TL;DR: A survey of 252 U.S. security and IT executives found that 86% plan to implement passwordless authentication within 12 months or already have, but 70% are overwhelmed by authentication complexity and 42% cite lack of visibility across practices, according to Axiad. Passwordless only reduces risk when identity architecture, governance, and user experience are aligned.
At a glance
What this is: This Axiad survey says passwordless adoption is advancing, but authentication complexity, fragmented practices and limited visibility are still blocking execution.
Why it matters: For IAM teams, the message is that passwordless succeeds only when authentication architecture, policy consistency and user experience are governed as one programme.
By the numbers:
- The survey covered 252 U.S. security and IT executives at organisations with 2,500 or more employees.
- 86% said they plan to implement a passwordless strategy in the next 12 months, or already have done so.
- 70% said they are overwhelmed by the complexity of their authentication systems.
- 42% said their organisation's biggest authentication challenges involve a lack of visibility across all authentication practices.
Context
Authentication complexity is the accumulation of overlapping login methods, fragmented controls, and inconsistent policy enforcement across systems. In this article, Axiad frames that complexity as the main reason passwordless adoption is harder to execute than it looks on paper.
The identity governance issue is not whether passwordless is desirable, but whether the surrounding authentication estate can be rationalised enough to support it. When visibility is poor and controls are scattered, teams struggle to remove friction without weakening security.
That is why passwordless should be treated as an operating model change, not a single control change. The survey suggests many organisations want the outcome before they have built the architecture and governance needed to sustain it.
Key questions
Q: What breaks when users rely on mixed authentication methods during a passwordless transition?
A: Mixed authentication can create uneven security, inconsistent user experience, and support complexity if different groups use different sign-in paths without clear policy. The main failure is governance drift: admins may believe passwordless is broadly enabled, while users still fall back to weaker methods. That gap weakens assurance and makes rollout outcomes harder to measure.
Q: Why does poor visibility across authentication practices increase security risk?
A: Poor visibility prevents teams from seeing where authentication methods are actually used, which makes policy drift invisible and exceptions hard to retire. If security teams cannot trace the full authentication path, they cannot prove that passwordless is replacing weaker controls rather than sitting beside them.
Q: How should security teams reduce passwordless friction without weakening control?
A: Security teams should simplify enrolment, recovery, and device replacement so the approved path is the easiest path. Passwordless fails when users must navigate too many platforms or steps, because they either contact IT or work around policy. A single governed portal, clear device binding, and fast recovery procedures reduce both support load and bypass behaviour.
Q: How should IAM teams sequence a passwordless rollout in complex environments?
A: Start by rationalising authentication paths, then standardise policy and recovery, and only then expand rollout across applications and user groups. A passwordless programme that begins with deployment often inherits the very complexity it was meant to remove. Sequencing matters because governance has to catch up with architecture.
Technical breakdown
Why fragmented authentication slows passwordless rollouts
Passwordless adoption usually fails in the seams between systems, not in the authenticator itself. Enterprises often run multiple identity providers, legacy MFA paths, device-bound credentials and application-specific exceptions at the same time. That creates inconsistent policy enforcement, hard-to-measure user journeys and a long tail of fallback methods that keep passwords alive. The technical problem is not simply migration, but coexistence: new methods must work across old applications, service dependencies and exception handling. Without architecture rationalisation, passwordless becomes another layer rather than a replacement.
Practical implication: Map every login path and eliminate overlapping authentication flows before you set a passwordless target state.
Authentication visibility and policy drift
Visibility matters because authentication is not one control, but a collection of controls that behave differently across users, applications and risk levels. When teams cannot see which methods are used where, they cannot tell whether policy exceptions are temporary, accidental or permanent. That makes governance weak and undermines assurance to the business. Poor visibility also hides bypass routes, such as alternate recovery methods or local application credentials, that preserve risk even after a passwordless rollout. In practice, fragmented reporting is a control failure, not just an inconvenience.
Practical implication: Inventory authentication methods by application and risk tier so policy drift and hidden fallback paths are visible.
Reducing friction without reopening attack paths
Passwordless programmes have to balance usability and assurance at the same time. If users encounter too much friction, they route around controls, reuse legacy paths or pressure administrators to create exceptions. If teams relax controls too much, they erode the very risk reduction passwordless is meant to deliver. The right design principle is to remove repetitive steps while preserving strong proof at enrolment, recovery and step-up points. That means treating user experience as part of the security design, not as a post-deployment tuning exercise.
Practical implication: Design enrolment, recovery and step-up flows together so convenience does not become a bypass channel.
NHI Mgmt Group analysis
Authentication complexity is the real blocker, not passwordless itself: the survey shows demand is already there, but the estate underneath is too fragmented to absorb a clean transition. Passwordless only works when the organisation can govern every authentication path, including recovery, fallback and exception handling. The practitioner takeaway is that adoption plans must start with rationalisation, not branding.
Visibility is the governance control that decides whether passwordless becomes measurable or aspirational: a programme cannot prove risk reduction if it cannot see where each method is used. Lack of visibility across authentication practices means teams are managing a policy narrative rather than a control environment. That pushes assurance work into the grey zone where exceptions become permanent by default.
Usability is a security variable, not a separate concern: the article is explicit that user friction leads people to bypass controls, and that is an identity governance failure. Passwordless designs that ignore administrator effort and recovery complexity merely shift pressure elsewhere in the stack. The practical conclusion is that authentication architecture must be judged by both security strength and the likelihood that people will actually use it.
Authentication sprawl: the article shows how multiple disjointed methods, silos and fallback paths turn authentication into a governance problem rather than a point solution. The implication is that identity programmes need one accountable operating model for methods, exceptions and lifecycle management, not a collection of local fixes.
Passwordless adoption is a lifecycle issue as much as an authentication issue: onboarding, recovery, certificate expiry and administrator workload all shape whether the programme survives contact with the enterprise. That puts IAM, PAM and identity governance teams in the same conversation. Practitioners should treat passwordless as a governed transition across the entire identity lifecycle.
What this signals
Authentication sprawl: passwordless adoption will keep stalling until teams reduce the number of fallback paths, duplicate identity provider flows and local exceptions that preserve weaker access methods.
The practical test is whether authentication governance can explain every login path, recovery option and override without relying on tribal knowledge. If it cannot, the organisation is not ready to measure passwordless as a control outcome.
For practitioners
- Map every authentication path Document primary login methods, recovery flows, fallback options and application exceptions so the full authentication estate is visible before any migration.
- Rationalise fragmented silos Consolidate duplicated identity provider paths and local authentication workarounds that keep passwords or weaker methods in place.
- Reduce end-user bypass pressure Remove repeated prompts and unnecessary steps in high-friction journeys so users are less likely to circumvent controls.
- Automate operational overhead Target routine tasks such as certificate expiry handling and access resets, because manual effort is one reason teams delay authentication change.
- Tie passwordless to risk governance Set success criteria that measure authentication consistency, visibility and bypass reduction, not just rollout volume.
Key takeaways
- Authentication complexity, not demand, is the main reason passwordless adoption remains difficult in many enterprises.
- The survey points to a real governance gap: organisations may want passwordless, but they still lack visibility and consistency across the full authentication estate.
- The control problem is architectural and operational, so teams need to rationalise fallback paths, recovery flows and policy exceptions before rollout.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST CSF 2.0 and NIST SP 800-63 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article is about authentication paths that remain complex and weakly governed. |
| Recommendation — Rationalise authentication methods and remove fallback paths that preserve insecure login behaviour. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Authentication visibility and policy consistency are core access governance issues. |
| Recommendation — Inventory authentication controls and enforce consistent authorization boundaries across methods. | ||
| NIST SP 800-63 | SP 800-63B — Authentication | Passwordless adoption is directly about authentication assurance and lifecycle design. |
| Recommendation — Apply authentication guidance to enrolment, recovery and step-up flows before broad rollout. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | The article concerns governed identity and authentication management across the enterprise. |
| Recommendation — Establish identity management ownership for authentication methods, exceptions and recovery paths. | ||
Key terms
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
- OAuth Sprawl: OAuth sprawl is the accumulation of many third-party applications, grants, and token relationships that no team can fully track. It creates hidden access paths, stale permissions, and ownership ambiguity, which is why inventory and lifecycle control matter as much as initial approval.
- Fallback Path: A secondary access route used when the primary authentication method fails. Fallback paths matter because they often become the real control in day-to-day use. If they are easier than the intended method, the organisation will drift toward them and weaken its identity posture.
- Authentication Visibility: Authentication visibility is the ability to see which login methods, exceptions and recovery routes are used across the estate. Without it, identity teams cannot measure policy drift, retire unsafe workarounds or prove that control changes are reducing risk rather than masking it.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org