TL;DR: Authentication processes stopped 60% of 2,000 US office workers from doing their job, while 59% had contacted IT after being locked out and 15% said fixes took nine hours or longer, according to Axiad’s survey. The pattern shows authentication friction is now a productivity and governance problem, not just a user experience complaint.
At a glance
What this is: Axiad’s survey shows password-based authentication is creating measurable productivity loss, with most respondents reporting job disruption, lockouts, and long repair times.
Why it matters: IAM teams need to treat authentication friction as an operational control problem because password bottlenecks drive support demand, interrupt work, and weaken the case for better authentication methods.
By the numbers:
- 60% of US workers surveyed said authentication processes had stopped them from doing their jobs.
- 59% had contacted IT because they were locked out of their computer.
- 15% said it took nine hours or longer to fix authentication issues at their workplace.
Context
Passwords are a human identity control, but they become a governance problem when routine authentication interrupts work, drives IT tickets, and creates long recovery delays. In this survey, the primary issue is not whether passwords are familiar, but whether they still fit a workforce that depends on continuous access to applications and communication tools.
Axiad’s survey of 2,000 US office workers points to a widening gap between authentication policy and day-to-day usability. The results show that password dependence is not only burdensome for users, it also creates avoidable operational friction for IAM teams that have to absorb lockout and reset demand.
Key questions
Q: How should IAM teams reduce password-related productivity loss?
A: They should start by measuring where password failures interrupt work most often, then redesign the highest-friction journeys first. That means stronger recovery flows, clearer enrolment, and expanding phishing-resistant methods where business impact is highest. If the programme cannot show reduced lockouts and faster restoration, the control change has not yet improved identity operations.
Q: Why do password-based authentication problems create so much productivity loss?
A: Because a failed password is rarely a single event. It often triggers a reset, a help desk ticket, and a delay before work can resume, which turns identity friction into lost time. The longer the recovery path, the more the authentication model behaves like an operational bottleneck.
Q: What are the signs that password friction is becoming a governance problem?
A: Rising lockout tickets, repeated reset requests, and long time-to-recover metrics are all signs that authentication is undermining availability. If workers regularly lose access to core applications or communication tools, the identity programme is no longer just protecting access; it is disrupting it.
Q: Should organisations replace MFA with passwordless authentication?
A: Organisations should not treat this as a simple replacement question. MFA is still useful where passwordless is not yet available, but passwordless raises the security baseline by removing the password as the primary failure point. The right path is to use MFA as a bridge and passwordless as the destination.
Technical breakdown
Why password lockouts become a productivity control failure
Password lockouts turn authentication into a business interruption because the user cannot prove identity, regain access, or continue work until a reset or recovery step succeeds. In IAM terms, the control is functioning as designed, but the workflow around it is brittle: help desk queues, reset delays, and app-specific lockouts convert a single failed login into lost time. When that pattern repeats across a workforce, authentication becomes an availability issue as much as a security one.
Practical implication: Measure lockout frequency and recovery time alongside authentication policy, not as separate service metrics.
Why password-only programmes keep creating support load
A password-only model concentrates risk and friction in one credential type, so forgotten secrets, reuse concerns, and complexity rules all land on the same recovery path. MFA awareness does not help if the organisation still requires passwords for most access flows. That is why workers report annoyance, stress, and memory burden: the process is forcing users to repeatedly solve a problem that modern identity architecture should reduce, not amplify.
Practical implication: Reduce the number of access paths that depend on memorised secrets and track the support load they generate.
Passwordless authentication as an operational design choice
Passwordless authentication is not just a user convenience pattern. It is an IAM design choice that shifts the burden away from memorised secrets and toward stronger authenticators and better recovery governance. For identity teams, the question is whether the current authentication stack preserves productivity while still meeting security objectives. If it does not, the organisation is paying twice: once in user frustration and again in support overhead.
Practical implication: Prioritise authentication methods that cut recovery friction without weakening identity assurance.
NHI Mgmt Group analysis
Password friction is now an IAM governance metric, not a usability complaint. When 60% of workers say authentication stops them doing their jobs, the programme is failing on operational resilience as well as user experience. Identity leaders should treat authentication throughput and recovery friction as measurable governance outcomes, not anecdotal complaints.
Lockouts expose the hidden cost of password-centric identity design. The survey shows that 59% of respondents had contacted IT after being locked out, which means the support model is absorbing costs that modern authentication should remove. Human authentication experience: the identity stack has to account for work interruption, not just login success. That makes passwordless migration a service design issue, not a cosmetic upgrade.
Awareness of MFA does not matter if the organisation still runs on passwords. The survey notes that 67% were aware of MFA, yet 46% said their IT departments had never asked them to use anything other than passwords. That gap shows policy inertia, not user resistance, and it keeps authentication risk and friction coupled. Practitioners should read this as a sign that control choice, not employee education, is the limiting factor.
Password recovery time is the real productivity tax. An average fix time of nearly five hours means the business is losing more than a login event. It is losing a working block, a communication channel, and often a support interaction. The practical conclusion is that authentication governance must be judged by how quickly users return to productive access after failure, not by whether the login page is familiar.
Passwordless adoption is becoming an availability strategy. The survey’s findings suggest that reducing dependence on memorised credentials can cut both user frustration and service desk churn. For IAM and IGA teams, the question is whether the current authentication model is still fit for a workforce that expects fast, continuous access across applications and devices.
From our research library:
- According to Forrester Research, a single password reset can cost around $70.
What this signals
Password-heavy authentication models create their own operational debt. When a workforce spends time resetting access instead of doing work, the IAM programme is carrying hidden productivity loss. Identity teams should expect the cost of authentication friction to surface in support queues, not just in user complaints.
Passwordless should be evaluated as a workload and support reduction strategy. The main benefit is not novelty. It is the removal of repeated failure points that consume help desk capacity and interrupt application access, which is why recovery design matters as much as the authenticator itself.
For practitioners
- Measure authentication friction as a governance metric Track lockout rates, reset volume, and average time to restore access so authentication performance is visible alongside security outcomes.
- Prioritise passwordless journeys for high-friction users Start with roles or populations that generate repeated lockouts and app access failures, then move those flows to stronger authenticators with simpler recovery.
- Reduce reliance on memorised secrets Audit where employees still depend on passwords as the only access method and remove them from the highest-volume workflows first.
- Align help desk metrics with authentication design Treat repeated lockouts and long reset times as signals that the identity design is creating avoidable support load, not just isolated incidents.
Key takeaways
- Password-centric authentication can damage both productivity and identity operations when workers are repeatedly locked out or delayed by recovery steps.
- The survey shows the scale of the problem clearly, with 60% reporting job disruption, 59% contacting IT after lockout, and 15% facing nine-hour-plus fixes.
- IAM teams should treat authentication friction as a programme metric and move the highest-volume access flows toward passwordless design.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Password dependence and recovery delays point to authenticator lifecycle and recovery controls. |
| Recommendation — Apply IA-5 to reduce password dependency and tighten authenticator recovery workflows. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about access friction and authentication outcomes for employees. |
| Recommendation — Review authentication pathways under PR.AA-05 to remove avoidable access bottlenecks. | ||
| NIST SP 800-63 | SP 800-63B — Authentication | The topic centres on workforce authentication methods and their operational impact. |
| Recommendation — Use SP 800-63B to guide stronger authenticators and lower password dependence. | ||
Key terms
- Authentication Friction: The delay, confusion, and support burden created when users cannot complete sign-in cleanly. In IAM programmes, friction is a governance signal because it drives resets, exceptions, and workarounds. If users routinely hit the recovery path, the authentication design is not yet operationally stable.
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
- Lockout Recovery: Lockout recovery is the process used to restore access after a user is blocked from an account or application. It is a critical IAM control because poorly designed recovery creates downtime, support overload, and inconsistent assurance, especially when passwords remain the dominant authenticator.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org