Join our Newsletter — 33% off our NHI Course

What should security leaders do when access controls are causing unsafe workarounds?

Security leaders should treat access control design as a business process, not just a technical setting. If people cannot complete routine tasks safely, they will bypass the control. The response is to reassess critical assets, tighten ownership of access, and redesign authentication and session handling so the secure path is also the practical path.

Why Unsafe Workarounds Are a Control Design Problem, Not Just a User Discipline Problem

When access controls push staff into unsafe workarounds, the control has failed its operational test. A policy that blocks routine work but still needs to be used every day will be bypassed, shared, or delegated informally. Security leaders should treat that as evidence that the control design, entitlement model, or session flow no longer matches the real business process.

The right response is to map the exact task path people are trying to complete, then identify where the current access model adds friction without adding meaningful protection. That usually means clarifying ownership, reducing approval bottlenecks, and making authentication and session steps fit the actual workflow rather than forcing users to invent their own.

For access controls, the practical question is not whether the rule is technically correct, but whether it can be followed consistently under normal operating pressure. If the secure path is slower, less reliable, or harder to recover from than the workaround, the workaround will become the real control.

What to Redesign Before People Normalize Bypassing the Control

Start with the critical assets and actions that truly need protection, then separate them from routine tasks that do not justify the same friction. In many environments, the fix is not to weaken security everywhere, but to narrow high-friction protection to the few actions that genuinely carry material risk, while simplifying day-to-day access for the rest.

Ownership matters because unsafe workarounds often appear where no one function owns the full access journey. Security may own the policy, IT may own the tooling, and the business may own the process, but if no one owns the end-to-end outcome, users will create their own shadow process. Strong access governance depends on IAM and IGA Basics for aligning entitlement decisions, reviews, and access request flows with the work people actually do.

Redesign also needs the right authorization model. If every user is forced through the same coarse role or blanket approval, you create exceptions by design. A more precise model can reduce exceptions, and Authorisation Models Guide is useful here because it shows how to move from broad roles toward policy-driven access that better matches context, task, and ownership.

How to Keep the Secure Path Usable in Real Operations

Authentication and session handling should be designed to preserve both assurance and flow. If repeated prompts, brittle timeouts, or awkward reauthentication steps interrupt ordinary work, users will share credentials, keep sessions open, or seek unofficial bypasses. The better pattern is to tighten the high-value actions while keeping the low-risk parts of the session as smooth as possible.

That principle applies especially where privileged or sensitive actions are involved. Security leaders should ask whether a user needs standing access, or whether just-in-time approval, shorter-lived sessions, or step-up checks would deliver the same protection with less friction. Privileged Access Management Guide helps frame this trade-off around zero standing privilege, session control, and approval boundaries rather than around blanket restriction.

Leaders should also avoid solving a user-experience problem by moving risk into unmanaged channels such as shared accounts, manual file transfers, or informal approval chains. The control should be redesigned so the safe route is also the fastest reliable route for normal work, not just the most compliant route on paper.

Risk and Threat Considerations

Unsafe workarounds turn access control failures into exposure. Once users start bypassing controls to get work done, organisations often lose visibility into who accessed what, weaken accountability, and create a wider blast radius if a credential, session, or approval path is misused. The concern is not only convenience, but the creation of unreviewed access paths that can be exploited or inherited.

Failure mechanism: Friction, broken task flow, or over-broad approval rules push users toward shared accounts, informal delegation, stale sessions, or exceptions that are never revisited. Over time, the workaround becomes the operational norm and the intended control becomes decorative.

Impact: That creates privilege creep, weaker attribution, higher compromise impact, and greater chance that attackers can abuse the same unofficial access path or session behaviour that staff created to get around the control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Unsafe workarounds often arise when access is broader than the task needs.
IA-5 — Authenticator Management Workarounds frequently follow awkward authentication, session, or credential handling.
Recommendation — Reduce standing access and scope permissions to the minimum needed for each task. Tighten credential and session handling so secure access remains usable in normal work.
CIS Controls v8 CIS-6 — Access Control Management This subject is about redesigning access so users do not bypass controls.
Recommendation — Review access workflows and remove friction that drives shadow access paths.
ISO/IEC 27001:2022 A.5.15 — Access control The topic centers on whether access controls fit the business process safely.
A.8.2 — Privileged access rights Unsafe workarounds often appear around privileged or exception-heavy access.
Recommendation — Align access control rules with operational tasks and review them when users bypass them. Limit privileged access and make exception paths tightly governed and time bound.

Practitioner Guidance

What to prioritise: Identify the highest-friction business tasks first, not every access rule. Fix the controls that are driving repeated bypasses in critical workflows before expanding policy coverage elsewhere.

What to verify: Confirm that the approved path is faster, more reliable, and more recoverable than the workaround for ordinary users. If the control still requires exceptions for routine work, treat that as a design defect, not a training issue.

What good looks like: Users can complete routine work without sharing access, extending sessions indefinitely, or asking for repeated manual exceptions. The control should be least painful where frequency is highest, and most stringent where blast radius is largest.

Practitioner takeaway: When people are bypassing access controls, the signal is usually that the control model, not the user population, needs redesign.