TL;DR: Passwordless adoption is accelerating, but credential issuance and lifecycle friction still drive help-desk load, policy workarounds, and delayed access, according to Axiad and Gartner figures cited in the post. The governance problem is not password removal alone, but whether organisations can issue, enroll, and manage new credentials without creating shadow workarounds.
At a glance
What this is: This is an analysis of why passwordless programmes still break down at credential issuance, with the key finding that user friction, not authentication theory, becomes the limiting factor.
Why it matters: IAM teams, IGA leads, and PAM practitioners need to treat enrolment and lifecycle usability as part of authentication design, because friction at issuance drives workarounds, tickets, and weaker control adherence.
By the numbers:
- By 2022, Gartner predicted that 60% of global companies would use passwordless solutions to authenticate their users and devices, and 90% of mid-size businesses would.
- 92% of CISOs predicted that passwordless was the future of authentication.
- Credential issues led to over 40% of users’ help desk calls.
Context
Passwordless authentication replaces passwords with other authenticators such as mobile authenticators, hardware tokens, smart cards, or device-bound methods. The governance problem is not simply whether the new factor is stronger, but whether users can issue, enrol, and maintain it without creating friction that pushes them back to unsafe workarounds.
Axiad’s argument is that passwordless programmes fail when credential lifecycle management becomes too complex for users to navigate on their own. That matters for human IAM because the authentication layer is only as strong as the enrolment and recovery experience that surrounds it, especially when staff need multiple credentials for different use cases.
The article frames this as a usability problem with security consequences: if users cannot issue or update credentials quickly, they call the help desk, lose productive time, or bypass policy. In other words, passwordless success depends on reducing operational friction around identity proofing, enrolment, and recovery, not just removing the password field.
Key questions
Q: How should organisations reduce friction in passwordless credential enrolment?
A: Start by simplifying the enrolment journey into a small number of consistent steps, then make routine issuance and recovery self-service where the assurance model allows. Users are far more likely to follow authentication policy when the path to a usable credential is fast, familiar, and visible inside one portal rather than spread across multiple tools.
Q: Why do passwordless programmes still need strong help desk controls?
A: Passwordless programmes still need strong help desk controls because recovery workflows often become the easiest way to defeat authentication. If a help desk can reset access or re-enrol a device without robust verification, the attacker does not need to break the login method. The help desk becomes a privileged identity gateway that must be governed like one.
Q: What are the signs that a passwordless access programme is failing to reduce friction?
A: Common warning signs include repeated helpdesk requests, slow onboarding for new users, separate recovery steps for different systems, and continued reliance on passwords or manual overrides. If users still need multiple credentials for doors, desktops, and apps, the programme has not removed enough operational complexity. A weak programme should also show inconsistent policy enforcement across user groups.
A: Passwordless changes the control surface, but it does not eliminate governance requirements around identity proofing, enrolment, recovery, and lifecycle management. The key difference is that the security outcome now depends more heavily on whether users can complete those steps without friction, support dependency, or policy workarounds.
Technical breakdown
Why passwordless still depends on credential issuance workflows
Passwordless is not a single factor. It is a collection of credential types and trust mechanisms, such as mobile authenticators, smart cards, USB tokens, TPMs, and hardware keys, each with its own enrolment and management path. When those paths are fragmented across separate platforms, users must switch interfaces, remember different steps, and handle device-specific requirements. That is where the control breaks down: the authentication method may be strong, but the workflow around it becomes the weak point. The article’s key technical point is that lifecycle usability is part of the security design, not an afterthought.
Practical implication: Practitioners need to treat enrolment and update flows as part of authentication architecture, not separate support processes.
How lifecycle friction creates shadow behaviour and help-desk dependence
When users cannot issue or refresh credentials quickly, two predictable outcomes follow. First, they open support tickets and wait for IT to complete tasks that should have been self-service. Second, they look for shortcuts that let them keep working, which can mean bypassing policy or using the wrong credential for the job. The article ties this directly to control failure because authentication policy only works when users can follow it under time pressure. In practice, that means the more steps a credential lifecycle requires, the more likely the organisation is to see workaround behaviour and avoidable downtime.
Practical implication: Design self-service issuance and recovery to reduce ticket volume and policy bypass pressure.
Why user-centric design is part of identity assurance
User-centricity in passwordless does not mean weaker security. It means the journey from proofing to enrolment to daily use has to be understandable and fast enough that people will actually follow it. The article’s example of one-click issuance shows the intent: give users a familiar portal, limit the steps, and tie the credential to a clear trust action such as PIN creation or device presence verification. That preserves assurance while reducing the cognitive and operational burden that causes abandonment. If the experience is too hard, the programme creates its own resistance.
Practical implication: Align assurance requirements with a simple user journey so the control is usable enough to be adopted consistently.
NHI Mgmt Group analysis
Passwordless programmes fail when issuance is harder than authentication itself: The market often treats passwordless as a factor replacement problem, but the article shows the real constraint is lifecycle experience. If users cannot enrol, refresh, or recover credentials quickly, the control becomes operationally brittle. The practitioner conclusion is simple: authentication strength does not survive a broken issuance journey.
Credential lifecycle usability is now part of identity governance: When a workforce relies on multiple credential types, governance has to cover how each one is issued, updated, and recovered, not just whether it exists. That shifts attention from factor selection to service design, because a credential that is technically strong but operationally confusing drives support load and policy drift. Teams should treat lifecycle friction as a governance defect, not a user-training problem.
Single-portal issuance creates a clearer control boundary: The article’s one-click model illustrates a broader governance pattern for human IAM, where familiar access paths reduce the temptation to bypass security steps. That does not remove the need for proofing or device checks. It does, however, show that security controls work better when the user journey is consistent enough to be followed under pressure. Practitioners should measure success by completion rate, not just by factor strength.
Hidden friction is the real adoption blocker in passwordless rollouts: Organisations often assume users resist passwordless because of preference, but the article points to process burden instead. If the path to a credential feels like a project rather than a routine task, adoption slows and shadow behaviour grows. The implication is that passwordless strategy must be evaluated as an access experience programme, not only as an authentication architecture decision.
What this signals
Identity friction is now an adoption risk, not just an experience issue: Passwordless programmes that overlook issuance and recovery end up shifting cost into support, downtime, and policy exceptions. The practical test is whether users can complete the credential journey fast enough to avoid needing workarounds.
Lifecycle design has become part of authentication assurance: For human IAM, the control is only credible when issuance, enrolment, and recovery are simple enough that users can follow them under pressure. That makes lifecycle experience a core governance measure, not a convenience feature.
For practitioners
- Standardise credential issuance journeys Consolidate enrolment flows into a small number of consistent paths so users do not have to learn separate workflows for each authenticator type.
- Reduce help-desk dependence for enrolment and recovery Make common credential updates self-service where assurance requirements allow, so users can complete routine identity steps without waiting for IT.
- Map credential types to clear use cases Assign mobile authenticators, hardware keys, smart cards, and device-bound methods to the access scenarios they actually support, then document those choices for users.
- Measure friction as an adoption signal Track failed enrolments, ticket volume, abandoned updates, and policy bypass behaviour so identity teams can see where passwordless is breaking down.
Key takeaways
- Passwordless adoption can still fail when credential issuance and lifecycle handling are too complex for ordinary users to complete without assistance.
- The article links credential problems to help-desk pressure, productivity loss, and policy bypass behaviour, showing that friction is an operational security issue.
- Teams should evaluate passwordless rollouts by enrolment simplicity, recovery success, and user adherence, not by factor strength alone.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63C — Federation | Passwordless issuance and enrolment sit within federated digital identity flows for users and devices. |
| Recommendation — Align passwordless enrolment journeys with federated identity controls so users can complete issuance without support friction. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article focuses on who can obtain and use credentials for access, which ties to authorisation management. |
| Recommendation — Apply PR.AA-05 to ensure credential issuance and access entitlement decisions stay consistent across user journeys. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential issuance, update, and lifecycle handling map directly to authenticator management controls. |
| Recommendation — Use IA-5 to govern authenticator lifecycle steps that affect enrolment, replacement, and recovery. | ||
| OWASP ASVS | V6 — Authentication | The article concerns authentication experience and control design for passwordless user access. |
| Recommendation — Use V6 to verify that authentication flows remain usable enough for users to complete without unsafe workarounds. | ||
Key terms
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
- Credential issuance: The process of creating, enrolling, and binding a credential to a user, device, or account. In mature identity programmes, issuance is a governed control point, not a convenience step, because it determines who can obtain access, how assurance is established, and how recovery is handled.
- Lifecycle Friction: Lifecycle friction is the delay and manual effort created when access cannot be provisioned, escalated, or revoked quickly. It is not just an operational inconvenience. It increases labour cost, slows delivery, and leaves privileged access exposed for longer than the business need justifies.
- Identity Assurance: The confidence an organisation has that a person or system is truly who it claims to be before access or action is granted. In modern IAM, assurance depends on evidence quality, channel trust, and the strength of verification around high-risk decisions.
Deepen your knowledge
Identity lifecycle management, secrets management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 12, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org