TL;DR: Passwords and stolen or weak credentials play a part in more than 80% of today’s breaches, according to Axiad, but fragmented passwordless rollouts can still leave enforcement gaps, inconsistent policy application, and user workarounds. The security problem is not simply replacing passwords, but building integrated authentication across all identity types and environments.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Navigating the path to passwordless authentication”.
By the numbers:
- Passwords, along with stolen or weak credentials, play a part in more than 80% of today's breaches.
Key questions
Q: What breaks when passwordless authentication is deployed in silos?
A: Siloed passwordless deployment breaks policy consistency, visibility, and enforcement.
Q: Why do fragmented passwordless rollouts increase security risk?
A: Fragmented rollouts increase risk because they preserve different rules for different systems and user groups.
Q: How can IAM teams tell whether a passwordless programme is actually working?
A: Look for completion rates, exception volumes, support calls, and the frequency of policy bypass behaviour.
Practitioner guidance
- Define enterprise passwordless coverage Inventory every authentication path across users, machines, operating systems, and major applications, then identify where passwords or alternate methods still remain in the journey.
- Standardise policy enforcement across silos Align enrolment, step-up, recovery, and fallback rules so that one team cannot relax controls without affecting the broader identity programme.
- Remove workaround incentives Watch for login exceptions, duplicate authenticators, and ad hoc access paths that appear when the control creates friction for users or administrators.
Bottom line: Passwordless authentication can still leave meaningful risk in place when it is rolled out as disconnected pilots instead of a governed enterprise model.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passwordless is an architecture decision, not an enrolment event: The article is right to frame siloed deployment as the core failure mode, because authentication strength collapses when policy, recovery, and visibility are not shared across the estate. A passwordless island may improve one workflow while leaving the wider trust model unchanged. Practitioners should judge passwordless by enterprise consistency, not by pilot success.
A few things that frame the scale:
- eBay's passkey data shows 55-60% of passkey adoption happens on mobile, against around 20% on desktop.
A question worth separating out:
Q: How should security teams reduce passwordless friction without weakening control?
A: Security teams should simplify enrolment, recovery, and device replacement so the approved path is the easiest path. Passwordless fails when users must navigate too many platforms or steps, because they either contact IT or work around policy. A single governed portal, clear device binding, and fast recovery procedures reduce both support load and bypass behaviour.
👉 Read our full editorial: Passwordless authentication fails when it is deployed in silos