TL;DR: Account sharing breaks the identity-to-action link that MFA depends on, making authentication confirm a valid account rather than the person behind it, according to Imprivata. That gap turns shared credentials into an accountability and audit problem, not just a password problem, and it keeps surviving because workflow friction still rewards shortcuts.
Editorial analysis by NHI Mgmt Group, based on content published by Imprivata: “What are the drawbacks of multifactor authentication and the challenges with shared accounts?”.
Key questions
Q: What breaks when multiple people use the same shared account password?
A: The main failure is accountability.
Q: Why does account sharing create compliance and investigation risk?
A: Because access logs stop being reliable evidence.
Q: How can organisations reduce account sharing without slowing work down?
A: Give each person their own authenticated identity and remove the need for credential handoffs.
Practitioner guidance
- Enforce one user, one account Eliminate shared credentials for any workflow that requires auditability, privileged actions, or user-level responsibility.
- Preserve user-level audit trails Make sure access logs, admin actions, and workflow events can be tied back to a single person.
- Replace shared logins with identity-based access Use individual authentication for shift work, team workflows, and maintenance tasks so MFA protects the person, not just the account.
Bottom line: Account sharing breaks the identity-to-action link that MFA is supposed to preserve, so authentication strength does not translate into accountability.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Account sharing turns MFA into account assurance, not identity assurance. The security control still verifies that a valid account completed a challenge, but the link to the actual person disappears. That means the real failure is not weak authentication strength, but broken identity accountability. For IAM and PAM teams, the control question is whether each access event remains attributable to one human actor.
A few things that frame the scale:
- 43% of security professionals are concerned about AI systems learning and reproducing sensitive information patterns from codebases, according to the State of Secrets in AppSec.
A question worth separating out:
Q: What should teams do when shared administrative accounts still exist?
A: Treat them as high-risk exceptions, not normal operating practice. Limit where they are used, tighten oversight, and prioritise migration to individual administrative identities so privileged actions remain attributable and reviewable.
👉 Read our full editorial: Account sharing weakens MFA by breaking identity accountability