By NHI Mgmt Group Editorial TeamBased on WorkOS: “UX best practices for MFA” (July 23, 2025)

TL;DR: User-friendly MFA design can improve adoption without reducing protection, especially when teams offer multiple enrollment methods, accessible TOTP setup, and low-friction OTP entry and sign-in flows, according to WorkOS. The main governance lesson is that authentication strength fails operationally when users abandon the process, so usability is part of control effectiveness, not a separate concern.


At a glance

What this is: This is a practical guide to MFA UX that argues enrollment and sign-in friction can undermine authentication adoption even when the underlying control is sound.

Why it matters: IAM teams need to treat MFA usability as a governance issue because poor flow design can reduce completion, increase abandonment, and weaken the real-world effectiveness of authentication controls.


Context

Multi-factor authentication only improves identity security when users can complete enrollment and sign-in without friction that causes abandonment. The article focuses on the governance gap between having MFA available and getting consistent user adoption across different devices, accessibility needs, and backup-method scenarios.

The core identity security problem is not whether MFA works in principle, but whether the user journey supports sustained use of the control. That makes enrollment choice, accessible TOTP setup, and clean OTP entry part of IAM design rather than a separate user experience concern.


Key questions

Q: How should security teams design MFA enrollment so users actually complete it?

A: Security teams should offer multiple enrollment paths, make the preferred method easy to set, and keep the process clear from the first screen. Completion improves when users can choose a method that fits their device and accessibility needs. The goal is not more options for their own sake, but fewer points where users abandon setup.

Q: Why do inaccessible MFA flows increase security risk for organisations?

A: When MFA is too hard to use, people look for faster paths around it, including shadow IT, shared workarounds, or unsupported devices. That weakens the control the organisation thought it had in place. Accessibility is therefore a security issue, not just a usability issue, because friction can drive behaviour that creates new attack paths and undermines policy enforcement.

Q: What are the signs that MFA UX is failing in production?

A: Look for incomplete enrollments, repeated OTP retries, users abandoning sign-in, and heavy reliance on backup methods or support tickets. Those signals show the control exists technically but is not being used reliably enough to deliver its intended security outcome.

Q: Should organisations prioritise accessibility in MFA design?

A: Yes, because accessibility is part of authentication reach, not an optional polish layer. If users cannot scan a QR code, read a screen clearly, or enter codes reliably, the factor does not protect the account population it was meant to cover.


Technical breakdown

Flexible MFA enrollment paths

A flexible enrollment flow lets users choose from more than one verification method, such as SMS, email, authenticator apps, or security keys. That matters because MFA adoption fails when the process assumes every user has the same device access or comfort level. Letting users select a primary method and change it later lowers friction without lowering assurance, because the control remains the same while the path to registration becomes more usable. The important design choice is to present all valid options clearly instead of forcing a single path that some users cannot complete.

Practical implication: expose multiple enrollment methods and make primary method selection reversible from account settings.

Accessible TOTP setup and OTP input

TOTP onboarding often fails at the details. QR codes are efficient for many users, but they create barriers for people using screen readers or devices that cannot scan easily, so the secret must also be available as text with proper accessibility support. OTP entry has similar pitfalls: number-only inputs can strip leading zeroes or behave inconsistently across browsers. Using text inputs with numeric hints, autofill support, and live validation preserves the security function while removing avoidable failure points. These are not cosmetic choices; they determine whether users can complete the second factor at all.

Practical implication: provide manual secret entry, accessible labels, and OTP fields that support autofill and numeric input without truncation.

Sign-in step design and backup method switching

The sign-in stage needs to make the MFA step obvious without making it confusing. A dedicated verification screen helps users understand why an extra step exists, while keeping the interface consistent reduces cognitive load. When users have enrolled in more than one factor, the flow should default to the primary method but make backup options easy to reach. That prevents lockouts when a phone is lost or a signal is unavailable. The underlying principle is resilience through graceful method switching, not hidden complexity that users only discover after failure.

Practical implication: add a clear MFA step screen and surface backup methods directly in the sign-in flow.


  • Uber breach 2022: A contractor's stolen password and MFA fatigue gave a Lapsus$-linked attacker Uber's internal tools; Uber rotated keys to many services.
  • Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

MFA usability is a control-effectiveness issue, not a UI preference: The article shows that authentication strength is only meaningful when users can complete the flow consistently. A control that is skipped, abandoned, or worked around because it is hard to use does not deliver its intended security outcome. For identity teams, the real question is whether the MFA journey supports completion at scale, not whether the factor exists on paper.

Enrollment choice is a governance control because one method does not fit every user: Supporting multiple methods recognises that device access, accessibility needs, and user context vary. A single mandatory path creates avoidable friction and can suppress adoption. This is a practical identity design lesson: assurance stays intact when the policy allows more than one approved way to satisfy the factor requirement.

Accessible authentication design closes an identity inclusion gap: QR-only TOTP onboarding and brittle numeric OTP fields exclude users who rely on assistive technology or alternate devices. The issue is not just compliance or convenience; it is whether the organisation has built an authentication process that all intended users can actually complete. That makes accessibility part of IAM programme quality.

Backup-method flexibility reduces lockout risk without weakening the factor model: Users rarely fail MFA because they reject security in principle. They fail when the primary method is temporarily unavailable, the interface obscures alternatives, or recovery is too awkward. The governance implication is that resilience belongs inside the authentication journey itself, not only in help desk procedures after users are already stuck.

MFA adoption should be measured as completion behaviour, not deployment count: Rolling out a factor is not the same as achieving effective authentication control. The more useful operational signal is whether users enrol successfully, switch methods when needed, and complete sign-in without repeated failure. If those behaviours degrade, the programme has a control-usage problem, not a feature-availability problem.

From our research library:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

What this signals

MFA adoption fails when the journey assumes too much about user devices and abilities: The operational test is not whether a factor is available, but whether users can register and sign in without avoidable friction. Teams that treat accessibility, backup methods, and input handling as part of authentication design get better control uptake and fewer help desk escalations.

Usability and assurance are linked in identity programmes: A factor that is technically strong but operationally awkward produces weaker protection in practice because users abandon it or find workarounds. The programme-level shift is to measure authentication by completion and reliability, not by the mere presence of MFA.

MFA design should be evaluated alongside broader identity journeys: Enrollment, recovery, and sign-in all affect whether a control survives contact with real users. That makes MFA UX a useful proxy for how well an IAM programme balances security, accessibility, and operational resilience.


For practitioners

  • Design multiple enrollment paths Offer SMS, email, authenticator app, and security key options where policy allows, then make the preferred method selectable during enrollment and changeable later in account settings.
  • Make TOTP accessible by default Expose the TOTP secret as text, add clear instructions, and support screen readers with meaningful alt text and ARIA attributes for QR-based setup.
  • Fix OTP entry behavior Use text inputs with numeric hints, enable autocomplete for one-time codes, and validate the expected length before submission to avoid failed sign-ins caused by input quirks.
  • Surface backup methods in sign-in Show the enrolled primary factor first but give users a visible path to switch to an alternate method when the default is unavailable.
  • Treat MFA completion as a control metric Track enrollment completion, sign-in success, and fallback-method usage so you can distinguish good policy from a flow that users abandon.

Key takeaways

  • MFA is only effective when users can complete enrollment and sign-in reliably, so usability directly affects security outcomes.
  • Multiple enrollment methods, accessible TOTP setup, and better OTP handling reduce abandonment without changing the underlying factor model.
  • Teams should measure MFA by completion, fallback usage, and sign-in success, not by deployment alone.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationThe article is about authentication flow design and user completion of MFA.
Recommendation — Apply SP 800-63B to keep authentication robust while reducing friction in MFA enrollment and sign-in.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsMFA UX determines whether authentication and authorization controls are actually usable.
Recommendation — Use PR.AA-05 to ensure access control works in practice for enrolled users.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe guide addresses authentication flows for accounts, including MFA enrollment and sign-in.
Recommendation — Review MFA journeys for insecure authentication paths that cause abandonment or bypass.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)The article focuses on MFA for user accounts and sign-in experience.
Recommendation — Use IA-2 to require strong authentication while keeping the user journey workable.
ISO/IEC 27001:2022A.8.5 — Secure authenticationAuthentication usability affects whether secure sign-in controls are consistently applied.
Recommendation — Align authentication design with secure authentication controls that users can complete reliably.

Key terms

  • Mfa Enrollment: The process of registering one or more second-factor methods on an identity so that future sign-ins can require additional verification. In practice, enrollment succeeds only when the user can complete setup across their device, accessibility, and recovery constraints.
  • TOTP: Time-based one-time password is a code generation method that combines a shared secret with the current time to produce a temporary login code. It is common in authenticator apps and reduces replay risk, but it still relies on shared-secret trust and careful clock synchronisation.
  • Backup Authentication Method: An alternate verification method used when the user’s primary MFA factor is unavailable. Good governance treats backup methods as part of the authentication design, not as an afterthought, because they preserve access without forcing unsafe recovery workarounds.
  • Authentication Friction: The delay, confusion, and support burden created when users cannot complete sign-in cleanly. In IAM programmes, friction is a governance signal because it drives resets, exceptions, and workarounds. If users routinely hit the recovery path, the authentication design is not yet operationally stable.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org