Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Passwordless continuous authentication: what changes for MFA teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19841
Topic starter  

TL;DR: Traditional MFA still breaks down under fatigue attacks, phishing relays, and user friction, according to SecureAuth, which positions passwordless continuous authentication as a way to combine FIDO2 passkeys, behavioral biometrics, risk-based step-up, and device trust. The real shift is that identity assurance must become session-aware instead of prompt-driven, because repeated challenge loops are easy to abuse and hard for users to sustain.

NHIMG editorial — based on content published by SecureAuth: Traditional MFA limits and passwordless continuous authentication

By the numbers:

Questions worth separating out

Q: How should security teams reduce MFA fatigue risk without weakening access control?

A: Security teams should reduce MFA fatigue risk by adding number matching, device binding, prompt throttling, and clear reporting paths for suspicious requests.

Q: When does passwordless authentication create more risk than it reduces?

A: It creates more risk when organisations adopt it without strong device governance, fallback controls, or recovery rules.

Q: What are the signs that MFA is failing in practice?

A: Repeated prompt approvals, rising help desk complaints about login fatigue, unexpected approvals from unusual locations, and successful phishing relays all indicate that the control is being treated as a ritual rather than a safeguard.

Practitioner guidance

  • Replace prompt-heavy MFA with phishing-resistant passkeys where possible Start with workforce applications that have the highest phishing exposure and the most repeated prompt burden.
  • Tune risk-based step-up around sensitive session actions Trigger additional verification for privilege elevation, payment changes, export activity, and access to regulated data rather than at every login.
  • Use device trust as a policy input, not a binary trust claim Treat verified device state as one signal among several, including location, behaviour, and application context.

What's in the full article

SecureAuth's full article covers the operational detail this post intentionally leaves for the source:

  • How SecureAuth positions FIDO2 passkeys, behavioural biometrics, and device trust inside its Continuous Authority model.
  • The way its risk-based step-up logic is intended to reduce prompt fatigue while preserving stronger verification for higher-risk actions.
  • Product-level framing of workforce and industry-specific deployment paths for financial services and healthcare.
  • The vendor's own explanation of how continuous verification is meant to fit into broader identity and access workflows.

👉 Read SecureAuth's analysis of passwordless continuous authentication and MFA limits →

Passwordless continuous authentication: what changes for MFA teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19434
 

Traditional MFA is no longer a stable control assumption when authentication can be socially engineered in-session. Fatigue attacks and relay attacks do not merely bypass a factor, they exploit the fact that the approval step is still tied to a human moment of judgment. That makes the control operationally brittle in high-volume environments. The practitioner takeaway is that assurance design must account for adversarial timing, not just factor strength.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which means identity teams still struggle to see the full credential estate.

A question worth separating out:

Q: What is the difference between MFA and continuous authentication?

A: MFA verifies identity at the start of access, usually by requiring more than one factor. Continuous authentication keeps checking risk while the session is active. MFA reduces initial compromise risk, while continuous authentication addresses session drift, hijacking, and context changes that occur after login.

👉 Read our full editorial: Traditional MFA limits and continuous authentication for passwordless access



   
ReplyQuote
Share: