TL;DR: Frictionless security only works when it accounts for every population, not just end users. Axiad’s blog argues that MFA adoption fails when organisations optimise for ease at the point of login while ignoring IT supportability, auditability, and executive governance across the enterprise. Frictionless does not mean governance-free; it means usable controls that survive real operational conditions.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “What’s All the Hype about Frictionless?”.
By the numbers:
- The number of unfilled cybersecurity roles is expected to grow from 1 million in 2018 to 1.5 million by the end of 2020, according to Gartner Group research cited by Axiad.
Key questions
Q: How should security teams replace traditional MFA without creating new access friction?
A: Start by removing passwords from the most sensitive sign-in paths and using phishing-resistant, device-bound authentication for those users first.
Q: Why do MFA programmes fail when they only optimise for end-user experience?
A: Because end-user ease does not address the people who must maintain, audit, and fund the control.
Q: What are the warning signs that frictionless MFA is becoming ungoverned?
A: Common warning signs include rising exception requests, inconsistent rollout across populations, excessive help desk dependency, and password reversion when support gets difficult.
Practitioner guidance
- Map MFA governance across all stakeholder populations Document how end users, IT operations, audit teams, and executives each interact with the MFA programme, including ownership, support, reporting, and approval responsibilities.
- Test operational supportability before rollout Measure help desk impact, exception handling, skill requirements, and maintenance effort under real operating conditions rather than assuming adoption proves viability.
- Build audit evidence into MFA design Ensure the programme can produce reliable evidence for enrolment, policy enforcement, third-party assurance, and ongoing control operation without manual reconstruction.
Bottom line: Frictionless MFA fails when organisations optimise only for login convenience and ignore the operational and governance work needed to sustain the control.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Frictionless MFA is an operating model problem, not just an adoption problem. A control that works in a pilot but cannot be supported at scale is not frictionless in practice. The real test is whether the programme reduces user resistance without transferring complexity into IT operations and governance. Practitioners should judge MFA by whether it can be sustained, not just whether it can be enabled.
A question worth separating out:
Q: How do IT supportability and auditability affect MFA success?
A: Supportability determines whether the control can be operated at scale, while auditability determines whether it can be defended in review. If either one is weak, the programme may still authenticate users but it will not remain trusted. The result is usually more exceptions, more manual work, and lower confidence in the control.
👉 Read our full editorial: Frictionless MFA fails when identity governance stops at users