TL;DR: Users routinely create insecure workarounds when authentication adds unnecessary friction, according to SecureAuth, and the article argues that customer-first identity design improves security by making safe paths easier to follow. For IAM teams, the real question is whether controls are usable enough to survive real behaviour.
NHIMG editorial — based on content published by SecureAuth: customer-first identity and authentication design
Questions worth separating out
Q: How should security teams reduce IAM friction without weakening control?
A: Start by identifying the access paths that users bypass most often, then redesign those steps so they fit the actual workflow.
Q: Why do users create insecure workarounds when identity controls are too strict?
A: Because people optimise for task completion when the control adds delay, confusion, or repeated effort without an obvious security benefit.
Q: What do organisations get wrong about identity-first security?
A: They often treat it as an authentication project rather than an operating model.
Practitioner guidance
- Audit user friction in live authentication journeys Review the highest-volume sign-in and step-up paths for repeated prompts, confusing exceptions, and abandonment points.
- Align step-up challenges to risk, not habit Use adaptive rules so that low-risk access remains simple and higher-risk access gets stronger verification.
- Measure workaround behaviour as a security signal Track support tickets, failed sign-ins, exception requests, and session persistence patterns to identify where friction is driving unsafe behaviour instead of safer adoption.
What's in the full article
SecureAuth's full article covers the operational detail this post intentionally leaves for the source:
- The specific customer-first design principles the vendor uses to reduce user friction in authentication flows.
- Platform-oriented examples of adaptive verification and continuous authority in workforce and consumer identity.
- Implementation context for balancing security prompts with usability across identity journeys.
- Product-level framing for how the vendor positions its identity approach in different industries.
👉 Read SecureAuth's article on customer-first identity and authentication design →
Customer-first IAM: what it means for authentication and user behavior?
Explore further
Human IAM fails when security design assumes users will comply with friction that the process itself makes unreasonable. The article’s central point is that users react to inconvenience, and those reactions often produce weaker security than the intended control. That makes usability part of the control surface, not an afterthought. For IAM leaders, the implication is that adoption and assurance have to be measured together.
A few things that frame the scale:
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which shows how often governance trails the actual identity estate.
A question worth separating out:
Q: How do you know whether an authentication control is too burdensome?
A: Look for abandonment, support escalation, exception growth, and repeated manual workarounds around the control. Those signals usually mean the control is harder to follow than to evade. If legitimate users keep finding alternate paths, the programme is paying for theoretical assurance instead of operational security.
👉 Read our full editorial: Customer-first IAM reduces friction that drives insecure workarounds