TL;DR: Passwordless authentication is gaining traction because 60% of workers say authentication has stopped them from doing their jobs and almost half have been locked out of productivity tools, according to Axiad's interview. The real issue is not just user friction but whether identity governance can keep pace when multiple credentials, devices, and assurance methods must be managed across the enterprise.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Jerome Becquart, Axiad: "current approaches to authentication are failing employees"”.
Key questions
Q: How should IAM teams govern passwordless identity without weakening assurance?
A: IAM teams should separate the convenience of passwordless login from the strength of identity proofing.
A: Warning signs include users bypassing the intended sign-in flow, unmanaged device syncing, inconsistent recovery controls, or a design that still depends on weak fallback secrets.
Q: What breaks when passwordless is rolled out without access governance?
A: The rollout can still leave recovery flows, legacy systems, and supplier accounts exposed.
Practitioner guidance
- Map every authenticator to a lifecycle owner Assign clear ownership for enrollment, rotation, replacement, and revocation of each credential type so passwordless methods do not accumulate unmanaged exceptions.
- Unify reporting across all login methods Build one operational view that shows which users have which authenticators, which devices they are bound to, and which methods are still active after role or device changes.
- Tie device changes to re-approval workflows Require explicit re-enrolment or step-up verification when a worker changes phone, key, or platform authenticator so stale bindings are not carried forward.
Bottom line: Passwordless authentication improves resistance to password-based attacks, but it also exposes weak lifecycle governance across multiple authenticators and recovery paths.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passwordless authentication is exposing an identity governance gap, not solving one. The article shows that removing passwords shifts risk into enrolment, recovery, device change, and authenticator choice. When those controls live in separate workflows, the enterprise gains convenience but loses consistent policy enforcement. The practitioner lesson is that passwordless only works as a governed lifecycle, not as a front-end login change.
A question worth separating out:
Q: What should teams do when users keep bypassing new authentication methods?
A: Treat the bypass as a design failure in recovery and rollout, not as user resistance alone. Teams should simplify re-enrolment, make support paths consistent, and remove incentives to keep using old credentials. If the fallback is easier than the secure path, users will continue to choose it.
👉 Read our full editorial: Passwordless authentication is exposing identity governance gaps