TL;DR: Passwordless MFA is becoming the default hygiene baseline, but its security value depends on phishing-resistant methods such as passkeys, CBA, and PKI, plus secure credential enrollment and account recovery, according to Axiad’s summary of Gartner summit takeaways. The real governance problem is not whether to adopt MFA, but whether identity programmes can remove password dependence without creating recovery and enrolment failure points.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Fresh Take: Our Five Key Takeaways from the 2023 Gartner® Identity & Access Management Summit in Texas”.
Key questions
A: Security teams should treat passwordless as the authentication layer, not the proofing layer.
Q: Why do conventional MFA controls still fail against phishing and prompt abuse?
A: Conventional MFA can fail when the second factor is easy to trick, relay or socially engineer through SIM swapping, push bombing or support-assisted reset flows.
A: Warning signs include users bypassing the intended sign-in flow, unmanaged device syncing, inconsistent recovery controls, or a design that still depends on weak fallback secrets.
Practitioner guidance
- Standardise phishing-resistant MFA for high-value access Prioritise passkeys, certificate-based authentication and PKI for workstation and cloud application access where phishing and prompt abuse present the highest risk.
- Harden credential enrollment and account recovery Replace weak proofing, temporary passwords and knowledge-based recovery with stronger enrollment checks and self-service recovery paths that do not depend on the help desk.
- Map authenticator choice to the use case Use different authenticator patterns for workstations, cloud apps, shared workstations and virtual desktop environments instead of assuming one factor fits all access scenarios.
Bottom line: Passwordless MFA only reduces risk when the enrollment and recovery paths are stronger than the password flow they replace.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passwordless is not a security outcome unless the recovery path is governed. Removing passwords can shrink the attack surface, but the actual security boundary moves to enrollment, binding and recovery. If those workflows can be satisfied through weak proof or help desk intervention, the programme has simply moved the compromise point rather than eliminated it. Practitioners should judge passwordless initiatives by the quality of the trust transition, not by the absence of passwords.
A question worth separating out:
Q: How should security teams handle MFA resets and account recovery?
A: Treat MFA resets and account recovery as privileged actions. Require out-of-band verification, enforce approval for high-risk changes, and log them as security events that trigger follow-up monitoring. If the recovery process is easy to socially engineer, it becomes an attacker entry point rather than a resilience control.
👉 Read our full editorial: Passwordless MFA and phishing-resistant identity: what matters now