TL;DR: Passwordless adoption still runs into issuance and lifecycle friction because users must juggle multiple credential types, platforms and workflows, according to Axiad. When enrolling or updating a credential is cumbersome, help desk volume rises and users work around policy, so the security gain of passwordless weakens at the point of issuance.
At a glance
What this is: This piece argues that passwordless programmes can fail at the credential issuance stage if users face too many platforms, steps and lifecycle tasks.
Why it matters: IAM teams need to treat issuance and recovery as part of the authentication design, because usability friction can drive help-desk load and policy workarounds.
By the numbers:
- By 2022, Gartner predicted that 60% of global companies would use passwordless solutions to authenticate users and devices, and 90% of mid-size businesses would.
Context
Passwordless authentication removes shared secret dependence, but it does not remove the operational burden of issuing, enrolling and updating credentials. In this article, the identity risk is not authentication itself so much as the user journey required to get a usable credential into service.
The source frames a common IAM problem: organisations may have the right credential types, but they still force users through fragmented portals, device-specific workflows and help-desk dependency. That creates friction in the joiner, mover and recovery lifecycle, which matters just as much for workforce access as the choice of factor.
For IAM and PAM teams, the lesson is simple. Passwordless only scales when credential issuance, recovery and update paths are predictable enough that users do not seek workarounds.
Key questions
Q: What breaks when passwordless credential issuance is too hard for users?
A: When issuance is too hard, users stop following the approved path and start using workarounds, delayed enrollment or repeated help-desk requests. That weakens both security and productivity. Passwordless only delivers value when users can obtain, replace and recover credentials quickly enough that the governed path remains the easiest path.
Q: Why do passwordless programmes still need strong lifecycle governance?
A: Passwordless shifts risk from passwords to issuance, recovery, and revocation. If those lifecycle steps are slow or unclear, users lose access, request exceptions, or reuse weaker paths to keep working. Strong lifecycle governance keeps the credential trusted throughout its usable life, not just at initial enrolment.
Q: How do IAM teams know whether passwordless adoption is actually working?
A: They should look for fewer lockouts, fewer reset requests, shorter time to access, and lower dependence on help desk intervention. Adoption is only successful if the new method is secure and easier for employees to use than the old one. Metrics should show both improved assurance and reduced operational drag.
Q: How should IAM teams reduce friction without weakening MFA controls?
A: Start by removing unnecessary steps, clarifying enrollment and recovery, and making the secure path the easiest path for each user population. Good MFA design reduces effort without reducing assurance. Teams should also measure support tickets, bypass requests, and fallback usage because those signals show whether the control is usable enough to survive in production.
Technical breakdown
Why passwordless credential issuance becomes a lifecycle problem
Passwordless is often discussed as an authentication shift, but the harder problem is lifecycle management across multiple credential types. A user may need a mobile authenticator, a security key, a smart card, or a certificate-backed device depending on the application and access level. Each of those introduces separate enrollment, recovery and replacement workflows. When those workflows are inconsistent, the identity system becomes harder to operate than the password-based model it replaces. The result is not just user confusion. It is a control-plane problem where the success of authentication depends on whether the issuance path is usable enough to complete before the user abandons it.
Practical implication: map credential issuance as a governed lifecycle workflow, not a one-time enrollment event.
How help-desk dependency undermines passwordless adoption
The article’s core operational issue is that users resort to IT when credential issuance is too slow or unclear. That means authentication support becomes a recurring service burden instead of a self-service function. In identity terms, the control fails because the issuance step is not designed for scale. If users cannot recover access or add a new factor without assistance, the programme creates its own outage window. This is especially relevant in distributed and remote work settings, where delays in credential setup translate directly into lost productive time and more pressure to bypass the intended process.
Practical implication: measure issuance and recovery as service metrics, including how often users need assisted enrolment.
Why usability failures create security workarounds
When secure issuance is hard, users look for the fastest path back to work. That can mean ignoring policy, reusing weaker methods, or delaying enrolment altogether. In NHI and human IAM programmes, that behaviour matters because access control only works when the approved path is easier than the unsafe one. The article shows a familiar identity pattern: if the security process is more expensive than the business task, adoption slips and shadow behaviour appears. Passwordless does not eliminate policy drift, it changes where drift shows up. The weak point becomes onboarding and re-issuance rather than login.
Practical implication: design issuance flows so the approved path is faster than any workaround.
Threat narrative
Attacker objective: The practical objective of the failure pattern is to push users toward insecure shortcuts that weaken the organisation’s authentication posture.
- Entry begins with a user needing a new credential or update and encountering a fragmented enrollment path that slows or blocks access.
- Credential access is then diverted into help-desk dependency or user workarounds when the approved issuance process is too complex.
- Impact follows as lost productivity, policy bypass and reduced trust in the passwordless programme when users cannot complete the lifecycle quickly.
Breaches seen in the wild
- Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.
- Twilio 0ktapus breach 2022: SMS phishing of employees exposed 209 Twilio customers and 1,900 Signal users, part of the 0ktapus campaign against 130+ firms.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Credential issuance is the real adoption gate for passwordless: Authentication strategy is only as strong as the user’s ability to obtain and replace the factor in a controlled way. When organisations treat issuance as a side function, they create friction that looks like a usability issue but behaves like an access-control failure. The practitioner conclusion is that passwordless programmes must be judged on issuance success, not just login strength.
Lifecycle complexity is the hidden cost centre in multi-credential environments: The article shows that different devices and platforms create separate operational paths, which increases confusion and support demand. That complexity does not just raise cost, it changes user behaviour by making the governed route feel optional. The practitioner conclusion is that lifecycle simplification is an authentication control, not an administrative convenience.
Help-desk dependency weakens identity assurance: If a user must call IT to recover access, the organisation has turned a self-service identity process into a bottleneck. That bottleneck produces delay, frustration and more tolerance for workarounds, especially under time pressure. The practitioner conclusion is that access recovery must be designed as part of the trust model, not as a back-office exception.
Passwordless friction exposes a governance gap between policy and operability: Security teams often assume users will comply if the factor is stronger, but the article shows that adoption fails when the process is too hard to follow. That is why governance has to account for actual user behaviour and not just policy intent. The practitioner conclusion is that secure authentication must remain operable at scale or it will be bypassed.
Identity attack surface shrinks only when issuance is simple enough to sustain adoption: Passwordless can reduce password risk, but only if the surrounding issuance workflow does not reintroduce friction, recovery debt and support escalation. This is a named design problem: credential issuance friction. The practitioner conclusion is that reducing attack surface requires removing lifecycle drag, not only changing the factor.
What this signals
Credential issuance friction: This is the point where passwordless programmes often lose momentum, because users experience the control as a process problem rather than an authentication upgrade. Organisations that do not simplify enrollment and recovery will keep seeing help-desk dependency and policy drift.
If a workforce cannot add, replace or recover credentials without special handling, the passwordless programme has not really removed friction, it has relocated it. That is why issuance paths need to be designed as part of IAM architecture, not left to separate product workflows.
For practitioners
- Standardise credential issuance flows Reduce the number of enrollment paths users must learn by consolidating device and factor onboarding into one governed workflow for the workforce.
- Design self-service recovery paths Make lost, replaced or updated credentials recoverable without a help-desk ticket wherever assurance requirements allow, so access restoration does not become an outage.
- Measure issuance friction as a control metric Track failed enrollments, assisted enrollments, credential replacement delays and recurring lockouts as signals that the authentication programme is too hard to operate.
- Remove policy-driven workarounds Review the situations where employees bypass the approved factor because the normal route takes too long, then simplify the path before tightening enforcement.
Key takeaways
- Passwordless does not fail at the login screen so much as at the issuance and recovery journey that precedes it.
- The article ties cumbersome credential workflows to help-desk demand, user lockouts and unsafe workarounds.
- IAM teams should treat credential lifecycle design as a core security control if they want passwordless to scale.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B — Authentication | Passwordless issuance and recovery directly affect authentication assurance and usability. |
| Recommendation — Align passwordless enrollment and recovery with SP 800-63B authentication requirements. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Credential issuance determines whether access can be granted and maintained under governance. |
| Recommendation — Use PR.AA-05 to govern credential issuance and authorization workflows. | ||
| CIS Controls v8 | CIS-5 — Account Management | Credential enrollment, recovery and lifecycle handling are account management functions. |
| Recommendation — Apply CIS-5 to standardise account and credential lifecycle handling. | ||
Key terms
- Credential Issuance Friction: The operational burden users face when creating, enrolling, updating or replacing a credential. In passwordless programmes, this friction often decides whether the new authentication model is adopted or bypassed, because users will seek the quickest path back to work when the approved route is confusing or slow.
- Authentication lifecycle: The authentication lifecycle is the full sequence of controls that decide whether an identity is trusted, from sign-up and verification through sign-in, session handling, and recovery. It matters because attackers do not need to beat every control if one stage leaks trust or creates a reusable session.
- Help-Desk Dependency: A condition where routine identity tasks cannot be completed without support intervention. In authentication programmes, high help-desk dependency is a sign that the self-service design has failed, and that users are likely to experience lockouts, delays or policy workarounds.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org