Join our Newsletter — 33% off our NHI Course

Passwordless, MFA, and biometrics: what IAM teams should change

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Traditional passwords still dominate enterprise authentication, but the article argues they create recurring security, usability, and support failures through reuse, phishing, resets, and weak recovery patterns, according to Imprivata. The real shift is from memorized secrets toward stronger credential management, because password policy alone cannot fix the structural trust problem.

Editorial analysis by NHI Mgmt Group, based on content published by Imprivata: “The problem with traditional passwords”.

Key questions

Q: What should security teams do first when they still rely on password-only authentication for some resources?

A: The first move is to identify the most sensitive applications and administrative accounts, then require MFA there before expanding broadly.

Q: Why do strong password rules still fail in practice?

A: They fail when policy design outruns the enforcement layer.

Q: How do IAM teams know whether passwordless adoption is actually working?

A: They should look for fewer lockouts, fewer reset requests, shorter time to access, and lower dependence on help desk intervention.

Practitioner guidance

  • Adopt phishing-resistant authentication Prioritise passkeys, device-bound authentication, or other phishing-resistant methods for user populations that face frequent credential attack pressure, especially where password reuse is common.
  • Reduce password dependency in high-risk access paths Use MFA and stronger authenticators first for privileged access, remote access, and cloud access where password-only login creates the most exposure.
  • Design device recovery as an identity control Define lost-device, revocation, and re-enrolment processes before rolling out passwordless access so users do not fall back to unsafe workarounds.

Bottom line: Traditional passwords create recurring security and support failures because they are easy to reuse, phish, forget, and reset.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 10 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Passwords are a control optimized for memorized secrets, not for modern access scale. The article shows the core mismatch: users are expected to maintain many unique credentials while attackers only need one reused or phished secret. That makes password-centric IAM structurally fragile, especially in heterogeneous enterprise environments. The practitioner conclusion is that password policy cannot carry the full authentication burden.

A few things that frame the scale:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

A question worth separating out:

Q: What is the difference between passkeys and hardware security keys in enterprise MFA?

A: Passkeys and hardware security keys both support phishing-resistant authentication, but they fit different operational needs. Passkeys are more convenient for broad adoption, while hardware keys remain stronger for privileged users, recovery, and environments that need a physical possession factor. The right choice depends on assurance target, lifecycle, and device model.

👉 Read our full editorial: Passwords are failing enterprise identity and access management


This post was modified 10 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.