By NHI Mgmt Group Editorial TeamBased on Beyond Identity: “The Future of Authentication Technologies” (August 5, 2025)

TL;DR: Passwords remain a dominant breach vector, with the 2021 Verizon Data Breach Investigation Report attributing 89% of web application breaches to stolen credentials or brute force attacks, while legacy MFA still suffers from low adoption and user friction, according to Beyond Identity and Verizon. The real shift is that identity and device posture now define the access perimeter, so authentication must become cryptographic, device-aware, and continuous rather than password-centric.


At a glance

What this is: This analysis argues that passwordless authentication is becoming the new trust boundary because passwords, legacy MFA and perimeter-based assumptions no longer match cloud and hybrid access realities.

Why it matters: IAM teams, PAM teams and identity architects need to treat device trust and continuous verification as core access controls, not optional enhancements to login UX.

By the numbers:

  • Passwords caused 89% of web application breaches, either through stolen credentials or brute force attacks, according to Beyond Identity.
  • 61% of all breaches exploited credential data via brute force attacks, credential stuffing attacks, or credential data leaked and used later, according to Beyond Identity.

Context

Passwords remain a weak authentication primitive because they are reusable, memorable and easy to steal or brute force at scale. In cloud and hybrid environments, that weakness matters more because the old network perimeter has largely disappeared and access decisions now depend on identity and device state.

The article frames passwordless authentication as a response to that shift, not as a cosmetic login improvement. For IAM programmes, the real question is whether authentication still assumes a static trust boundary when users, devices and resources are all moving targets.

Legacy MFA reduces some password risk, but the article argues that friction, insecure second factors and low adoption leave too many organisations exposed. That makes device trust and continuous verification central to the modern access model.


Key questions

Q: How should security teams govern privileged access in cloud and hybrid environments?

A: Teams should govern privileged access around runtime authorization, not just connectivity or login. That means scoping elevation to a specific task, setting an expiry, logging approvals, and revoking access automatically when work is complete. The goal is to reduce standing privilege and create evidence that can withstand incident review and audit.

Q: Why do legacy authentication protocols create risk after MFA is enabled?

A: Legacy protocols such as IMAP and POP can bypass MFA because they use password-only authentication paths that sit outside modern sign-in enforcement. If those routes remain enabled, an attacker with valid credentials can re-enter the account even after standard remediation. MFA only helps if it covers every access path.

Q: What breaks when device trust is not part of privileged access decisions?

A: Privilege becomes detached from real session risk. A user or workload may still be authenticated, but the device may be compromised, unmanaged, or operating from an unexpected context. Without device trust, security teams lose a major signal for deciding whether elevated access should be granted, narrowed, or denied.

Q: When should organisations prioritise persistent authentication over a one-time login check?

A: Organisations should prioritise persistent authentication when users return repeatedly, transactions have financial impact, or account takeover would be costly. A one-time login check is weak in these environments because trust has to continue after entry. Persistent identity signals help teams reassess risk across the customer lifecycle and reduce reliance on static credentials alone.


Technical breakdown

Why passwords and legacy MFA fail as a trust boundary

Passwords can be replayed, guessed, phished or stuffed, which makes them a poor basis for proving identity at scale. Legacy MFA helps, but if it still depends on passwords, SMS codes or other weak factors, it often shifts rather than removes the attack surface. The article ties this to cloud adoption and hybrid work, where the network perimeter no longer provides a reliable outer boundary. In that model, the authentication event itself becomes the enforcement point, and weak credentials cannot safely carry that responsibility.

Practical implication: treat password-based and SMS-based flows as transitional controls, not a durable trust boundary.

How device trust changes authentication architecture

Device trust means the access decision depends on both who the user is and whether the endpoint meets required security conditions. That can include approved hardware, local secure elements, anti-hammering protections and policy checks on device posture before access is granted. This is materially different from classic MFA because the device is not just a factor, but part of the trust decision. The result is closer alignment between identity assurance and endpoint assurance, which matters when the endpoint is the new perimeter.

Practical implication: bind access policy to device state, not only user credentials or one-time prompts.

Continuous risk-based authentication and zero trust

Zero Trust Architecture assumes no transitive trust, so authentication should not be a one-time gate at session start. The article’s model checks every identity and device continuously and enforces granular policy during each transaction, which turns trust into an ongoing condition rather than a login event. That is important for cloud applications, remote access and high-risk workflows where session context can change after initial sign-in. In practice, this shifts identity governance from access issuance to access surveillance and re-evaluation.

Practical implication: design authentication to re-evaluate trust during the session, not only at login.


Threat narrative

Attacker objective: The attacker wants durable authenticated access that can be used to reach internal applications and remote resources without triggering stronger trust re-evaluation.

  1. Entry begins with stolen, reused or brute-forced passwords, often enabled through credential stuffing against remote access services.
  2. Escalation follows when legacy MFA is weak, poorly adopted or bypassed through insecure second factors, allowing the attacker to validate access.
  3. Impact occurs when the attacker reaches cloud applications or remote resources through a trust model that still treats initial authentication as sufficient.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Passwordless is becoming a trust boundary issue, not just an authentication preference. Once cloud adoption and hybrid work remove the network perimeter, identity assurance and device assurance have to carry the access decision. That makes passwordless a governance topic, not an UX feature. The practitioner conclusion is that authentication design now defines the boundary of the programme.

Legacy MFA often leaves the same structural weakness in place. If a control still depends on passwords, SMS or other weak second factors, it inherits the same replay and phishing exposure it was meant to reduce. The low adoption problem matters because weak controls that users avoid do not become governance controls in practice. The practitioner conclusion is that adoption, not just architecture, determines control effectiveness.

Device trust is the missing control plane for modern identity programmes. The article’s strongest point is that access should depend on whether the endpoint is approved and properly configured before it reaches critical resources. That changes device posture from an endpoint-management concern into an IAM input. The practitioner conclusion is that device state must become part of the access policy model.

Continuous verification reflects a broader collapse of static trust assumptions. Access reviews and one-time authentication were designed for stable sessions and predictable trust boundaries. In cloud and remote environments, those assumptions no longer hold. The practitioner conclusion is that identity governance has to move toward continuous evaluation of identity, device and context.

Password sprawl creates a broader identity debt that passwordless helps expose. Reused credentials, forgotten passwords and user workarounds show that human convenience has already broken the older model. A modern programme should treat this as evidence that authentication is now a lifecycle and assurance problem, not a login-method debate. The practitioner conclusion is to align identity strategy with the actual behaviour of users and endpoints.

From our research library:

  • The average user manages 70 to 100 passwords, many of them outside centralised identity platforms.

What this signals

Passwordless authentication changes the control point, not just the user experience. Identity teams should expect authentication to absorb more of the boundary function that the network used to provide. That means device trust, session policy and factor strength now sit in the same design conversation.

Continuous verification is becoming the practical expression of Zero Trust Architecture for identity teams. Access granted once is no longer enough when devices, locations and risk signals can change mid-session. Programmes that still treat sign-in as the end of the control path will miss the real enforcement point.

The new trust boundary is only real when it reduces workarounds as well as attacks. If users are still choosing convenience over policy, the control is not operating as designed. Identity leaders should watch for reduced password dependence, lower MFA fatigue and tighter device-policy coupling as the meaningful signals of progress.


For practitioners

  • Replace password-dependent authentication flows Prioritise applications and remote access paths that still depend on reusable passwords or SMS-based second factors, then phase in cryptographic authentication where the risk is highest.
  • Bind access decisions to device posture Require approval state, security configuration and device health to be checked before access is granted to cloud resources or sensitive applications.
  • Reduce reliance on legacy MFA Inventory which applications still accept weak second factors and identify where user friction is driving bypass, help desk workarounds or low enrolment.
  • Make continuous verification part of policy Move high-risk access paths toward session-level re-evaluation so that identity, device and context remain under policy after initial sign-in.
  • Use hybrid work as a design assumption Treat remote and hybrid access as the default operating model and validate whether your current authentication controls still make sense without a network perimeter.

Key takeaways

  • Password reuse, credential stuffing and brute-force attacks remain central to web application compromise, which is why password-centric authentication is losing relevance as a boundary control.
  • The more identity programmes depend on cloud access and hybrid work, the more they have to treat device trust and session policy as part of authentication design.
  • A durable modern model replaces static trust with cryptographic verification, approved devices and continuous re-evaluation of access conditions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST Zero Trust (SP 800-207), NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article argues that password-centric and weak-factor authentication no longer provides sufficient trust.
NHI-10 — Human Use of NHIThe post highlights password sprawl and user workarounds that create risk at the human-machine boundary.
Recommendation — Replace weak authentication paths with cryptographic methods that do not depend on reusable passwords. Reduce human workarounds by removing password handling from the authentication flow.
NIST Zero Trust (SP 800-207)Principle 1 — Verify explicitlyContinuous verification and device trust are central to the article's zero-trust argument.
Recommendation — Apply explicit verification at each access decision instead of trusting initial login state.
NIST SP 800-63SP 800-63B — AuthenticationThe article is fundamentally about authentication assurance and factor strength.
Recommendation — Use authentication guidance to raise factor assurance and avoid weak out-of-band second factors.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article treats access policy and authentication as linked controls in the trust boundary.
Recommendation — Align authorization decisions with authentication assurance and approved device state.

Key terms

  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Device Trust: Device trust is the confidence that a requesting endpoint is known, managed, and in a compliant state. It matters because identity alone does not prove safety. In zero trust programmes, device trust becomes one of the inputs used to decide whether access should be granted or sustained.
  • Continuous authentication: A model where access is re-evaluated after the initial login instead of being trusted for the full session. It uses live signals such as posture, telemetry, and policy to detect when a session should be stepped up, constrained, or revoked.
  • Legacy MFA: Older multi-factor authentication methods that add a second check but still depend on human response or reusable codes. In practice, SMS, voice, and push-based flows can reduce casual compromise while leaving room for phishing, fatigue attacks, and adversary-in-the-middle interception.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on May 29, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org