TL;DR: Authentication complexity is overwhelming 70% of security and IT professionals, while almost 85% of organisations experienced a cyberattack last year and nearly 9 in 10 plan passwordless adoption, according to Axiad and cited survey data. The real issue is not feature choice but whether MFA, phishing resistance, and user friction are governed as one identity programme.
At a glance
What this is: This is an analysis of enhanced authentication choices and the governance tradeoffs between MFA, passwordless, phishing resistance, and usability.
Why it matters: IAM teams need to treat authentication design as a programme-level decision because fragmented controls and poor user experience create bypass paths, inconsistent enforcement, and weak resilience across human and machine access.
By the numbers:
- 70% of Security/IT professionals say they are overwhelmed by the complexity of their authentication systems.
- Almost 85% of organisations experienced a cyberattack in the last year.
- Almost 9 in 10 organisations are planning to implement a passwordless strategy in the next 12 months or have already done so.
Context
Authentication is no longer a single control choice. It is a portfolio decision that has to balance phishing resistance, usability, deployment consistency, and the risk of bypass behaviour when controls become too cumbersome or too fragmented.
For IAM programmes, the governance problem is not whether MFA or passwordless exists somewhere in the stack. The issue is whether the organisation can enforce one coherent policy across users, devices, operating systems, and use cases without creating silos that attackers can exploit.
Key questions
Q: What breaks when authentication is managed in silos across multiple IAM systems?
A: Authentication gaps appear when assurance rules, recovery steps, and policy enforcement differ across systems. Users may receive inconsistent access treatment, audit teams lose a single view of identity assurance, and attackers can target the weakest path between platforms. The fix is not another isolated control, but a common governance model across the whole authentication estate.
Q: Why do phishing-resistant MFA methods matter if attackers can still get in?
A: They materially reduce real-time credential harvesting and replay attacks, which removes one of the easiest entry paths. But they do not stop an attacker who already controls a valid session through social engineering, stolen tokens, or compromised administrators. The practical goal is to reduce entry opportunities and then limit post-login blast radius.
Q: How do security teams know if identity friction is becoming a risk?
A: They should watch login duration, failed authentication, device utilisation, and the volume of manual exceptions. Rising friction metrics often indicate that users are working around controls or abandoning secure workflows. That is an early signal that the access design is misaligned with how people actually work.
Q: Should organisations replace MFA with passwordless authentication?
A: Organisations should not treat this as a simple replacement question. MFA is still useful where passwordless is not yet available, but passwordless raises the security baseline by removing the password as the primary failure point. The right path is to use MFA as a bridge and passwordless as the destination.
Technical breakdown
Why disjointed authentication silos create exploitable gaps
When organisations run multiple authentication methods across separate IAM ecosystems, they create policy drift. Different apps, operating systems, and user groups end up enforcing different assurance levels, recovery paths, and exception handling. That fragmentation weakens the overall identity plane because attackers look for the weakest or least consistently governed path. Authentication is only as strong as its least governed branch, especially when user experience and operational exceptions encourage inconsistent rollout.
Practical implication: map every authentication method to one governance model and remove exceptions that create unaudited access paths.
Why phishing-resistant MFA is not interchangeable with generic MFA
MFA raises the bar, but not every MFA method resists phishing. Some factors can still be intercepted, replayed, or socially engineered through prompt-bombing and user approval fatigue. Phishing-resistant approaches reduce that risk by binding authentication more tightly to the legitimate device or cryptographic assertion, which changes the attack economics. The distinction matters because a control that merely adds a second prompt may improve friction without materially improving assurance.
Practical implication: classify MFA methods by phishing resistance, not just by whether they add a second factor.
How usability pressure changes authentication risk
Authentication controls that become too burdensome often trigger workarounds. Users reuse passwords, seek exceptions, or bypass protective steps when enrollment, recovery, or repeated prompts slow them down. That is why lower-friction methods such as passwordless are attractive in modern IAM programmes: they can improve adoption without relying on memorised secrets. The control question is not simply convenience versus security, but whether the chosen method can be adopted at scale without eroding compliance.
Practical implication: measure abandonment, bypass requests, and recovery exceptions alongside security outcomes when evaluating authentication changes.
Threat narrative
Attacker objective: The attacker aims to obtain authenticated access through the weakest or least governed authentication path while avoiding the strongest assurance controls.
- Entry begins when an attacker targets credentials, phishing flows, or MFA prompts rather than relying on password guessing alone.
- Escalation occurs when weak or disjointed authentication methods allow approval fatigue, recovery abuse, or inconsistent enforcement across systems.
- Impact follows when the attacker gains authenticated access through the path with the lowest assurance and the organisation cannot apply one policy consistently.
Breaches seen in the wild
- Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Authentication sprawl is a governance problem, not just a user-experience problem: When organisations maintain multiple disconnected MFA approaches across use cases and operating systems, they create policy drift that weakens assurance. The issue is not merely complexity at the edge. It is the absence of one accountable identity policy that can be enforced across the full authentication estate.
Phishing resistance is the real control boundary: Generic MFA and phishing-resistant authentication are not equivalent security choices. The article’s core lesson is that the control name alone does not tell you whether the method can survive phishing, prompt fatigue, or replay-style abuse. Practitioners should treat resistance to interception as the differentiator that matters.
User friction is a security signal: Rising bypass behaviour, recovery workarounds, and multiple sign-in paths usually mean the programme has made authentication harder to follow than to circumvent. That is a design failure in the identity programme, not a training issue. The practical implication is that usability metrics belong in authentication governance reviews, alongside assurance metrics.
Passwordless adoption is accelerating because memorised secrets no longer scale: The article reflects a broader shift away from password dependence as organisations seek lower-friction access that is harder to phish. That does not eliminate governance work. It shifts it toward lifecycle design, device trust, recovery handling, and policy consistency across human identity journeys.
Enhanced authentication forces a programme decision, not a product decision: Organisations that treat MFA, passwordless, and phishing resistance as separate tool choices miss the real tradeoff. The decision is how much assurance, operational burden, and user tolerance the identity programme can support at once. Practitioners need a coherent authentication architecture, not a collection of point controls.
What this signals
Authentication governance is becoming a policy consistency problem: The more teams spread MFA variants across apps and environments, the more they have to manage assurance drift rather than authentication strength. Programme owners should treat that drift as an architecture issue and centralise the decision logic before it turns into exception sprawl.
Passwordless changes the identity control conversation: It does not solve governance by itself, but it can reduce the dependence on memorised secrets that users routinely struggle to manage. For IAM teams, the real question is whether passwordless is being deployed as a consistent policy shift or just as another disconnected access option.
Friction is a measurable security outcome, not a side effect: When users bypass controls or create shadow recovery paths, the programme is telling you where the design is failing. Security teams should monitor those signals as part of authentication health, not treat them as isolated service desk noise.
For practitioners
- Define one authentication policy tiering model Classify authentication methods by assurance, phishing resistance, and recovery risk so every application maps to the same policy logic.
- Inventory authentication silos across the estate Document where separate MFA stacks, operating-system differences, and application-specific exceptions create inconsistent enforcement.
- Prioritise phishing-resistant methods for high-risk access Use the strongest available factors for administrative access, sensitive workloads, and any workflow where prompt approval could be abused.
- Measure friction as a security control outcome Track bypass requests, enrolment drop-off, recovery failures, and repeated prompts to see whether the programme is driving unsafe workarounds.
Key takeaways
- Authentication choice is now a governance issue because disconnected methods create inconsistent assurance across the identity estate.
- The article ties complexity, phishing exposure, and user friction to the same programme problem rather than treating them as separate issues.
- Practical teams should focus on policy consistency, phishing resistance, and adoption signals when deciding how to evolve authentication.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B — Authentication | The article focuses on authentication choice, assurance strength, and phishing resistance. |
| Recommendation — Use SP 800-63B to classify authenticators by assurance and phishing resistance before standardising policy. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Authentication design here is tied to how access is granted consistently across systems. |
| Recommendation — Apply PR.AA-05 to align authentication policy with consistent entitlement enforcement across apps. | ||
| OWASP ASVS | V6 — Authentication | The article centres on authentication method selection and assurance tradeoffs. |
| Recommendation — Use V6 to validate that authentication choices resist phishing and support secure recovery paths. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The piece is about governing access decisions across authentication methods and environments. |
| Recommendation — Apply A.5.15 to keep authentication methods under one access control policy. | ||
Key terms
- OAuth Sprawl: OAuth sprawl is the accumulation of many third-party applications, grants, and token relationships that no team can fully track. It creates hidden access paths, stale permissions, and ownership ambiguity, which is why inventory and lifecycle control matter as much as initial approval.
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
- Authentication recovery: Authentication recovery is the process used when a user cannot complete primary sign-in and needs access restored. It matters because recovery pathways can be weaker than the main authentication stack, especially for privileged accounts, and attackers often target those fallback controls when they are under-governed.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org