TL;DR: Multiple credentials across badges, YubiKeys, Office 365 logins, phone tokens, and admin access create friction, lockout risk, and lifecycle overhead for organizations, according to Axiad. The governance problem is not credential quantity alone but fragmented management that makes access recovery, deprovisioning, and assurance levels harder to control.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Manage all of your credentials from a single platform”.
Key questions
Q: What is the main governance problem with multiple credentials for employees?
A: The main problem is not the number of credentials by itself.
Q: Why do frequent password resets increase security risk?
A: Frequent resets increase risk because they encourage weak user behaviour such as password reuse, predictable patterns, and reliance on fallback channels.
Q: What should IAM teams do first when credential sprawl is causing lockouts?
A: They should inventory every credential type tied to each user and identify which recovery steps are still handled manually.
Practitioner guidance
- Consolidate human credential lifecycle governance Map every user credential type, including badges, tokens, cloud logins, and admin access, to one lifecycle owner and one recovery policy.
- Eliminate emailed temporary passwords Remove recovery shortcuts that bypass MFA and replace them with verified reset flows that preserve the original assurance level.
- Unify privileged access handling Put privileged users on a coordinated update path so device changes, role changes, and expiry events are handled together rather than platform by platform.
Bottom line: Multiple human credentials create governance friction when each one is issued, recovered, and revoked through a different process.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Credential fragmentation is the real governance problem, not credential volume. Human users can tolerate multiple authenticators only if the organisation can still govern state, assurance, and recovery as one lifecycle. Once badges, tokens, cloud logins, and admin access live on separate platforms, identity assurance becomes inconsistent by design. The practitioner conclusion is to treat credential sprawl as an identity governance defect, not a user inconvenience.
A question worth separating out:
Q: How should organisations handle privileged users with multiple MFA devices?
A: They should treat privileged access as one coordinated lifecycle, not as separate authenticator updates across different systems. That means role changes, expiry events, and revocation actions should be governed together so elevated access does not drift across platforms.
👉 Read our full editorial: Credential consolidation for human access: what IAM teams should weigh