TL;DR: Traditional passwords still dominate enterprise authentication, but the article argues they create recurring security, usability, and support failures through reuse, phishing, resets, and weak recovery patterns, according to Imprivata. The real shift is from memorized secrets toward stronger credential management, because password policy alone cannot fix the structural trust problem.
Editorial analysis by NHI Mgmt Group, based on content published by Imprivata: “The problem with traditional passwords”.
Key questions
A: The first move is to identify the most sensitive applications and administrative accounts, then require MFA there before expanding broadly.
Q: Why do strong password rules still fail in practice?
A: They fail when policy design outruns the enforcement layer.
Q: How do IAM teams know whether passwordless adoption is actually working?
A: They should look for fewer lockouts, fewer reset requests, shorter time to access, and lower dependence on help desk intervention.
Practitioner guidance
- Adopt phishing-resistant authentication Prioritise passkeys, device-bound authentication, or other phishing-resistant methods for user populations that face frequent credential attack pressure, especially where password reuse is common.
- Reduce password dependency in high-risk access paths Use MFA and stronger authenticators first for privileged access, remote access, and cloud access where password-only login creates the most exposure.
- Design device recovery as an identity control Define lost-device, revocation, and re-enrolment processes before rolling out passwordless access so users do not fall back to unsafe workarounds.
Bottom line: Traditional passwords create recurring security and support failures because they are easy to reuse, phish, forget, and reset.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passwords are a control optimized for memorized secrets, not for modern access scale. The article shows the core mismatch: users are expected to maintain many unique credentials while attackers only need one reused or phished secret. That makes password-centric IAM structurally fragile, especially in heterogeneous enterprise environments. The practitioner conclusion is that password policy cannot carry the full authentication burden.
A few things that frame the scale:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
A question worth separating out:
Q: What is the difference between passkeys and hardware security keys in enterprise MFA?
A: Passkeys and hardware security keys both support phishing-resistant authentication, but they fit different operational needs. Passkeys are more convenient for broad adoption, while hardware keys remain stronger for privileged users, recovery, and environments that need a physical possession factor. The right choice depends on assurance target, lifecycle, and device model.
👉 Read our full editorial: Passwords are failing enterprise identity and access management