TL;DR: Password-based authentication problems are stopping 60% of US workers from doing their jobs, while just under 60% have contacted IT after being locked out, according to Axiad’s survey of 2,000 office workers. Passwordless only works when the user journey is simpler than the old one, not when it adds another layer of friction.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Say Goodbye to Passwords for Good, Your Employees Will Thank You”.
By the numbers:
- 60% of US workers surveyed said password problems had stopped them from doing their jobs.
- just under 60% said they had to contact the IT department because they were locked out of their computer.
Key questions
Q: How should IAM teams implement passwordless authentication without breaking customer journeys?
A: Start with hybrid deployment in new or low-risk flows, then expand to existing journeys once recovery, fallback, and step-up rules are proven.
Q: Why do passwordless programmes still need strong lifecycle governance?
A: Passwordless shifts risk from passwords to issuance, recovery, and revocation.
Q: What are the signs that password-only authentication is failing in practice?
A: Password-only authentication is failing when a valid password is enough to grant access from an unusual place, device, or time without any additional checks.
Practitioner guidance
- Standardise the authentication journey Design one coherent path for enrolment, login, device change and recovery so users are not forced to guess which system owns their credential.
- Remove fallback to older credentials Retire legacy password paths once passwordless coverage is stable enough that users do not need a workaround to keep working.
- Consolidate MFA support models Document which authenticator, app and recovery workflow applies in each scenario so help desk support does not become the hidden control plane.
Bottom line: Passwordless authentication does not fix IAM problems unless it removes friction from the full user journey, including recovery and support.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Authentication friction is now an identity governance signal, not just a usability complaint. When employees cannot complete access quickly and confidently, they compensate with workarounds, old credentials or support tickets. That behaviour tells security teams the control is failing at the human boundary, where policy meets actual use. Practitioners should read friction as a sign that authentication design and governance are out of alignment.
A few things that frame the scale:
- According to Forrester Research, a single password reset can cost around $70.
A question worth separating out:
Q: What should organisations do when multiple MFA methods confuse employees?
A: Reduce the number of authentication paths users must navigate and make the recovery process consistent across applications and devices. Fragmented MFA increases mistakes and pushes users toward convenience behaviour. A single operating model is easier to support, easier to govern and more likely to be adopted.
👉 Read our full editorial: Passwordless authentication is exposing the limits of legacy IAM