TL;DR: Users routinely create insecure workarounds when authentication adds unnecessary friction, according to SecureAuth, and the article argues that customer-first identity design improves security by making safe paths easier to follow. For IAM teams, the real question is whether controls are usable enough to survive real behaviour.
At a glance
What this is: This is an argument for customer-first IAM, with the central finding that authentication friction pushes users toward less secure workarounds.
Why it matters: It matters because identity programmes fail when controls are theoretically strong but operationally inconvenient for the people who must use them.
👉 Read SecureAuth's article on customer-first identity and authentication design
Context
Identity controls do not succeed just because they are technically sound. In human IAM, the practical test is whether people can complete authentication and access tasks without resorting to unsafe shortcuts, because every unnecessary prompt increases the chance of bypass behaviour.
A customer-first approach treats usability as part of security design rather than a separate experience problem. For teams running SSO, MFA, passwordless, or adaptive access, the question is whether the control reduces risk in practice or simply relocates it into user workarounds.
SecureAuth frames the issue around human behaviour, which is a familiar failure mode in workforce and consumer identity programmes. That starting point is typical for IAM environments where friction and compliance requirements compete with adoption and supportability.
Key questions
Q: How should security teams reduce IAM friction without weakening control?
A: Start by identifying the access paths that users bypass most often, then redesign those steps so they fit the actual workflow. The goal is not to remove verification, but to place it where it changes risk. If controls are too slow or disruptive, users will create shadow practices that reduce both security and visibility.
Q: Why do users create insecure workarounds when identity controls are too strict?
A: Because people optimise for task completion when the control adds delay, confusion, or repeated effort without an obvious security benefit. In practice, that can lead to session sharing, exception requests, or avoidance of stronger authentication. Usability failures therefore become security failures once the workaround is easier than compliance.
Q: What do organisations get wrong about identity-first security?
A: They often treat it as an authentication project rather than an operating model. In practice, identity-first security has to cover credential issuance, tracking, offboarding, and user experience across human and machine identities. If it only adds more login steps, teams will get workarounds instead of durable security.
Q: How do you know whether an authentication control is too burdensome?
A: Look for abandonment, support escalation, exception growth, and repeated manual workarounds around the control. Those signals usually mean the control is harder to follow than to evade. If legitimate users keep finding alternate paths, the programme is paying for theoretical assurance instead of operational security.
Technical breakdown
Why authentication friction creates insecure workarounds
Authentication friction changes user behaviour before it changes attacker behaviour. When a sign-in flow adds repeated prompts, confusing exception paths, or extra steps without clear value, users look for ways around it, such as reusing sessions, avoiding registration, or sharing access. In human IAM, the control is only as strong as the path people actually take. Security design therefore has to account for user choice, not just policy intent. This is why adaptive authentication, risk-based step-up, and passwordless methods are often evaluated as much for usability as for assurance.
Practical implication: review the paths users take in production, not the policy document, and remove steps that do not materially improve assurance.
Designing human IAM controls for usability and assurance
Human IAM works best when security actions are aligned with expected user behaviour. That means prompts should be understandable, repeatable, and limited to situations that genuinely change risk. Adaptive MFA and continuous verification are useful only when they are calibrated so that low-risk activity stays low-friction while higher-risk activity gets stronger challenge. The design problem is not whether to add more gates, but where friction actually improves confidence and where it simply trains users to avoid the control entirely.
Practical implication: tune authentication challenges to the risk context and retire blanket prompts that do not improve decision quality.
Customer-first identity is still a security control
A customer-first mindset does not weaken identity security. It recognises that authentication, access, and verification are part of a system that includes human behaviour, support burden, and operational continuity. If a control is too cumbersome, users will create informal alternatives that are harder to govern than the original risk. That is why good identity programmes measure both resistance to attack and resistance to workaround behaviour. Usability is not a soft metric here, it is a control effectiveness indicator.
Practical implication: treat user friction as a measurable security signal and include it in identity governance reviews.
NHI Mgmt Group analysis
Human IAM fails when security design assumes users will comply with friction that the process itself makes unreasonable. The article’s central point is that users react to inconvenience, and those reactions often produce weaker security than the intended control. That makes usability part of the control surface, not an afterthought. For IAM leaders, the implication is that adoption and assurance have to be measured together.
Customer-first identity is a governance model, not a branding exercise. When authentication and verification are designed around real user behaviour, the programme reduces shadow workarounds, support escalation, and policy exceptions. That is especially important in workforce and consumer identity where scale magnifies every poor decision. The practical conclusion is that identity teams should evaluate whether a control is usable enough to remain enforceable under load.
Security programmes that optimise only for challenge strength tend to miss the operational cost of abandonment. A control that users bypass, delay, or game is weaker than a simpler control that is consistently followed. This is why identity design has to balance assurance, user experience, and recoverability. Practitioners should treat friction as a governance issue, not just a UX metric.
Authentication friction: controls that make legitimate access unnecessarily difficult often trigger insecure workarounds, which can reduce overall assurance more than the original risk they were meant to address. The lesson for practitioners is to remove low-value steps and preserve only the prompts that materially change risk.
From our research:
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which shows how often governance trails the actual identity estate.
- That same visibility gap is why teams should also review the NHI Lifecycle Management Guide when designing lifecycle controls for machine and human identities alike.
What this signals
Human IAM programmes increasingly win or lose on the quality of the user path, not the number of controls deployed. When authentication creates avoidable friction, users route around it, and those detours become part of the real control environment. That is why identity teams should assess journey quality alongside assurance metrics and keep recovery flows simple.
A useful programme signal is whether users ask for exceptions more often than they complete the intended path. If that pattern is rising, the control design is probably misaligned with how people work. Teams should treat workaround behaviour as evidence that governance and usability are out of balance.
The broader shift is toward identity controls that are both enforceable and tolerable at scale. That means integrating identity governance with user experience review, support analysis, and access policy tuning instead of treating them as separate workstreams.
For practitioners
- Audit user friction in live authentication journeys Review the highest-volume sign-in and step-up paths for repeated prompts, confusing exceptions, and abandonment points. Focus on where users are most likely to switch to informal or weaker access methods.
- Align step-up challenges to risk, not habit Use adaptive rules so that low-risk access remains simple and higher-risk access gets stronger verification. Retire blanket prompts that do not change the security decision.
- Measure workaround behaviour as a security signal Track support tickets, failed sign-ins, exception requests, and session persistence patterns to identify where friction is driving unsafe behaviour instead of safer adoption.
- Review identity governance with usability in scope Include user journey quality in access reviews, authentication design changes, and policy recertification so the programme can identify controls that are technically correct but operationally unusable.
Key takeaways
- Customer-first IAM is about reducing the friction that causes users to bypass controls, not lowering the security bar.
- Usability becomes a security variable when repeated prompts, exceptions, and workarounds shape the access path users actually follow.
- Identity teams should judge controls by both assurance quality and whether people can use them without inventing unsafe alternatives.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B | The article centers on human authentication and user-facing assurance choices. |
| NIST CSF 2.0 | PR.AC-1 | Identity and access control design is the core governance issue in this article. |
| NIST Zero Trust (SP 800-207) | 4.1 | Continuous verification and reduced implicit trust align with the article's access model. |
Apply zero trust principles to keep high-risk access visible while preserving low-friction paths for routine use.
Key terms
- Authentication Friction: The delay, confusion, and support burden created when users cannot complete sign-in cleanly. In IAM programmes, friction is a governance signal because it drives resets, exceptions, and workarounds. If users routinely hit the recovery path, the authentication design is not yet operationally stable.
- Customer-First Identity: Customer-first identity is an approach to IAM that designs access controls around how people actually behave while still preserving assurance. It treats usability, recovery, and supportability as part of the control environment, because controls that users cannot follow consistently will be bypassed or weakened.
- Continuous Verification: A Zero Trust practice that re-evaluates trust during the session instead of relying on a single successful login. The control is stronger when context signals are available in real time and when the identity programme can act on those signals without creating excessive exceptions.
What's in the full article
SecureAuth's full article covers the operational detail this post intentionally leaves for the source:
- The specific customer-first design principles the vendor uses to reduce user friction in authentication flows.
- Platform-oriented examples of adaptive verification and continuous authority in workforce and consumer identity.
- Implementation context for balancing security prompts with usability across identity journeys.
- Product-level framing for how the vendor positions its identity approach in different industries.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on September 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org