TL;DR: Browser-based identity verification now removes the app-install barrier, but Trusona’s analysis shows the real dividing line is whether a flow still depends on prior enrollment, because users without registered factors still fall back to the help desk. The operational issue is not app-free access, but removing prerequisites that turn account recovery into a manual exception path.
NHIMG editorial — based on content published by Trusona: Verifying users without making them install an app
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
Questions worth separating out
Q: How should security teams handle users who never enrolled a verification app?
A: They should test whether the recovery flow can authenticate a user with no prior registration at all.
Q: Why do app-free identity verification flows still fail in practice?
A: Because app-free only removes the install step, not necessarily the enrollment prerequisite.
Q: What do organisations get wrong about identity proofing in the service desk?
A: Many organisations assume the help desk can safely validate identity using employee facts that are easy to research or steal.
Practitioner guidance
- Validate enrollment-free coverage Test every recovery flow with a user who has never enrolled anything, a user whose device is lost, and a user who cannot install software on a personal phone.
- Separate app-free from setup-free in procurement Ask vendors to show exactly what prerequisites remain, including prior passkeys, enrolled devices, or legacy authenticators.
- Add reverse verification for help desks Require a caller-check process that lets employees confirm the support agent through a time-limited code or internal validation page before they act on password reset or MFA changes.
What's in the full article
Trusona's full blog covers the operational detail this post intentionally leaves for the source:
- The browser-based verification flows and when they still depend on prior enrolment.
- The reverse help desk verification pattern for confirming an agent before the employee acts.
- The public-sector constraints around personal devices, accessibility, and procurement.
- The practical comparison of app-based, app-free, and document-based identity verification paths.
👉 Read Trusona's analysis of app-free identity verification and recovery coverage →
App-free identity verification: where the enrollment gap still breaks recovery?
Explore further
App-free is not the same as enrollment-free: The market keeps collapsing those two ideas, but they solve different problems. A browser flow that still depends on a previously registered factor does not help the unenrolled user, the lost-device user, or the contractor who never got through onboarding. The implication is that identity programmes must measure recovery coverage, not just delivery convenience.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage.
A question worth separating out:
Q: Who is accountable when identity recovery is abused?
A: Accountability sits with the organisation that designed or approved the recovery path, because that path is part of the identity control plane. If resets, revocation, and escalation steps can be manipulated, the failure is governance and design, not just user error.
👉 Read our full editorial: App-free identity verification still depends on enrollment assumptions