TL;DR: Poor password hygiene remains widespread, with 66% of employees reporting risky password behaviour and 89% of security and IT professionals saying their company is pushing passkeys, according to 1Password's Annual Report 2025 analysis. The governance challenge is not whether passwordless will arrive, but whether teams can reduce raw credential exposure while it is still partial and uneven.
At a glance
What this is: This analysis from 1Password shows that passwordless adoption is rising, but weak and reused passwords still leave organisations exposed to credential risk.
Why it matters: IAM and security teams need to manage the transition carefully because partial passwordless adoption does not eliminate the governance burden around credentials, MFA, storage, and offboarding.
By the numbers:
- 66% of employees report having poor password hygiene, including default passwords and password reuse.
- 44% of CISOs report that employees using weak or compromised passwords is one of their top security challenges.
- 89% of security and IT professionals say their company is encouraging employees to shift logins to passkeys.
Context
Passwordless access is not the same as password elimination. Most organisations are operating in a mixed state where some users, apps, and workflows still depend on passwords while others move to passkeys, which means the real control problem is credential governance during the transition.
For IAM teams, that creates a practical gap between authentication strategy and day-to-day access reality. Weak passwords, reused credentials, and unmanaged storage remain part of the attack surface until organisations reduce user handling of raw credentials and tighten the controls around the ones that remain.
Key questions
Q: What is the biggest failure mode in passwordless onboarding?
A: The biggest failure mode is treating the first credential as harmless because it is temporary. If the bootstrap secret is emailed, spoken aloud, or left valid too long, passwordless onboarding still begins with a phishing- and replayable credential. The issue is not passkeys themselves, but the unmanaged handoff that precedes them.
Q: Why do passwordless programmes still need MFA and step-up authentication?
A: Passwordless removes the password, not the need to verify identity under higher-risk conditions. MFA and step-up checks remain useful when users switch devices, work from shared endpoints, or request access that exceeds normal context. The goal is to keep assurance aligned with risk, not to rely on a single factor everywhere.
Q: What signs show that passwordless controls are not yet reducing risk?
A: The warning signs are weak-password pockets, repeated fallback logins, inconsistent adoption across business units, and continued manual handling of passwords for shared or legacy access. If those patterns persist, the organisation is modernising the front door while leaving the back door open.
Q: How should teams govern access when some users have passkeys and others still rely on passwords?
A: Teams should govern the transition as a lifecycle issue, with explicit ownership for exceptions, recovery methods, offboarding, and review of any remaining passwords. The goal is to control the mixed state until passwordless becomes the default, not to treat coexistence as an end state.
Technical breakdown
Why passwordless adoption does not remove credential risk
Passwordless authentication reduces how often users type passwords, but it does not automatically remove every credential dependency in an organisation. Applications, fallback flows, legacy systems, and shared access patterns can still rely on passwords, recovery factors, or stored secrets. That is why passwordless should be treated as an access-flow redesign, not a single authentication feature. The security outcome depends on how much raw credential exposure remains across the estate, including where people still handle, reset, share, or recover access through traditional credentials.
Practical implication: Measure credential exposure across the full access journey, not just successful passkey enrollment.
The governance gap in hybrid authentication environments
Hybrid authentication environments create a split between users who are already on stronger methods and users who still depend on passwords or enterprise vaulting. That split matters because security teams often govern the end state better than the transition state. A programme can support passkeys while still leaving weak-password pockets, unmanaged fallback, and inconsistent enforcement of MFA or password storage. In governance terms, the control plane has to cover adoption, exception handling, and offboarding, not just the preferred login method.
Practical implication: Treat passwordless rollouts as a lifecycle governance problem and track exceptions as first-class risk.
Why password managers and MFA still matter in a passwordless roadmap
Even in a passwordless roadmap, passwords do not disappear overnight. Where passwords remain necessary, enterprise password managers and MFA still reduce the chance that credentials are reused, shared insecurely, or left exposed in unmanaged places. The technical point is not that vaulting replaces passwordless, but that it constrains the residual credential surface until stronger methods become universal. That makes storage, sharing, and recovery controls part of the migration architecture rather than temporary conveniences.
Practical implication: Use enterprise password management and MFA as compensating controls while passwordless adoption remains incomplete.
NHI Mgmt Group analysis
Passwordless adoption is an access-governance transition, not an authentication finish line. The article makes clear that organisations can push passkeys while still living with password reuse, fallback credentials, and uneven adoption. That means the programme question is not whether passwordless exists, but how much raw credential exposure remains during the transition. Practitioners should judge maturity by reduction in handling, not by enrollment headlines.
Residual password use creates a credential governance gap that traditional IAM reporting often misses. The report points to a mixed environment where some accounts have moved forward and others still depend on passwords or vaulted access. That split is operationally important because exceptions, recovery paths, and shared credentials become the real control surface. Teams need to see the hybrid state as the risk, not just the legacy password.
Passwordless only changes the security model when it removes people from direct credential handling. The article's own framing says the goal is to minimise exposure to raw credentials. That is the right criterion because passwordless that still leaves users storing, sharing, or recovering secrets manually does not materially change the attack surface. The implication for identity programmes is to measure reduction in human-mediated credential handling, not merely feature adoption.
Enterprise password managers remain part of the transition architecture, not a competing destination. Where passwords persist, central storage, controlled sharing, and admin visibility are still necessary to contain risk. This is particularly relevant for organisations that cannot move every workflow to passkeys at once. The practitioner conclusion is straightforward: manage the residual credential estate as long as it exists, even while the roadmap moves toward passwordless.
Credential risk is now a mixed-state problem, which means governance must span human, NHI, and access workflow boundaries. Passwordless for humans does not remove the broader identity problem if service accounts, shared logins, or recovery processes still depend on reusable secrets. The post points to an industry where authentication is becoming more modern faster than governance processes are changing, and that mismatch is where exposure lingers. The practical conclusion is to align IAM, PAM, and NHI lifecycle controls around the remaining credential surface.
From our research library:
- eBay's passkey data shows 55-60% of passkey adoption happens on mobile, against around 20% on desktop.
What this signals
Access-trust debt: passwordless programmes often reduce visible authentication friction faster than they reduce underlying credential exposure. The real work is to shrink the number of places where users still touch raw credentials, because that is where reuse, storage, and recovery risk persist.
Mixed authentication states change what identity teams should measure. Instead of reporting only passkey adoption, practitioners need a view of fallback paths, password reuse, and unmanaged sharing, because those are the controls that determine whether the transition is actually improving security.
The programme implication is to align IAM, PAM, and NHI lifecycle governance around the residual credential estate. If passwords remain necessary for any workflow, they still need ownership, storage control, and retirement planning.
For practitioners
- Map the remaining credential surface Inventory where passwords still exist across users, recovery flows, shared accounts, and legacy applications so you can see what passwordless has not yet removed.
- Treat fallback paths as governed exceptions Document password recovery, shared access, and legacy login exceptions with ownership, expiry, and review so the transition state does not become permanent.
- Keep MFA on all residual password flows Require multifactor authentication wherever passwords remain in use, including fallback and administrative access, so residual credentials do not become easy takeover paths.
- Use enterprise password managers for unavoidable passwords Centralise storage and approved sharing of any passwords that remain necessary, especially for teams that still exchange access through human-managed credentials.
- Track passwordless progress by exposure reduction Measure success by reduced reuse, fewer unmanaged logins, and less direct handling of raw credentials rather than by the number of enrolled users alone.
Key takeaways
- Passwordless adoption reduces one category of exposure, but it does not eliminate credential risk while passwords and fallback flows still exist.
- The article's evidence shows both high risky-password behaviour and strong push toward passkeys, which makes the transition state the real governance challenge.
- Organisations should manage residual credentials as a governed lifecycle problem until passwordless becomes the norm across users and workflows.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article centres on authentication weakness during the move away from passwords. |
| NHI-07 — Long-Lived Secrets | Residual passwords and stored credentials remain long-lived secrets in hybrid environments. | |
| NHI-10 — Human Use of NHI | The post highlights people still handling credentials directly instead of using stronger authentication flows. | |
| Recommendation — Reduce insecure authentication paths by accelerating passkey adoption and eliminating weak fallback logins. Shorten the lifetime of residual passwords and remove them from unmanaged storage wherever possible. Minimise human handling of credentials by shifting users to passwordless flows and controlled vaulting. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about governing authentication and access permissions during transition. |
| Recommendation — Review access and authentication pathways together so residual credentials are governed as part of the access model. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article addresses account-level credential handling, storage, and offboarding during migration. |
| Recommendation — Apply account management discipline to remove unused credentials and control residual password use. | ||
Key terms
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
- Passkey: A passkey is a passwordless credential based on public key cryptography. A private key stays on the user’s device, while a public key is stored by the service. During login, the device signs a challenge after local unlock, which reduces phishing and eliminates shared secret reuse.
- Residual Credential Surface: The set of passwords, recovery factors, shared logins, and legacy authentication paths that still exist after a modernisation effort begins. This surface is often where risk persists longest because it spans users, applications, and exceptions that are not yet ready for full passwordless adoption.
- Access-trust gap: The gap between having a policy and actually enforcing it when access is requested. It appears when compliance, HR, or training data sits in separate systems from the access decision, allowing users to reach resources even though a required condition has not been met.
Deepen your knowledge
NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or access governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org