Because friction drives users toward credential sharing, repeated sign-ins and other workarounds that weaken accountability. When that happens, the organisation no longer knows whether the person using the access path is the one originally authenticated, which undermines secure access governance.
Why login friction becomes a control problem, not just a usability issue
Passwords and repeated sign-ins create friction that users try to defeat when the workflow gets in the way of ordinary work. The security problem is not the annoyance itself, it is the predictable workaround behaviour: shared accounts, sticky notes, browser save prompts, helpdesk resets, or reusing the same credentials across systems. Those choices reduce the organisation’s ability to trust the access event it thinks it saw.
That is why friction changes the security model. A login that is too hard or too frequent pushes people toward convenience patterns that weaken accountability and make access paths harder to attribute cleanly. Once that happens, the system may still have authentication, but it has less confidence in who is actually using the session or credential.
How workaround behaviour weakens accountability and governance
The key failure is not simply that credentials are exposed, it is that the access relationship stops being well governed. When users hand off passwords, share active sessions, or keep re-entering credentials in ways that encourage copying and reuse, the original identity proof becomes less meaningful. The organisation can no longer treat “the authenticated user” as the same thing as “the person currently operating the access path.”
That gap matters because accountability depends on an auditable link between person, credential, and action. If that link is blurred, investigation becomes harder, approvals become less reliable, and access reviews lose value. In practical terms, login friction can turn authentication into a ritual that people bypass rather than a control that actually constrains access.
Modern password guidance reflects this reality: controls work best when they reduce the need for users to invent their own exceptions. The most effective password policy discussions focus on Password Security and Password Manager Guide because the real issue is not memorability in isolation, but whether the process encourages safe behaviour at scale.
What changes when passwords are the main gate to access
Passwords are weakly suited to environments where people must authenticate often, switch devices, recover frequently, or collaborate across shared systems. The more often a password is asked for, the more often users are asked to trade security for speed. That trade-off increases the chance of reuse, local storage of secrets, “temporary” sharing, and overdependence on helpdesk resets, all of which make access harder to govern.
Friction also increases the blast radius of a compromise. If users respond to complexity by reusing passwords or choosing easier patterns, then one compromised credential can unlock multiple services. If they respond by sharing credentials, then a single account can represent several operators, which undermines non-repudiation and makes anomaly detection less reliable.
That is why stronger identity guidance stresses phishing-resistant and lower-friction authentication paths, including modern approaches described in NIST SP 800-63 Digital Identity Guidelines. The point is not to eliminate assurance, but to make the secure path easier than the unsafe workaround.
When login friction starts creating real security risk
Risk becomes material when the process repeatedly encourages behaviour that breaks the organisation’s expected access model. Shared credentials, repeated re-authentication for routine work, password resets that skip proper verification, and “just this once” exceptions all signal that the control is generating compensating behaviour. That is a warning sign that the access model no longer reflects actual use.
This is also where technical controls and user behaviour intersect. For example, policies that force frequent secret changes without addressing usability often increase reuse and recording of credentials, while systems that fail to support modern session handling push users toward workarounds. The safer pattern is to reduce password dependence and align authentication design with how people really work, not how policy authors wish they worked.
At the control level, access governance should support least privilege and strong authentication without forcing constant re-entry for low-risk activity. Standards such as PCI DSS v4.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls both reflect that access must be both constrained and workable if it is to remain effective.
Risk and Threat Considerations
When users are forced into repeated password entry or cumbersome login patterns, they are more likely to share credentials, store them insecurely, or accept insecure shortcuts. That creates a direct security exposure because the organisation loses confidence that the credential holder and the actual operator are the same person.
Failure mechanism: Friction drives workaround behaviour, and workaround behaviour breaks attribution, weakens session integrity, and increases the chance that a single credential or shared account will be used by multiple people.
Impact: Investigations become harder, access reviews become less trustworthy, and a compromised or shared credential can persist unnoticed long enough to enable misuse, fraud, or lateral access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while PCI DSS v4.0 and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Covers authentication assurance and phishing-resistant login design for user access. |
| Recommendation — Adopt phishing-resistant authentication and reduce unnecessary reauthentication. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Applies because login friction directly affects how organizational users authenticate. |
| IA-5 — Authenticator Management | Relevant to password handling, reuse, resets, and lifecycle pressure from login friction. | |
| Recommendation — Tune user authentication so assurance stays strong without driving unsafe workarounds. Manage authenticators to minimize reuse, sharing, and insecure recovery paths. | ||
| PCI DSS v4.0 | 7 — Restrict access by business need to know | Login friction can undermine least-privilege access by encouraging account sharing and shortcuts. |
| Recommendation — Restrict access by business need and avoid controls that invite shared credentials. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control is central because the issue changes how access is granted and trusted. |
| Recommendation — Set access controls that preserve accountability and avoid unsafe login workarounds. | ||
Practitioner Guidance
What to verify: Check whether your login journey is creating measurable exceptions, such as password sharing, repeat resets, shared inbox credentials, or users bypassing MFA prompts through unsafe habits. If those patterns appear, the problem is not user discipline alone, it is the control design.
Decision rule: If a credential is used more than once a day for routine access, ask whether the authentication flow can be redesigned to reduce prompts without reducing assurance. If the answer is no, the environment is probably making security harder than necessary.
What good looks like: Users can authenticate with minimal repetition, helpdesk resets are rare, and the organisation can still tie access events to a specific accountable identity. Convenience should remove friction from the workflow, not from the control.
Practitioner takeaway: Login friction is a security issue when it changes user behaviour enough to weaken trust in who actually used the access path, so the right fix is usually better authentication design, not stricter password policy alone.
Related resources from NHI Mgmt Group
- Why do repeated login prompts create more risk instead of more security?
- Why do noisy security scanners create programme risk instead of just inconvenience?
- How should security teams help employees create stronger passwords without making login friction worse?
- Why does repeated login friction create both security and productivity risk for employees?