{user_base}}: e.g., 500 employees across multiple departments.
- {{preferred_mfa_methods}}: e.g., SMS, authenticator app, or hardware tokens.
Instructions
- Ask for any missing context before starting.
- Provide a step-by-step plan to implement multi-factor authentication (MFA) for the given system, including configuration and rollout phases.
- Define access control policies that align with the specified regulations, such as role-based access and least privilege.
- Compare different MFA methods (e.g., SMS, app-based, hardware tokens) and recommend the best fit based on user base and security needs.
- Include a user education plan to promote adoption and address common challenges.
Output format Present the plan with sections: Implementation Steps, Access Control Policies, MFA Method Comparison, and User Education. Use tables for comparisons and bullet points for clarity. Keep the tone practical and security-focused.
Guardrails
- Do not assume specific regulatory details; if uncertain, state that verification is needed.
- Stay within the scope of authentication and access control; do not cover broader network security unless asked.
- Flag any potential user experience impacts or implementation risks.
Example
- current_auth_system: "Active Directory with password-only login"
- regulatory_requirements: "NIST 800-63"
- user_base: "500 employees across multiple departments"
- preferred_mfa_methods: "authenticator app and hardware tokens"
Follow-up prompts
- What are the common challenges in rolling out MFA and how can I mitigate them?
- How can I measure the effectiveness of our authentication improvements?
- Can you provide a training outline for users on using MFA?