By NHI Mgmt Group Editorial TeamBased on Axiad: “The Path to Passwordless, Phishing-Resistant MFA: Emerging but Still a Long Road Ahead” (August 6, 2025)

TL;DR: 93% of organisations still use passwords for business, even as 45% plan to adopt passwordless technology and 27% plan phishing-resistant MFA within the next year, signalling a slow shift away from credential-based risk, according to Axiad’s 2023 State of Authentication Survey. Passwords remain the weak link because AI-assisted phishing still outpaces governance and adoption friction, according to Axiad.


At a glance

What this is: Axiad’s survey shows phishing-resistant MFA and passwordless authentication are gaining traction, but password usage remains the default in most organisations.

Why it matters: IAM teams should treat the gap between stated intent and actual authentication practice as a governance problem, not just a technology preference, because passwords continue to anchor credential risk.

By the numbers:

  • 93% of respondents are still using passwords for business.
  • 45% said they will use passwordless technology over the next year.
  • 27% said they will use phishing-resistant multi-factor authentication over the next year.
  • 52% have fallen victim to a password-based cyberattack.

Context

Password-centric authentication remains a governance liability because it preserves a reusable secret at the centre of access decisions. In NHI and human identity programmes alike, that creates an attack path that phishing, credential stuffing, and replay can still exploit even when other layers exist.

Axiad’s survey points to a familiar gap between strategy and execution. Organisations say they want passwordless and phishing-resistant MFA, but change anxiety, legacy replacement risk, time, and staffing constraints still keep passwords in place.

The primary issue is not a lack of awareness. It is that authentication programmes still optimise for continuity of access rather than resistance to modern credential attack patterns.


Key questions

Q: What should security teams do first when they still rely on password-only authentication for some resources?

A: The first move is to identify the most sensitive applications and administrative accounts, then require MFA there before expanding broadly. Password-only access leaves organisations exposed because stolen credentials remain enough for entry. Teams should pair rollout with user-friendly enrollment, clear policy enforcement, and a plan to replace telephony-based methods with stronger options.

Q: Why do passwords remain such a common authentication weakness?

A: Passwords remain weak because they depend on human memory, user discipline, and secrecy under attack pressure. They are often reused, guessed, phished, or stolen. Once that happens, the control no longer verifies identity reliably. That is why password-only access is still a frequent point of failure.

Q: What are the signs that an authentication modernisation effort is stalling?

A: Common signs include high password exception rates, limited enrolment outside a pilot group, repeated help desk fallback to legacy sign-in, and delayed recovery design. If users still depend on passwords for most business access after a rollout, the programme has not yet displaced the old trust model.

Q: How should organisations implement phishing-resistant MFA for regulated access?

A: Start by mapping each protected system to the identity type that uses it, then choose a phishing-resistant method that fits that subject. Use passkeys for human login where appropriate, certificate-based authentication for machine or enterprise trust, and verify that enrollment, recovery, and revocation are part of the control, not afterthoughts.


Technical breakdown

Why passwords still anchor authentication risk

Passwords remain attractive to attackers because they are reusable, widely understood, and easy to phish at scale. Even when MFA exists, password-first designs leave a primary secret in the authentication chain, and that secret can be harvested through email phishing, adversary-in-the-middle techniques, or credential reuse from other breaches. Passwordless and phishing-resistant MFA change the structure of the attack by reducing reliance on a shared secret and binding authentication more tightly to a device or cryptographic credential. The security gain is real, but only when the organisation actually removes password dependence from the critical path.

Practical implication: prioritise authentication flows that remove reusable secrets from primary login paths, not just add another factor.

Why adoption slows even when the risk is obvious

The article shows that adoption barriers are mostly operational: fear of change, rip-and-replace concerns, time pressure, and limited staff. That matters because authentication is not a single control swap; it is a migration across IdP configuration, endpoint readiness, user enrolment, recovery processes, and exception handling. If those dependencies are not planned, teams default to the familiar mechanism, which is the password. From an IAM perspective, this is a programme design issue, not a user preference issue.

Practical implication: treat passwordless deployment as an operating model change, with migration sequencing and rollback planning.

Phishing-resistant MFA as a control against credential theft

Phishing-resistant MFA is designed to make authentication harder to relay or reuse by binding the user to a cryptographic authenticator rather than a recoverable password. That is why regulators and guidance bodies continue to push it: it reduces the chance that a successful phishing interaction becomes durable account compromise. In practice, this is most valuable where accounts access sensitive data, admin functions, or high-volume business workflows. The control is strongest when paired with device trust, conditional access, and strong recovery governance, because attackers often move to the weakest adjacent path once passwords are removed.

Practical implication: focus phishing-resistant MFA first on privileged, sensitive, and externally exposed accounts.


Threat narrative

Attacker objective: The attacker wants durable account access that can be reused for impersonation, data access, or lateral movement.

  1. Entry begins with AI-assisted or traditional phishing that captures a password or convinces a user to disclose authentication data.
  2. Credential harvesting succeeds because the password remains a reusable secret that can be replayed or combined with weak MFA flows.
  3. Impact follows when the attacker uses the compromised account to access systems, impersonate the user, or establish a broader intrusion path.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Password dependence is now a governance failure, not a user convenience issue. The survey shows that most organisations still run authentication through reusable secrets even while they acknowledge the threat. That creates a control model built around compromise recovery instead of compromise resistance. The practitioner conclusion is simple: authentication strategy must be judged by attacker resilience, not by how familiar it feels to users.

Phishing-resistant MFA only matters when it is treated as a default control boundary. If it is reserved for a few privileged users while the rest of the estate stays password-based, the organisation preserves the same attack surface with a thinner wrapper. The right governance question is where credential replay would be most damaging and where password removal changes the risk profile most materially.

Fear of change is the hidden control gap in authentication programmes. The article makes clear that adoption friction is often organisational, not technical. That means the real blocker is usually migration governance, exception management, and recovery design, not the absence of product capability. The practitioner takeaway is that authentication modernisation must be managed as a transition programme.

Zero Trust authentication cannot coexist comfortably with password-first habits. Zero Trust assumes continuous verification and reduced trust in static credentials, but password-based workflows preserve the very secret most likely to be phished or reused. The implication for identity architects is that authentication architecture and access policy have to move together, or the trust model remains undermined.

Credential attack economics still favour the attacker when passwords remain the default. Generative AI lowers the cost of convincing phishing content, while passwords keep the compromise path reusable. That combination widens the window between awareness and actual control change. Practitioners should interpret rising phishing-resistant MFA interest as evidence of overdue architectural correction, not as proof the problem is closing.

From our research library:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

What this signals

Authentication modernisation fails when programme design stops at feature deployment. Passwordless and phishing-resistant MFA only change risk if recovery, enrolment, and exception handling are redesigned around them. Otherwise the organisation simply adds a modern path beside the old one and keeps the same exposure.

Identity teams should treat phishing-resistant MFA as a control boundary, not a branded capability. The important question is where reusable credentials still exist in the access journey and which populations face the highest replay risk. That lens helps security leaders decide where to invest first and where legacy authentication is no longer defensible.


For practitioners

  • Prioritise passwordless migration for high-risk populations Start with privileged users, remote access, and systems that expose sensitive business workflows. Those populations create the highest payoff when reusable passwords are removed first.
  • Require phishing-resistant MFA for sensitive access paths Use phishing-resistant methods for administrators, finance, HR, and externally exposed applications where credential replay would have the highest impact.
  • Inventory password recovery and exception paths Map every recovery route, bypass, and legacy exception that still depends on passwords, because those paths often preserve the old risk even after a modern login is added.
  • Plan identity migrations as change programmes Sequence enrolment, communications, fallback authentication, and help desk readiness together so adoption barriers do not force teams back to password defaults.

Key takeaways

  • Passwords still dominate authentication even as organisations say they plan to move toward passwordless and phishing-resistant MFA.
  • The biggest blockers are organisational and operational, including change resistance, legacy replacement concerns, time pressure, and staffing limits.
  • The control value comes from removing reusable secrets from the highest-risk access paths first and redesigning recovery around the new model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-63, NIST Zero Trust (SP 800-207), NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationThe article centres on authentication methods and phishing-resistant MFA adoption.
Recommendation — Align authentication policy to SP 800-63B by prioritising phishing-resistant authenticators over reusable passwords.
NIST Zero Trust (SP 800-207)Principle of continuous verification — Continuous VerificationThe article frames passwordless adoption as part of stronger verification and reduced trust in static credentials.
Recommendation — Use continuous verification principles to reduce reliance on static password-based trust signals.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe survey is about access authentication and how organisations grant entry to business systems.
Recommendation — Review access authorisation paths to remove password dependence from sensitive authentication flows.
CIS Controls v8CIS-5 — Account ManagementPassword and MFA migration touches account lifecycle, exception handling, and access governance.
Recommendation — Tighten account management processes so legacy password exceptions do not persist indefinitely.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationPassword-based machine and service authentication remains a central non-human identity weakness in the article's theme.
Recommendation — Replace weak secret-based authentication for non-human identities with stronger, phishing-resistant patterns where possible.

Key terms

  • Phishing-Resistant MFA: Phishing-resistant MFA uses authentication factors that cannot be easily replayed, intercepted, or socially engineered. In regulated environments, this usually means device-bound or cryptographic methods rather than push prompts or SMS codes, because the control must hold up under realistic attack conditions.
  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Authentication migration: The controlled shift from one access method to another, usually from password-based sign-in to stronger authentication. In practice, the hardest parts are enrolment, fallback recovery, exception handling, and user adoption rather than the new login technology itself.
  • Credential-driven attack: A credential-driven attack uses valid, stolen, reused, or exposed credentials to gain access and move through a system. These attacks often bypass exploit-based controls because the activity is authenticated, which makes identity quality, privilege scope, and secrets hygiene central to detection and containment.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org