Your practical dashboard
Protect accounts. Keep access under control.
Use passwords and MFA safely, recover accounts and revoke access on time – with templates and practice cases for your team.
Account and access templates
Three editable pages for employees, business owners and IT. Adapt them together to your systems and internal procedures.
- Password and MFA rules for your team
- Account recovery checklist
- Access for joiners, movers and leavers
How to use the templates
Add owners, approvals and review dates. Record account or case references only, never passwords, tokens or recovery codes. The PDF is a print template without digital form fields.
Recover an account
Locked out or suspect an account takeover? Contact the responsible IT team through a known route and follow the agreed process.
Identify the situation
Lost device, broken factor or suspicious sign-in? If compromise is suspected, use the internal incident route immediately; changing the password alone may not be enough.
Use a known contact
Contact IT through the recorded number or known portal. Do not seek help through unverified search ads, unfamiliar callback numbers or unexpected links.
Let IT verify identity
Follow the agreed identity-checking procedure with IT. Urgency does not replace verification. Do not disclose MFA codes to callers.
Use an approved fallback
Use a backup factor or secure recovery procedure as authorised. Have lost factors revoked and new factors registered under controlled conditions.
Review other access if compromise is suspected
IT checks active sessions, tokens, application grants, recovery details and mailbox rules, among other relevant items. Block or revoke affected access as appropriate.
Record completion
Test contact routes and sign-in, update the fallback and document actions in the internal case. Do not copy secrets into the record.
This checklist does not recover an account or authorise taking over someone else’s account.
Three practice cases
Open a case, decide as a team and compare the next step. All situations are fictional.
MFA prompt without signing in
Your phone asks you to approve a sign-in that you did not start.
Next step: Reject it, do not let repeated prompts pressure you and contact IT through a known route.
New phone and no second factor
After changing phones, you can no longer access your work account.
Next step: Use the agreed recovery route. IT verifies your identity and registers a replacement factor under controlled conditions; do not bypass MFA yourself.
A colleague leaves the company
Their email account is disabled. Is that enough?
Next step: Also review other services, sessions, tokens, sharing permissions and shared secrets. Transfer data and work under the agreed rules; do not simply give the personal account to a replacement.
No inputs or score. The cases support learning and do not assess the actual security of your accounts.
Relevant awareness training
The core mission “The New Customer” covers topics including MFA prompts, phishing and cloud sharing, with a knowledge test and participation record.
Templates, checklist and practice cases can be used without booking training.
Sources & usage notes
Paragamix GmbH · 12.09.2026 · Version 1.0
Organisational worksheets to adapt to your systems with IT before use. Not a complete access audit or confirmation of compliance.