By NHI Mgmt Group Editorial TeamBased on Axiad: “What’s All the Hype about Frictionless?” (September 16, 2025)

TL;DR: Frictionless security only works when it accounts for every population, not just end users. Axiad’s blog argues that MFA adoption fails when organisations optimise for ease at the point of login while ignoring IT supportability, auditability, and executive governance across the enterprise. Frictionless does not mean governance-free; it means usable controls that survive real operational conditions.


At a glance

What this is: This is a vendor blog arguing that frictionless MFA only works when identity governance covers users, IT, audit, and executive stakeholders, not just login convenience.

Why it matters: It matters because IAM teams often judge MFA by adoption at the point of login, while the real failure mode is operational: supportability, auditability, and executive sponsorship determine whether controls survive in practice.

By the numbers:

  • The number of unfilled cybersecurity roles is expected to grow from 1 million in 2018 to 1.5 million by the end of 2020, according to Gartner Group research cited by Axiad.

Context

Frictionless MFA is not just a user-experience question. In identity programmes, friction appears whenever the control is hard to support, hard to audit, or hard to sustain across multiple populations with different responsibilities.

Axiad’s article argues that many organisations optimise for the end-user login journey and stop there. That creates a narrow view of identity governance, because IT, security, and executive stakeholders also determine whether MFA can be operated, evidenced, and maintained over time.

For IAM teams, the practical issue is not whether a control feels elegant in a demo. It is whether the control survives real-world support, staffing, audit, and governance pressure without falling back to passwords.


Key questions

Q: How should security teams replace traditional MFA without creating new access friction?

A: Start by removing passwords from the most sensitive sign-in paths and using phishing-resistant, device-bound authentication for those users first. Then keep policy lightweight and contextual, so access depends on trusted devices and current posture rather than repeated prompts. The goal is to reduce compromise paths without forcing users back into shared secrets or unnecessary second-device steps.

Q: Why do MFA programmes fail when they only optimise for end-user experience?

A: Because end-user ease does not address the people who must maintain, audit, and fund the control. If IT cannot support it, security cannot evidence it, and leadership cannot align it with business constraints, the programme becomes fragile. Friction simply moves from the user interface into operations, where it is less visible and more damaging.

Q: What are the warning signs that frictionless MFA is becoming ungoverned?

A: Common warning signs include rising exception requests, inconsistent rollout across populations, excessive help desk dependency, and password reversion when support gets difficult. These signals show that the control is not durable across the organisation. A secure MFA programme should reduce friction without creating hidden maintenance debt or undocumented bypass paths.

Q: How do IT supportability and auditability affect MFA success?

A: Supportability determines whether the control can be operated at scale, while auditability determines whether it can be defended in review. If either one is weak, the programme may still authenticate users but it will not remain trusted. The result is usually more exceptions, more manual work, and lower confidence in the control.


Technical breakdown

Why frictionless MFA fails when operational burden is ignored

Frictionless MFA is a usability goal, not a security property by itself. If the deployment increases help desk load, requires specialist troubleshooting, or cannot be maintained by the team responsible for day-to-day operations, users and administrators will route around it. That often means password fallback, exceptions, or delayed rollout. In identity governance terms, the control has to work for the operator population as well as the authenticated population. Otherwise, the programme shifts friction out of the login flow and into maintenance, where it is less visible but more damaging.

Practical implication: assess MFA not only for user adoption, but also for support cost, operational complexity, and exception volume.

How auditability changes the definition of frictionless MFA

Auditability is part of the control design, not an afterthought. An MFA programme that cannot produce reliable evidence of who enrolled, who approved, and how the control is managed across populations will struggle in assurance reviews even if users like it. In practice, this means reporting, lifecycle visibility, and policy consistency matter as much as authentication prompts. The article points to the need for third-party certifications, proven experience in higher assurance environments, and reporting that can stand up to scrutiny. That is why frictionless governance is broader than frictionless login.

Practical implication: verify that MFA evidence, reporting, and policy enforcement are available before treating the rollout as complete.

Why population-based governance matters more than a one-size-fits-all MFA design

Different populations interact with identity controls differently. End users want low friction, IT teams need maintainability, security teams need consistency, and executives need alignment with business risk and resource constraints. A one-size-fits-all model usually fails because it assumes the same operating conditions for all groups. In reality, governance has to account for support depth, skill shortages, and change-management pressure. The article’s core point is that the identity programme must be designed around organisational roles, not just around the login moment.

Practical implication: segment MFA governance by population and lifecycle responsibilities instead of treating all users as a single control class.


NHI Mgmt Group analysis

Frictionless MFA is an operating model problem, not just an adoption problem. A control that works in a pilot but cannot be supported at scale is not frictionless in practice. The real test is whether the programme reduces user resistance without transferring complexity into IT operations and governance. Practitioners should judge MFA by whether it can be sustained, not just whether it can be enabled.

The governance gap is that most MFA programmes stop at the end user. That assumption is too narrow because IT, audit, and executive stakeholders determine whether the control remains viable over time. When those populations are excluded, the organisation gets a login experience but not a durable identity control. The implication is that identity governance must cover all populations that operate, evidence, and approve the control.

Supportability is part of security architecture. A control that depends on scarce skills, fragmented tooling, or constant exception handling creates hidden risk even when authentication succeeds. That is why the shortage of skilled staff is not just a resourcing problem, it is a control durability problem. Practitioners should treat operational maintainability as a security requirement, not a post-deployment concern.

Audit-ready MFA should be designed as a lifecycle service. If reporting, assurance, and accountability are not built into the programme, friction reappears later as audit friction, exception sprawl, or governance drift. That is the point where organisations often backslide to passwords or weak exemptions. The better model is to govern MFA as an ongoing lifecycle capability with evidence, ownership, and support built in.

Named concept: population-aware frictionless governance. This article makes clear that frictionless identity control must be measured across user groups, not just at the interface. That means the design has to account for end users, operators, auditors, and executives as distinct governance populations. Practitioners should use that lens whenever a control is described as easy to use but hard to sustain.

What this signals

Population-aware frictionless governance: Security teams should stop treating MFA as a single-user journey and design it for the populations that operate, support, and audit it. That shift matters because the control fails when its maintenance burden is invisible to the people responsible for sustaining it.

The practical question is no longer whether MFA is easy to use in isolation. It is whether the programme remains supportable when skills are scarce, reporting is required, and exceptions begin to accumulate across the enterprise.


For practitioners

  • Map MFA governance across all stakeholder populations Document how end users, IT operations, audit teams, and executives each interact with the MFA programme, including ownership, support, reporting, and approval responsibilities.
  • Test operational supportability before rollout Measure help desk impact, exception handling, skill requirements, and maintenance effort under real operating conditions rather than assuming adoption proves viability.
  • Build audit evidence into MFA design Ensure the programme can produce reliable evidence for enrolment, policy enforcement, third-party assurance, and ongoing control operation without manual reconstruction.
  • Reduce password fallback paths Identify where users or administrators can bypass MFA and remove those routes before the control becomes dependent on convenience-based exceptions.

Key takeaways

  • Frictionless MFA fails when organisations optimise only for login convenience and ignore the operational and governance work needed to sustain the control.
  • The article’s evidence shows that IT staffing constraints, audit expectations, and executive pressure all shape whether MFA remains viable in practice.
  • The most effective MFA programmes are population-aware, supportable, and auditable, not just easy for the first user who logs in.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationThe article is about MFA usability, deployment, and maintenance across populations.
Recommendation — Use SP 800-63B to align MFA requirements with authentication assurance and deployment reality.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe post centres on enforcing access controls in a way that remains operationally sustainable.
Recommendation — Apply PR.AA-05 to govern authentication controls with consistent policy and lifecycle oversight.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)The article discusses enterprise authentication for internal user populations and support teams.
AU-6 — Audit Review, Analysis, and ReportingThe article repeatedly stresses auditability and evidence for security assurance.
Recommendation — Use IA-2 to ensure organisational user authentication remains supportable and auditable at scale. Apply AU-6 to make MFA evidence reviewable and usable during assurance and compliance checks.
CIS Controls v8CIS-5 — Account ManagementThe post’s governance concerns include maintaining accounts, exceptions, and supportable access control.
Recommendation — Use CIS-5 to govern account lifecycle and exception handling for MFA-dependent access.

Key terms

  • Frictionless Mfa: A multi-factor authentication approach designed to preserve strong identity assurance while reducing the steps and interruptions a user experiences. In healthcare, it matters because repeated prompts can slow clinicians, encourage workarounds, and undermine the practical value of the control.
  • Auditability: Auditability is the ability to reconstruct who or what acted, what permissions were used, and what data or tools were touched. For AI and NHI governance, it is the minimum evidence needed to investigate incidents, validate controls, and prove that autonomous actions stayed within approved scope.
  • Population-aware governance: An identity governance approach that treats different user groups as distinct operating populations with different support, reporting, and approval needs. For MFA, this means designing controls for end users, IT operators, security teams, and executives rather than assuming one experience fits all.
  • Supportability: Supportability is the extent to which a platform can still receive guidance, updates, diagnostics, and recovery help from the vendor. In identity operations, it is a security property because unsupported systems are harder to fix quickly and can linger as unresolved exposure in critical access paths.

Deepen your knowledge

NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org