TL;DR: Traditional MFA still depends on passwords, shared secrets, or weak out-of-band factors, leaving phishing, SIM swap, and push fatigue paths open, according to Beyond Identity. For IAM and NHI governance, the practical shift is toward passwordless authentication, device-bound assurance, and continuous policy checks rather than stronger add-ons to a flawed login stack.
At a glance
What this is: This article explains why passwordless authentication is positioned as a better fit than traditional MFA for reducing login risk, especially where shared secrets and weak second factors still dominate.
Why it matters: IAM teams and NHI governors should care because authentication controls that still rely on passwords or out-of-band codes can leave both human and machine-access programmes exposed to avoidable compromise.
Context
Passwords remain the weak point in many authentication designs because they are reusable shared secrets. MFA reduces risk, but it does not remove that first factor, so the underlying attack surface persists across human access and any downstream identity workflows that depend on the same login stack.
For NHI governance, the practical question is not whether a second factor exists. It is whether access decisions still depend on a compromised secret somewhere in the chain. If the answer is yes, the programme is still managing password risk rather than eliminating it.
Passwordless authentication changes the control model by binding access to device-backed factors and local assurance rather than a password plus add-on verification. That matters when teams want continuous policy checks without relying on an insecure starting point.
Key questions
Q: What breaks when MFA is used only at sign-in and not for privileged actions?
A: The main failure is stale trust. A user may authenticate once and then remain authorized for hours or days, which is too broad for account deletion, payment approval, or access to secrets. Without re-authentication at the point of action, an attacker who inherits the session can complete high-risk operations without facing a fresh challenge.
Q: Why does SMS-based MFA still create account takeover risk?
A: SMS creates risk because the factor travels through a channel that can be redirected through SIM swapping, message interception, or social engineering. It may block low-effort attacks, but it does not provide strong assurance against an attacker who can compromise the phone number or trick the user into sharing the code. That makes it unsuitable for sensitive or privileged access.
A: Organisations should treat passwordless authentication as an access-control redesign, not a cosmetic login change. The right decision depends on risk tolerance, user population, device readiness, and support capacity. Passwordless can reduce password theft and reset burden, but it also introduces rollout complexity, training needs, and troubleshooting overhead. A phased approach with strong identity proofing and fallback controls is usually safer than a big-bang switch.
Q: What signals show that MFA is no longer strong enough for the programme?
A: Frequent push approvals, heavy reliance on SMS or email codes, password reset dependency, and repeated user complaints about friction all indicate that the programme is leaning on brittle factors. Those symptoms mean authentication is still built around shared secrets, not durable identity assurance.
Technical breakdown
Why traditional MFA still leaves a password attack surface
Traditional MFA improves login security, but it does not remove the password from the chain. That matters because passwords are shared secrets, so phishing, reuse, leaks, and credential stuffing remain viable entry paths even when a second factor is present. In practice, the security of MFA becomes only as strong as the weakest factor in the stack, and many common second factors such as SMS codes, email OTPs, and push approvals are themselves vulnerable to interception or user fatigue. The architectural weakness is not factor count, but factor quality and whether the first factor is already assumed compromised.
Practical implication: treat password-based MFA as risk reduction, not risk elimination, and map which login paths still depend on a reusable secret.
How passwordless authentication changes assurance and policy enforcement
Passwordless authentication removes the password entirely and replaces it with stronger device-bound and biometric assurance. That shifts the trust model from a shared secret to possession of a protected endpoint plus locally verified identity, often backed by asymmetric cryptography. Because the device can be evaluated at login, the control can also incorporate posture signals such as encryption status, secure enclave use, or managed security tooling. The main technical change is that authentication becomes bound to the device state and the session context, rather than to a knowledge factor that attackers can steal and replay.
Practical implication: prefer authentication flows that validate device state and local factors at the point of access instead of layering controls onto passwords.
Why out-of-band factors fail under phishing, SIM swap, and push fatigue
Out-of-band MFA factors fail because they create a second channel that attackers can target separately from the initial login. SMS codes can be redirected through SIM swap fraud, email OTPs inherit the weakness of the email account, and push notifications can be accepted reflexively when users are conditioned to approve alerts. These failures are not edge cases. They are structural weaknesses in authentication designs that depend on user attention, telephony trust, or a second channel that is easier to intercept than the first. Passwordless design removes that dependency by eliminating the out-of-band gap altogether.
Practical implication: phase out SMS, email, and approval-based factors wherever the threat model includes phishing or account takeover.
Breaches seen in the wild
- Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.
- SonicWall SSL VPN account compromises 2025: Attackers used valid credentials to log in to more than 100 SonicWall SSL VPN accounts across 16 environments in October 2025.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Passwords in the MFA chain are not a secondary weakness, they are the primary assumption failure. Traditional MFA assumes a compromised password can be rescued by a stronger second factor. In practice, that makes the second factor carry the entire burden of assurance, which is an unstable foundation for both human and non-human access. The practitioner takeaway is that password removal is a control decision, not a user-experience preference.
Continuous policy checks matter because authentication is now a device-state decision as much as an identity decision. Once the login is bound to device posture, the organisation can evaluate security state at the point of access rather than relying on a static secret. That aligns better with NHI governance, where access should be evaluated in context rather than granted because a credential was presented successfully. The practitioner takeaway is to treat device trust as part of the access boundary.
Device-bound authentication reduces the blast radius of compromised credentials by removing reusable secrets from the workflow. Passwords can be leaked, reused, or sold, but a local biometric plus protected device posture cannot be replayed in the same way. That changes the economics of account takeover across human and workload-adjacent identity programmes. The practitioner takeaway is to prioritise controls that make stolen credentials less transferable.
Authentication programmes that still rely on shared secrets are carrying identity debt, not just technical debt. Every exception for SMS, email OTPs, or password fallbacks preserves a path that attackers already know how to abuse. For governance teams, that means the target state is not stronger MFA everywhere, but fewer shared secrets in the access flow. The practitioner takeaway is to measure how many login journeys still begin with a password.
Passwordless authentication is increasingly the practical baseline for modern identity governance. The article’s logic is not that MFA is useless, but that MFA is often compensating for a flawed starting point. For teams running identity programmes across humans and non-human access, that means the design question has shifted from factor count to trust construction. The practitioner takeaway is to redesign authentication around elimination of shared secrets, not accumulation of them.
From our research library:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
What this signals
Passwordless removes the weakest assumption in the access stack: if the login journey still begins with a reusable secret, the programme is managing exposure rather than reducing it. For IAM teams, that means the control objective is to make stolen credentials non-transferable, not merely harder to use.
Continuous device-based policy evaluation becomes more relevant when the identity signal and the security signal are evaluated together. That is especially useful in environments where privileged access, workforce access, and downstream NHI administration all depend on the same trust boundary.
The programme question is shifting from how many factors exist to whether any factor can be replayed off-device. Once the answer is yes, the authentication layer still contains a credential path that attackers can operationalise.
For practitioners
- Remove password fallbacks from priority access flows Identify the applications and admin pathways where password reset or password-based fallback still exists, then remove those paths first so a stolen secret cannot become the default recovery route.
- Replace SMS and email OTPs with device-bound assurance Retire out-of-band codes for high-value access and require device possession plus local verification on the endpoint, especially where phishing and SIM swap are realistic threats.
- Enforce device posture checks at login Require the access decision to evaluate endpoint posture such as encryption, secure enclave support, and managed security tooling before granting the session.
- Track how many journeys still start with a shared secret Measure password dependence across workforce, privileged, and service-adjacent access paths so you can prove whether authentication is still built on a reusable secret.
Key takeaways
- Traditional MFA still leaves a reusable secret in the access path, which preserves the attack surface for phishing, reuse, and account takeover.
- Passwordless authentication shifts assurance to device-bound factors and local verification, making the login flow harder to replay or intercept.
- For practitioners, the governance priority is to remove password fallbacks and weak out-of-band factors before treating MFA coverage as complete.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article centres on insecure password-based and out-of-band authentication paths for identities. |
| NHI-10 — Human Use of NHI | The article touches identity controls that affect how humans authenticate into systems tied to non-human access. | |
| Recommendation — Replace password-dependent login flows with stronger authentication that removes shared-secret exposure. Separate human authentication assurance from non-human access control and avoid shared login assumptions. | ||
| NIST SP 800-63 | SP 800-63B — Authentication | Passwordless and MFA choices map directly to digital authentication assurance guidance. |
| Recommendation — Align authentication methods to assurance levels that reduce replayable secret dependence. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about how authentication strength affects access permission decisions. |
| Recommendation — Tie access decisions to verified identity and device assurance before granting entitlements. | ||
Key terms
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
- Traditional MFA: A multi-factor login design that still starts with a password and adds another factor such as a code, push approval, or biometric check. It improves security compared with password-only access, but it still inherits the weakness of the first factor when the password remains in the flow.
- Device-bound assurance: Evidence that an access request is tied to a trusted endpoint rather than only to a known secret or user prompt. In practice, this means the device, its protection state, and its local verification mechanisms become part of the trust decision, which is especially important when login risk must be evaluated in context.
- Shared Secret: Any credential or factor that can be known by more than one party and copied or reused, such as a password, OTP, or recovery code. Shared secrets are fragile because once exposed, they can often be replayed to bypass identity controls.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on May 28, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org