What breaks is the enrollment and renewal process. If credential issuance depends on face-to-face identity proofing, organizations struggle to onboard new remote workers, replace expired credentials, and maintain access continuity during disruption. The result is a gap between security policy and operational reality, where users either wait too long for access or fall back to weaker, less manageable controls.
Where the Enrollment Model Stops Scaling
Strong authentication only scales as fast as the trust step that creates the credential. When that step requires a physical meeting, a notarised process, or another in-person proofing event, the organisation has made access issuance dependent on a bottleneck that cannot keep up with remote hiring, contractor churn, or urgent continuity needs. That is why the problem is not the authentication factor itself, but the enrollment workflow that feeds it.
The break becomes visible when policy assumes one lifecycle but operations run another. Remote staff cannot wait for a branch visit, replacement credentials cannot depend on travel, and recovery teams cannot treat proofing delays as a minor inconvenience. In practice, the system starts to fail at the point where identity assurance, issuance speed, and business continuity have to coexist.
A useful way to think about this is that strong authentication is only as durable as its renewal path. If renewal is awkward, organisations accumulate expired credentials, dormant accounts, and exceptions that are difficult to govern. The result is often a drift toward temporary workarounds, which may be faster but are usually harder to audit and standardise.
Operational Friction, Not Just Security Friction
The operational cost shows up in three places: onboarding, re-issuance, and exception handling. Onboarding slows when new starters cannot prove identity quickly enough to receive usable access. Re-issuance slows when a device is replaced, a certificate expires, or a credential is lost. Exception handling grows when teams are forced to choose between delaying work and relaxing the control.
That trade-off is why the strongest designs separate proofing from every later lifecycle event. Organisations that rely on physical issuance for every renewal tend to create a fragile control surface, because one failed appointment or one unavailable office can block access for an otherwise legitimate user. For a useful reference point on lifecycle and credential handling, see Ultimate Guide to NHIs, which covers lifecycle, rotation, offboarding, and access governance patterns that also expose how brittle renewal becomes when it is too manual. The broader identity control model is reflected in ISO/IEC 27001:2022 Information Security Management and NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where access control, authentication, and auditability must stay aligned with operations.
Physical issuance also creates concentration risk. If one office, one verifier, or one local process is the only path to restore access, the organisation has built a single point of failure into the identity lifecycle. That matters even when the underlying authentication method is strong, because the control can still fail organizationally while remaining technically sound.
Risk and Threat Considerations
When strong authentication depends on in-person credential issuance, the main risk is not that the factor itself becomes weak, but that the organisation cannot maintain it consistently. Delayed proofing creates pressure to bypass policy, extend expired access, or accept temporary alternatives that are easier to phish, steal, or mismanage.
Failure mechanism: the assurance step is tied to a manual, location-dependent workflow, so enrollment and renewal fail when people are remote, time-constrained, or operating during disruption. That gap encourages exceptions, and exceptions are where stronger controls often erode.
Impact: users may lose access at critical moments, service restoration slows, and teams may adopt weaker backup methods that expand attack surface. In a real incident, the concern is often not the original factor, but the fallback process that replaces it under pressure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IAL/AAL/FAL — Identity Assurance, Authenticator Assurance, Federation Assurance | Strong authentication at scale depends on assurance, proofing, and renewal paths. |
| Recommendation — Align proofing and authenticator renewal to the required assurance level. | ||
| CIS Controls v8 | 5 — Account Management | Enrollment and renewal are account lifecycle problems that can create access gaps. |
| Recommendation — Automate account and credential lifecycle events to reduce manual issuance bottlenecks. | ||
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication and Access Control | The issue is a control/operations mismatch between access policy and real-world issuance. |
| Recommendation — Define access paths so authentication remains operationally usable during normal and disrupted conditions. | ||
| ISO/IEC 42001:2023 | A.4 — Context of the organization | If AI or automation is used in issuance, governance must reflect operational constraints and accountability. |
| Recommendation — Document operational assumptions and escalation paths for any automated identity workflow. | ||
Practitioner Guidance
What to verify: check whether enrollment, renewal, and recovery can be completed without a physical visit for every user class you intend to support. If any of those flows still depend on a single site or a narrow window, treat that as an availability and governance defect, not an administrative inconvenience.
Decision rule: if the control cannot be renewed quickly during travel, remote work, or disruption, redesign the issuance path before tightening policy further. Strong authentication fails operationally when the exception process becomes the real access path.
What good looks like: proofing is proportionate to risk, renewal is repeatable, recovery is documented, and the fallback path does not quietly become the standard path. For incident-driven perspective on how access controls fail under pressure, the Microsoft Midnight Blizzard breach and Uber Breach both show how authentication shortcuts and recovery pressure can become material security weaknesses.
Practitioner takeaway: the real scaling question is not whether the factor is strong, but whether the organisation can re-issue and renew it at the speed of the business without turning exceptions into the default.
Related resources from NHI Mgmt Group
- What happens when teams try to scale password security without a shared policy model?
- How should public sector agencies implement strong authentication for remote onboarding without slowing down new hires?
- What breaks when agencies try to onboard large remote workforces with legacy authentication processes?
- What breaks when software updates are signed or distributed without strong secrets management?