By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: SecureAuthPublished October 10, 2025

TL;DR: Traditional MFA still breaks down under fatigue attacks, phishing relays, and user friction, according to SecureAuth, which positions passwordless continuous authentication as a way to combine FIDO2 passkeys, behavioral biometrics, risk-based step-up, and device trust. The real shift is that identity assurance must become session-aware instead of prompt-driven, because repeated challenge loops are easy to abuse and hard for users to sustain.


At a glance

What this is: This is an analysis of why traditional MFA weakens under fatigue and phishing, and how passwordless continuous authentication changes the assurance model.

Why it matters: It matters because IAM teams need authentication controls that reduce prompt abuse without weakening assurance, especially where human access, device trust, and session risk all intersect.

By the numbers:

👉 Read SecureAuth's analysis of passwordless continuous authentication and MFA limits


Context

Traditional MFA was built for a world where each authentication request could be treated as a discrete event. That assumption weakens when attackers can bombard users with prompts, relay credentials in real time, or exploit device and session context faster than the user can reason through the challenge. For IAM programmes, the question is no longer whether MFA exists, but whether the assurance model survives contact with modern attack patterns and user behaviour.

Passwordless continuous authentication moves the control point from one-time approval to ongoing session assurance. That shifts the discussion from isolated login events to how identity is verified across the full session, which is the right lens for workforce access, especially where friction, phishing resistance, and trust in the device all matter together.


Key questions

Q: How should security teams reduce MFA fatigue risk without weakening access control?

A: Security teams should reduce MFA fatigue risk by adding number matching, device binding, prompt throttling, and clear reporting paths for suspicious requests. The goal is to make approval harder to coerce and easier to verify, while also limiting the access a single approved session can reach through least privilege and session controls.

Q: When does passwordless authentication create more risk than it reduces?

A: It creates more risk when organisations adopt it without strong device governance, fallback controls, or recovery rules. If an attacker can steal a token, hijack a mobile device, or abuse a weak reset flow, the organisation has simply moved the problem from passwords to another credential path.

Q: What are the signs that MFA is failing in practice?

A: Repeated prompt approvals, rising help desk complaints about login fatigue, unexpected approvals from unusual locations, and successful phishing relays all indicate that the control is being treated as a ritual rather than a safeguard. If users approve challenges reflexively, the system is already under behavioural attack, even if the factor itself has not technically broken.

Q: What is the difference between MFA and continuous authentication?

A: MFA verifies identity at the start of access, usually by requiring more than one factor. Continuous authentication keeps checking risk while the session is active. MFA reduces initial compromise risk, while continuous authentication addresses session drift, hijacking, and context changes that occur after login.


Technical breakdown

Why traditional MFA breaks under prompt fatigue and phishing relay

Traditional MFA assumes that a user will correctly evaluate each challenge at the moment it appears. Fatigue attacks exploit the opposite: repeated prompts condition users to approve without scrutiny. Phishing relay attacks add another weakness by forwarding valid credentials or session challenges in real time, which means the attacker does not need to defeat the factor, only to proxy it. In practice, the control is only as strong as the user’s attention and the channel’s resistance to interception.

Practical implication: reduce reliance on prompt approval alone and treat MFA as one layer inside a broader session assurance model.

How FIDO2 passkeys change the authentication boundary

FIDO2 passkeys bind authentication to a device and origin in a way that is phishing-resistant by design. Unlike shared secrets or one-time codes, the passkey flow does not hand an attacker a reusable credential that can be replayed elsewhere. For identity teams, this changes the threat model from password theft and relay risk to device-held cryptographic assurance. The remaining challenge is governance: passkeys strengthen login assurance, but they do not by themselves solve session hijack, device compromise, or over-trusted endpoints.

Practical implication: prioritise passkeys for high-risk workforce access, but align them with device posture and session monitoring.

Why continuous authentication is really session governance

Behavioral biometrics, risk-based step-up, and device trust only make sense when they are used to reassess identity during the session, not just at sign-in. Continuous authentication means the system keeps evaluating whether the current user, device, and context still match the expected pattern. That is different from static MFA because the decision is not a single gate but an ongoing policy process. In identity architecture terms, it is closer to adaptive assurance than to conventional login verification.

Practical implication: design policy to re-evaluate high-risk actions mid-session, especially for privileged or sensitive workflows.


Threat narrative

Attacker objective: The attacker wants to obtain authenticated access that looks legitimate enough to move through the environment without triggering immediate suspicion.

  1. Entry begins with repeated MFA fatigue prompts or a real-time phishing relay that captures the user’s approval path.
  2. Escalation occurs when the attacker reuses the authenticated session or bypasses the user’s attention through a trusted-looking login flow.
  3. Impact follows when the attacker operates inside the session with legitimate-looking access, making detection harder than a simple password compromise.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Traditional MFA is no longer a stable control assumption when authentication can be socially engineered in-session. Fatigue attacks and relay attacks do not merely bypass a factor, they exploit the fact that the approval step is still tied to a human moment of judgment. That makes the control operationally brittle in high-volume environments. The practitioner takeaway is that assurance design must account for adversarial timing, not just factor strength.

Passwordless access changes the authentication problem from secret verification to device-bound trust. FIDO2 passkeys remove the reusable credential from the attacker’s path, which closes off one of the most common phishing outcomes. But that does not eliminate the need for session controls, because a strong login can still lead to a weak session if the endpoint or browser context is compromised. Identity teams should treat passwordless as an enabling control, not a complete boundary.

Continuous authentication is best understood as identity governance inside the session. Behavioral biometrics, device trust, and risk-based step-up are most effective when they continuously test whether the session still deserves its level of confidence. This is a better fit for modern workforce access than repeated static prompts, because it aligns control strength with changing context. The implication for IAM architecture is a move toward adaptive assurance and away from one-time gatekeeping.

Adaptive authentication closes the user-friction gap only if policy is tuned to actual risk, not to convenience alone. Overuse of step-up creates fatigue of a different kind, while underuse leaves high-value actions exposed. The challenge for identity leaders is to calibrate trust signals so that strong authentication remains usable at scale. That makes policy design and telemetry quality as important as the factor choice itself.

From our research:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which means identity teams still struggle to see the full credential estate.
  • That visibility gap makes the case for Top 10 NHI Issues stronger, because broken identity hygiene compounds every access-control decision.

What this signals

Passwordless will not fix governance by itself: the operational win comes when identity teams combine phishing-resistant login with session-level assurance and clear step-up policy. That is why the control conversation is moving from authentication events to trust management across the full access journey.

The broader signal for IAM programmes is that user friction is now a security variable, not just a usability complaint. When authentication becomes too predictable or too noisy, attackers exploit the pattern and users normalise the prompt, which weakens assurance from both ends.

Teams that already track Ultimate Guide to NHIs , Key Challenges and Risks should apply the same discipline to human access journeys, because poor identity hygiene in one domain often predicts weak governance in the other.


For practitioners

  • Replace prompt-heavy MFA with phishing-resistant passkeys where possible Start with workforce applications that have the highest phishing exposure and the most repeated prompt burden. Migrate those populations first, then measure whether help desk resets, approval fatigue, and login complaints fall together.
  • Tune risk-based step-up around sensitive session actions Trigger additional verification for privilege elevation, payment changes, export activity, and access to regulated data rather than at every login. This keeps assurance tied to risk while avoiding constant prompts on low-risk interactions.
  • Use device trust as a policy input, not a binary trust claim Treat verified device state as one signal among several, including location, behaviour, and application context. Reassess trust whenever the session changes materially, especially on unmanaged or shared endpoints.
  • Instrument fatigue and relay indicators in identity telemetry Track prompt frequency, repeated denials, impossible approvals, and abnormal step-up patterns so teams can distinguish user friction from active abuse. Pair those signals with response playbooks for account containment.
  • Review privileged user journeys separately from standard workforce flows Administrators and sensitive-role users need different assurance thresholds because their sessions create higher blast radius. Separate policy paths reduce both over-challenge and under-protection.

Key takeaways

  • Traditional MFA is vulnerable when attackers can exploit fatigue, relay, and prompt habituation rather than defeating the factor outright.
  • Passkeys, device trust, and continuous session evaluation shift assurance from a one-time login check to an ongoing trust model.
  • Identity teams should treat authentication design as a governance problem, because the real risk is predictable approval behaviour inside trusted sessions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-7Continuous authentication maps to ongoing access verification and trust reassessment.
NIST SP 800-53 Rev 5IA-2Authentication assurance and step-up controls are central to this article.
NIST Zero Trust (SP 800-207)Section 2.1The article aligns with continuous verification and session trust principles.
NIST SP 800-63SP 800-63BPasskeys and authentication strength directly connect to digital identity assurance.

Apply IA-2 to strengthen initial and ongoing user authentication for sensitive workforce access.


Key terms

  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Continuous authentication: A model where access is re-evaluated after the initial login instead of being trusted for the full session. It uses live signals such as posture, telemetry, and policy to detect when a session should be stepped up, constrained, or revoked.
  • MFA Fatigue Attack: An MFA fatigue attack is a social engineering technique that bombards a user with repeated authentication prompts until they approve one out of annoyance, confusion, or urgency. The attacker usually starts with stolen credentials, then uses the approval flow itself to obtain access.
  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.

What's in the full article

SecureAuth's full article covers the operational detail this post intentionally leaves for the source:

  • How SecureAuth positions FIDO2 passkeys, behavioural biometrics, and device trust inside its Continuous Authority model.
  • The way its risk-based step-up logic is intended to reduce prompt fatigue while preserving stronger verification for higher-risk actions.
  • Product-level framing of workforce and industry-specific deployment paths for financial services and healthcare.
  • The vendor's own explanation of how continuous verification is meant to fit into broader identity and access workflows.

👉 SecureAuth's full article covers the product framing, deployment context, and control design details behind continuous authentication.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org