Join our Newsletter — 33% off our NHI Course

Password fatigue and secure access design: what IAM teams should change

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Human error remains a major breach driver because pressure, password fatigue and shared-device workarounds push employees toward risky shortcuts, while passwordless authentication, automated credential rotation and single sign-on reduce friction without relying on perfect user discipline, according to Imprivata. Secure access design, not behaviour change alone, is the durable control.

Editorial analysis by NHI Mgmt Group, based on content published by Imprivata: “As Employees Remain the Weakest Link, Experts Say It’s Time to Eliminate Passwords”.

By the numbers:

  • 90% of successful cyberattacks and 70% of data breaches originate at endpoint devices, according to IBM’s Cost of a Data Breach Report cited by Imprivata.

Key questions

Q: How do compliance teams reduce password-related support burden without weakening security?

A: They should simplify the user path, automate resets where possible, and align rules to actual risk so users do not work around them.

Q: Why do password-based controls often fail in busy operational environments?

A: They fail because people under pressure optimise for speed, not policy.

Q: What are the signs that IAM automation is creating too much friction for end users?

A: Common signs include repeated password reset requests, frequent help desk tickets for entitlement changes, slow support resolution, and users trying to bypass formal IAM steps.

Practitioner guidance

  • Eliminate high-friction password steps Identify workflows where users repeatedly type or reset passwords under time pressure, then move those journeys to passwordless authentication first.
  • Reduce shared-device sign-in risk Tighten session handling on shared workstations so users do not leave applications signed in between shifts or handovers.
  • Automate credential rotation for shared access Shorten the usable life of credentials that support shared devices, service desks or operational applications, especially where manual rotation is already being skipped.

Bottom line: Human error remains a breach driver when access design still depends on passwords, repeated logins and user discipline.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Password fatigue is a governance failure, not just a usability complaint. When access design forces users to choose between productivity and security, workarounds become the expected behaviour rather than an exception. That weakens human IAM because the control plane is being judged by how often people bypass it, not by how elegant the policy looks on paper. The implication is that access design must be measured against real operational behaviour, not ideal user behaviour.

A few things that frame the scale:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

A question worth separating out:

Q: Should organisations prioritise passwordless adoption or credential consolidation first?

A: Credential consolidation should come first when identities are already spread across several IAM systems. Passwordless reduces dependence on passwords, but it cannot remove the administrative burden of fragmented renewal, recovery, and offboarding. A single governance model makes the passwordless transition safer and easier to support at scale.

👉 Read our full editorial: Passwordless access and credential rotation reduce human IAM risk


This post was modified 5 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.