By NHI Mgmt Group Editorial TeamBased on Axiad: “Say Goodbye to Passwords for Good, Your Employees Will Thank You” (September 16, 2025)

TL;DR: Password-based authentication problems are stopping 60% of US workers from doing their jobs, while just under 60% have contacted IT after being locked out, according to Axiad’s survey of 2,000 office workers. Passwordless only works when the user journey is simpler than the old one, not when it adds another layer of friction.


At a glance

What this is: This article argues that legacy password and MFA journeys still create friction, productivity loss and support burden, and that passwordless only helps when it reduces that friction.

Why it matters: IAM teams need to treat authentication experience as a security control, because adoption fails when users bypass or work around controls that make access harder instead of safer.

By the numbers:

  • 60% of US workers surveyed said password problems had stopped them from doing their jobs.
  • just under 60% said they had to contact the IT department because they were locked out of their computer.

Context

Passwordless authentication is the move away from reusable passwords toward methods such as phishing-resistant credentials, PKI-backed login and centrally managed authenticators. The security problem is not only whether the method is stronger, but whether the user can actually complete access without creating new failure points.

Axiad's argument is that many organisations keep layering authentication controls on top of a brittle user journey. When employees cannot easily understand, remember or recover their login path, they either fall back to older credentials, call support, or bypass the intended control.

That makes authentication design part of IAM governance, not just a help desk issue. For human identity programmes, the question is whether passwordless reduces friction enough to change behaviour at scale rather than simply adding another control surface.


Key questions

Q: How should IAM teams implement passwordless authentication without breaking customer journeys?

A: Start with hybrid deployment in new or low-risk flows, then expand to existing journeys once recovery, fallback, and step-up rules are proven. The goal is not to remove passwords overnight but to reduce their role while preserving login success, support stability, and user trust.

Q: Why do passwordless programmes still need strong lifecycle governance?

A: Passwordless shifts risk from passwords to issuance, recovery, and revocation. If those lifecycle steps are slow or unclear, users lose access, request exceptions, or reuse weaker paths to keep working. Strong lifecycle governance keeps the credential trusted throughout its usable life, not just at initial enrolment.

Q: What are the signs that password-only authentication is failing in practice?

A: Password-only authentication is failing when a valid password is enough to grant access from an unusual place, device, or time without any additional checks. Warning signs include successful logins from unfamiliar geographies, unmanaged devices, odd hours, and repeated alerts that arrive only after access has already been attempted or achieved.

Q: What should organisations do when multiple MFA methods confuse employees?

A: Reduce the number of authentication paths users must navigate and make the recovery process consistent across applications and devices. Fragmented MFA increases mistakes and pushes users toward convenience behaviour. A single operating model is easier to support, easier to govern and more likely to be adopted.


Technical breakdown

Why passwordless adoption fails when recovery is harder than login

Passwordless schemes often fail at the recovery and support layer, not the primary login step. If a user loses a device, cannot reach the mobile authenticator, or is unsure which system owns the credential, the organisation has replaced one friction point with another. That creates shadow workarounds, repeated help desk escalations and lingering dependence on old credentials. The technical issue is not password removal alone, but the completeness of the authentication journey across enrolment, recovery, device change and support.

Practical implication: map the full login and recovery path before you retire passwords.

Multiple MFA methods can fragment the authentication experience

Many organisations deploy several MFA systems without creating a single operating model for users. That means the employee must know which factor, app or recovery process applies in each context, which increases mistakes and lockouts. From an identity governance perspective, fragmented authentication undermines assurance because users choose convenience paths that may not align with policy. The control problem is not only assurance strength, but consistency of the user experience across devices, applications and support channels.

Practical implication: standardise authenticator policy and recovery flows across the enterprise.

Passwordless still depends on centralised credential management

Passwordless does not remove identity governance; it changes the assets being governed. Phishing-resistant authentication, PKI and centrally managed credentials still need issuance, lifecycle control, reporting and revocation. Without central visibility, organisations can end up with orphaned authenticators, inconsistent enrolment states and weak recovery assurance. The architecture therefore shifts from password management to credential lifecycle management, where the integrity of the authentication system depends on inventory, policy and reporting discipline.

Practical implication: treat passwordless as a credential lifecycle programme, not a UI change.


NHI Mgmt Group analysis

Authentication friction is now an identity governance signal, not just a usability complaint. When employees cannot complete access quickly and confidently, they compensate with workarounds, old credentials or support tickets. That behaviour tells security teams the control is failing at the human boundary, where policy meets actual use. Practitioners should read friction as a sign that authentication design and governance are out of alignment.

Passwordless changes the control objective from memorised secrets to managed authentication journeys. The point is not to replace one factor with another, but to remove the dependency on reusable credentials that users can forget, reuse or circumvent. That makes enrolment, recovery and re-issuance the real governance surface. The implication is that IAM teams need to measure whether the journey is simpler before they claim security improvement.

Multiple MFA tools can erode assurance when the user does not know which control path applies. A fragmented stack pushes people toward convenience-based behaviour, which weakens the practical effect of policy. This is a governance problem because the organisation has technically deployed control without producing consistent user execution. Practitioners should collapse authentication sprawl into a coherent operating model rather than adding more options.

Centralised credential management is the hidden requirement behind passwordless adoption. Passwordless still depends on inventory, issuance, revocation and reporting for each authenticator type, including people and machines. That is where identity assurance is either sustained or lost. The practical conclusion is that passwordless belongs inside lifecycle governance, not outside it.

Identity journey simplification: The concept that matters most here is whether authentication reduces effort across login, recovery and support in one coherent path. If it does not, the organisation has not removed friction, only redistributed it across more systems and more help desk demand. Practitioners should evaluate passwordless by journey coherence, not by factor count.

From our research library:

  • According to Forrester Research, a single password reset can cost around $70.

What this signals

Identity journey simplification: Passwordless adoption should be judged by whether it reduces the total effort required to enrol, authenticate and recover access. If users still need support to find the right path, the programme has shifted rather than solved the problem.

Authentication controls now influence productivity as much as security posture. When employees are blocked by confusing login paths, the business absorbs the cost in lost time, repeated tickets and bypass behaviour.

The next maturity step is not just stronger factors. It is governance over the complete authentication journey, from issuance through recovery, so the user experience and the control model reinforce each other.


For practitioners

  • Standardise the authentication journey Design one coherent path for enrolment, login, device change and recovery so users are not forced to guess which system owns their credential.
  • Remove fallback to older credentials Retire legacy password paths once passwordless coverage is stable enough that users do not need a workaround to keep working.
  • Consolidate MFA support models Document which authenticator, app and recovery workflow applies in each scenario so help desk support does not become the hidden control plane.
  • Govern credentials centrally Track issuance, recovery, revocation and reporting for every passwordless authenticator as part of identity lifecycle management.
  • Measure user friction before migration Use lockout rates, support tickets and bypass behaviour to decide whether the new authentication journey is actually simpler than the old one.

Key takeaways

  • Passwordless authentication does not fix IAM problems unless it removes friction from the full user journey, including recovery and support.
  • Survey evidence in the source article shows that password issues still interrupt work and drive IT contact at material rates.
  • The decisive control question is whether authentication governance is simple enough that users follow it without fallback behaviour.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationThe article centres on human authentication experience and passwordless login flows.
Recommendation — Apply SP 800-63B to validate authentication choices and recovery paths for human users.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsPasswordless still depends on governed access and consistent authentication decisions.
Recommendation — Use PR.AA-05 to keep authentication and entitlement rules aligned across access paths.
ISO/IEC 27001:2022A.5.15 — Access controlThe article is about access control design and user access governance.
Recommendation — Use A.5.15 to define consistent access control rules for passwordless adoption.

Key terms

  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Authentication Friction: The delay, confusion, and support burden created when users cannot complete sign-in cleanly. In IAM programmes, friction is a governance signal because it drives resets, exceptions, and workarounds. If users routinely hit the recovery path, the authentication design is not yet operationally stable.
  • Credential Lifecycle: Credential lifecycle is the process of issuing, rotating, expiring, and revoking secrets, certificates, and tokens across their usable life. For non-human identities, lifecycle discipline is the core control that separates temporary access from persistent exposure.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org