Keep the user experience simple where risk is low, but do not remove MFA from privileged, sensitive, or anomalous access. The right compromise is targeted verification, not blanket relaxation. That preserves adoption while still protecting the accounts and actions most likely to be targeted by attackers.
Why extra authentication is usually a targeted decision, not a blanket policy
Pushback on additional authentication is often a UX complaint, but the security decision should be based on context: who is signing in, what they can reach, and whether the access looks normal. Low-risk journeys can stay simple, while privileged, sensitive, or anomalous access deserves step-up verification. That preserves adoption without treating all users and all sessions the same.
Good teams separate convenience from assurance. They avoid forcing stronger checks everywhere, but they also avoid removing MFA from the accounts and actions attackers are most likely to target. The practical goal is to apply more friction only when the risk justifies it, and to make that friction predictable rather than arbitrary.
That is why phishing-resistant methods matter for higher-risk access paths. Guidance on NIST SP 800-63 Digital Identity Guidelines supports stronger authenticator assurance when the session must be trusted more heavily, and a rollout can be phased so users only encounter the extra check where the assurance requirement changes.
When users object, separate friction from control value
Most resistance comes from one of three places: repeated prompts, unclear policy, or a control that feels disconnected from the task. If the authentication step appears on every login, users experience it as friction. If it appears only for privileged actions, unfamiliar devices, unusual locations, or risky sessions, it is easier to defend and easier to understand.
Teams should also remember that not every sign-in needs the same verifier. A normal, low-impact workflow may only need simple MFA or single sign-on, but access to admin consoles, production systems, financial actions, or recovery flows should be treated differently. That distinction is what makes extra authentication defensible instead of merely annoying.
Workforce Identity Security Guide is useful here because it ties user experience, step-up authentication, and recovery controls together rather than treating MFA as a one-size-fits-all checkbox.
Why the compromise is targeted verification, not relaxation
The right compromise is to reduce prompts where the blast radius is low and increase assurance where the blast radius is high. That means privileged users, recovery actions, new devices, impossible travel, and other anomalous access should be candidates for step-up verification even if ordinary users are allowed a lighter path. This avoids training attackers to look for the weakest, least-defended paths.
Teams should also be cautious about treating MFA as the end of the story. Attackers regularly bypass weak or poorly implemented MFA through push fatigue, session theft, phishing proxies, or stolen credentials. If users are allowed to opt out of stronger verification on the very paths that matter most, the organisation ends up with convenience on the front door and exposure behind it.
The most practical way to handle the pushback is to define where assurance must stay high and where it can be relaxed safely. For sign-in methods and bypass patterns, MFA Guide is a useful reference point because it covers the trade-offs between MFA methods and the common bypass patterns teams need to anticipate.
Risk and Threat Considerations
Extra authentication is not just a usability issue. If teams remove it too broadly, they weaken protection around privileged access, account recovery, and anomalous sessions, which are exactly the paths attackers favour once they obtain a password or session token.
Failure mechanism: Users accept weaker controls on the normal path, then attackers exploit the exception path, such as reused passwords, legacy accounts, fatigue-based approval, or intercepted sessions, to reach higher-value actions without meaningful resistance.
Impact: Credential abuse becomes easier to turn into account takeover, lateral movement, or privileged misuse, and the organisation loses the ability to distinguish ordinary login friction from high-risk access that deserves stronger proof.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, CIS Controls v8, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Guides assurance strength and phishing-resistant authentication for higher-risk access. |
| Recommendation — Apply stronger authenticators where access risk is elevated and keep routine paths lighter. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Access should tighten for privileged and sensitive paths instead of being relaxed globally. |
| Recommendation — Separate routine access from high-risk access and preserve stronger verification for the latter. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Organizational user sign-in controls are central when teams tune MFA expectations. |
| IA-5 — Authenticator Management | MFA pushback often involves how authenticators are issued, used, and renewed. | |
| Recommendation — Use stronger authentication for users who can reach sensitive or privileged systems. Manage authenticators so higher-risk access still requires strong proof. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | Step-up verification aligns with verifying trust at the point of access, not once at sign-in. |
| Recommendation — Verify access context continuously and raise assurance when risk changes. | ||
Practitioner Guidance
Decision rule: If the access path can reach privileged settings, sensitive data, recovery functions, or production systems, keep step-up authentication in place even when users object. If the path is low impact and low risk, reduce friction there instead of weakening the stronger control globally.
What to verify: Make sure the exception logic is risk-based and explicit, not ad hoc. Users should see fewer prompts for routine activity, but stronger verification should still trigger for unfamiliar devices, anomalous locations, admin roles, and high-value actions.
Common mistake: Teams often respond to complaints by lowering the control for everyone. That improves sentiment in the short term, but it usually shifts the burden onto incident response later when a stolen credential or abused session reaches the most valuable systems.
Practitioner takeaway: The best authentication policy is the one users notice less on safe paths and more on dangerous ones, because selective friction is what keeps adoption and assurance aligned.
Related resources from NHI Mgmt Group
- How should security teams handle authentication when users, digital IDs, and AI agents share the same trust model?
- How should security teams handle an authentication platform retirement without disrupting users?
- How should security teams handle TOTP authentication when users want one app for both password management and verification codes?
- How should security teams handle authentication for autonomous AI agents that cannot log in or maintain sessions like human users?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org