Join our Newsletter — 33% off our NHI Course

Enrollment friction

The practical difficulty a user faces when setting up a security control for the first time. In identity programmes, friction includes device compatibility, setup steps, support gaps, and user confusion. High friction lowers adoption and can leave stronger controls unused even when policy says they are required.

Expanded Definition

Enrollment friction is the practical effort required to activate a control for the first time, and it matters because even well-designed security can fail at the point of adoption. In NHI and IAM programmes, the term covers onboarding steps, device constraints, identity proofing prompts, certificate installation, app compatibility, help desk delays, and confusing recovery paths. Definitions vary across vendors, but the security meaning is consistent: if initial setup is too hard, users delay, bypass, or abandon the control. NIST guidance on digital identity and risk management treats enrolment quality as part of the overall assurance journey, not a separate usability issue, which is why NIST AI 600-1 Generative AI Profile and the broader NIST AI Risk Management Framework are useful reference points for thinking about adoption barriers and governance impacts. The most common misapplication is treating enrollment friction as a training problem, which occurs when organisations blame users instead of fixing the setup path.

Examples and Use Cases

Implementing enrolment rigorously often introduces a real tradeoff: stronger assurance and tighter governance usually require more steps, more support, or more device constraints, so organisations must weigh adoption speed against control strength.

  • Rolling out phishing-resistant authentication can fail when mobile enrolment requires unsupported operating systems, forcing users into weaker fallback methods.
  • A new AI agent control plane may require developer keys, approvals, and workspace binding before first use, and teams may postpone setup if the workflow is too complex. That pattern is visible in NHIMG research such as AI Agents: The New Attack Surface report and the OWASP Top 10 for Agentic Applications 2026.
  • Certificate-based access may be approved in policy but unused in practice if users must manually install profiles, manage trust stores, and request help from IT for every new device.
  • Secrets vault adoption often slows when first-time setup requires multiple approvals and confusing migration steps, creating a temptation to leave credentials in ad hoc storage instead.
  • Admin-controlled enrolment for privileged access can be effective, but if recovery and re-enrolment are painful, operators may seek shortcuts during urgent incidents.

Why It Matters in NHI Security

Enrollment friction is not merely a user experience issue. In NHI security, it directly shapes whether controls are actually deployed, whether secrets remain exposed, and whether privileged access paths stay within governance boundaries. NHIMG research shows the scale of this problem: in the SailPoint report AI Agents: The New Attack Surface report, 92% of respondents said governing AI agents is critical, yet only 44% had implemented policies, a gap that often reflects adoption friction as much as policy intent. When first-time setup is cumbersome, teams work around controls, reuse credentials, or leave agent permissions in an unsafe default state. That creates blind spots that later show up in incident response, audit failures, and access sprawl. The security relevance is even sharper when credentials are involved, because exposed secrets can be abused quickly, as illustrated by LLMjacking: How Attackers Hijack AI Using Compromised NHIs and the Anthropic report on AI-orchestrated cyber espionage. Organisational teams typically encounter the consequences only after users have already bypassed the control or an agent has overstepped scope, at which point enrolment friction becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-02 Enrollment friction often drives weak secret handling and bypassed onboarding controls.
OWASP Agentic AI Top 10 A-03 Agentic controls fail when initial onboarding is too complex for operators to adopt.
NIST SP 800-63 IAL2 Identity proofing and enrollment steps shape assurance and user completion rates.
NIST CSF 2.0 PR.AC-1 Access control only works if identities can be enrolled and managed reliably.
NIST Zero Trust (SP 800-207) PL-1 Zero trust depends on practical enrollment for devices, users, and workload identities.

Simplify first-time setup so NHI controls are usable without exposing secrets or creating shadow workflows.