Common warning signs include users preferring password-only login, repeated complaints about extra steps, and authentication that feels disconnected from normal device use. When the second factor becomes an annoyance, people look for ways around it or avoid it altogether. That weakens adoption and can push organisations toward a false sense of coverage rather than real protection.
Why OTP Friction Shows Up in User Behaviour First
When an OTP second factor starts to feel cumbersome, the earliest signs are behavioural rather than technical. Users begin to delay logins, abandon sessions, ask for fewer prompts, or fall back to whatever path feels fastest. That shift matters because friction is often measured by complaints, exceptions, and workarounds long before it appears in a formal security review.
In practice, the strongest signal is not that people dislike security in the abstract, but that the OTP step no longer fits the rhythm of normal work. If the factor interrupts frequent access, mobile switching, or shared-device workflows, users start treating it as overhead rather than protection.
What User Pushback Usually Looks Like
Burden shows up in a few repeatable patterns: more password-only preference where that option exists, more help desk contact about login delays, and more requests to bypass or reduce the second factor. A second signal is “workarounds by habit”, such as leaving devices signed in longer than intended or reusing sessions simply to avoid re-entry.
Another warning sign is when the second factor becomes detached from the user’s actual device behaviour. If people must interrupt their task flow, hunt for a phone, or copy a code from one place to another repeatedly, the control starts to feel like an obstacle. That is especially true when the OTP is required for low-risk, high-frequency actions rather than only for sensitive access.
The MFA Guide is useful here because it compares OTP-style factors with phishing-resistant options and explains why repeated friction often precedes bypass behaviour.
When Burden Becomes a Security Problem
Excessive OTP friction is not just a user experience issue. It can reduce adoption, increase exception handling, and encourage policies that are easier to live with but weaker in practice. Once users start seeing the second factor as optional in spirit, organisations may end up with coverage on paper and erosion in day-to-day behaviour.
The security risk is that people look for the shortest path through authentication. That can lead to the wrong kind of simplification, such as longer-lived sessions, weaker fallback methods, or reduced enforcement in the name of convenience. The control then protects less than intended because the real-world behaviour is no longer aligned with the policy.
For a broader control perspective, NIST SP 800-63 Digital Identity Guidelines helps distinguish stronger authenticators from lower-friction alternatives, while NIST SP 800-53 Rev 5 Security and Privacy Controls anchors the authentication control family that organisations use when they formalise these requirements.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Guides authenticator choice and assurance when OTP friction affects login experience. |
| Recommendation — Use stronger, less burdensome authenticators when OTP friction is driving avoidance. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Covers enforcing authentication for employee and admin access when second-factor design matters. |
| Recommendation — Align login enforcement with user risk and remove unnecessary authentication friction. | ||
Practitioner Guidance
What to verify: Look for repeated login complaints, rising password-only preference where exceptions exist, and unusually frequent requests to disable or soften the second factor. Those signals are more useful than a generic “users dislike MFA” sentiment because they show the control is failing in context, not just in opinion.
Decision rule: If the OTP step is creating routine friction for everyday access, treat that as a design problem, not a training problem. At that point, the better response is usually to reduce unnecessary prompts, improve factor fit, or move to a stronger but easier-to-use method rather than to keep forcing the same pattern.
What practitioners underestimate: The biggest loss is often behavioural drift, not immediate compromise. Once users learn that the second factor is slow, intrusive, or unreliable, they start normalising avoidance, and the control’s practical value drops even if the policy still says it is enforced.
Practitioner takeaway: An OTP factor is too burdensome when it starts changing user behaviour in favour of avoidance, because that is the point where usability pressure begins to weaken real authentication assurance.
Related resources from NHI Mgmt Group
- What are the main signs that KYC or KYB compliance is becoming too burdensome for customers?
- What are the signs that clinical trial access processes are becoming too burdensome for site teams?
- What are the signs that managing external users in an existing directory is becoming too hard to operate safely?
- What are the signs that an MFA rollout is becoming too disruptive for users and support teams?