Authentication sprawl is a governance problem, not just a user-experience problem: When organisations maintain multiple disconnected MFA approaches across use cases and operating systems, they create policy drift that weakens assurance. The issue is not merely complexity at the edge. It is the absence of one accountable identity policy that can be enforced across the full authentication estate.
A question worth separating out:
Q: Should organisations replace MFA with passwordless authentication?
A: Organisations should not treat this as a simple replacement question. MFA is still useful where passwordless is not yet available, but passwordless raises the security baseline by removing the password as the primary failure point. The right path is to use MFA as a bridge and passwordless as the destination.
👉 Read our full editorial: Enhanced authentication choices expose the real IAM tradeoffs