Security teams should move toward identity proofing and stronger authentication that verifies the person at the other end of the session, not just knowledge of a password or possession of a second factor. The practical goal is to replace hope based authentication with evidence based identity assurance, especially for remote access over open networks. That reduces phishing exposure and weakens credential reuse as an attack path.
Why This Matters for Security Teams
Remote system logins are one of the easiest places for attackers to turn a stolen password into a durable foothold. Password-based access also encourages reuse, phishing, replay, and help-desk social engineering, especially when users connect over unmanaged networks and personal devices. That is why evidence-based identity assurance matters more than simple credential possession, and why guidance increasingly points toward stronger, phishing-resistant authentication and continuous verification.
For NHI Management Group, the same pattern shows up across human and machine access: weak secrets handling and overexposed credentials create avoidable paths into critical systems. The Ultimate Guide to NHIs notes that 79% of organisations have experienced secrets leaks, with 77% causing tangible damage. That is not just an NHI problem. It is a signal that identity controls fail when organisations rely on static, reusable access artifacts instead of short-lived proof. Current best practice aligns with the OWASP Non-Human Identity Top 10 and NIST control thinking that treats authentication as part of a broader access-risk decision, not a one-time gate.
In practice, many security teams encounter password-driven compromise only after a remote admin session has already been used to pivot into the rest of the environment.
How It Works in Practice
Reducing reliance on passwords for remote logins means replacing static knowledge factors with stronger identity proofing, phishing-resistant sign-in, and tighter session controls. The most common direction is to use MFA that is resistant to phishing, then layer device posture checks, conditional access, and short-lived session tokens. For privileged or sensitive administrative access, current guidance suggests moving further toward certificate-based authentication, hardware-backed authenticators, and just-in-time access grants.
In operational terms, the workflow should look like this:
- Verify the user with an identity-backed factor that cannot be easily replayed, such as a FIDO2 security key or platform authenticator.
- Check context at login time, including device health, location anomalies, session risk, and whether the request matches expected admin behavior.
- Issue short-lived access rather than long-lived standing access, and revoke it automatically when the task ends.
- Require privileged actions to re-authenticate or step up when the risk changes during the session.
This approach aligns with NIST SP 800-53 Rev 5 Security and Privacy Controls, especially for access control, authentication, and session management. It also fits the NHI governance model described in the Ultimate Guide to NHIs - Key Challenges and Risks, where long-lived secrets and poor rotation create persistent exposure. The same principle applies to remote admin access: limit what is reusable, shorten what is valid, and make the login decision depend on evidence, not memory.
These controls tend to break down in legacy remote access environments that still depend on shared accounts, SSH keys without lifecycle control, or applications that cannot support modern authentication flows.
Common Variations and Edge Cases
Tighter remote authentication often increases operational overhead, requiring organisations to balance stronger assurance against admin friction and legacy compatibility. That tradeoff is real, especially where contractors, break-glass access, or field operations need fast recovery paths.
Some environments cannot move straight to passwordless access. In those cases, best practice is evolving rather than settled: organisations may keep passwords temporarily, but only behind a hardened gateway, with phishing-resistant MFA, risk-based step-up checks, and aggressive credential rotation. Shared admin accounts should be eliminated where possible, but if they remain for transition purposes, every session should be recorded, approved, and time-bound.
One useful benchmark from NHI Management Group is that only 20% of organisations have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them. That same lifecycle weakness often appears in remote access, where old credentials stay valid long after the business need has ended. The lesson is consistent across 52 NHI Breaches Analysis and the Microsoft SAS Key Breach: long-lived access artifacts become liabilities when organisations delay revocation, rotation, and verification.
In mixed estates, the safest path is to phase out password reliance first for privileged remote access, then for all administrative sessions, and finally for standard user sign-ins where platform support allows it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Reduces reliance on reusable secrets and weak remote authentication. |
| OWASP Agentic AI Top 10 | Phishing-resistant access and runtime checks help autonomous workflows too. | |
| CSA MAESTRO | IAM-03 | Covers strong identity and access controls for autonomous and remote workloads. |
| NIST CSF 2.0 | PR.AC-7 | Supports least-privilege and authenticated access for remote logins. |
| NIST AI RMF | GOVERN | Identity assurance and access decisions need accountable governance. |
Use phishing-resistant authentication and contextual checks before granting tool or session access.
Related resources from NHI Mgmt Group
- What breaks when organisations keep password-based remote access in place?
- How should organisations move from password-based authentication to identity-based authentication in customer and workforce environments?
- How should organisations reduce the risk of VPN-based compromise when remote access still depends on usernames and passwords?
- How should organisations reduce password reset volume without weakening access control?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org