Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What are the most common signs that an…
Governance, Ownership & Risk

What are the most common signs that an MFA programme is being adopted poorly?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Governance, Ownership & Risk

Common signs include heavy reliance on SMS or mobile OTP, limited coverage for non-IT staff, and privileged users still depending on passwords as a primary method. If users see MFA as complex, inconvenient, or optional, they are more likely to bypass it or resist rollout. Those patterns usually point to incomplete policy design and weak user experience.

How Poor MFA Adoption Shows Up in Day-to-Day Use

Poor adoption usually shows up first in the path of least resistance. If the programme leans on weaker second factors, covers only a narrow slice of users, or leaves high-risk roles on password-first access, it is signalling that MFA is present as a requirement, not yet operating as a real control. The practical test is whether users can complete access without treating MFA as a normal part of work.

The strongest warning sign is mismatch between policy intent and lived behaviour. When an organisation says MFA is mandatory but users can still authenticate through fallback routes, bypass exceptions, or partial enrolment paths, the programme is likely generating friction without consistently raising assurance. That gap also tends to produce shadow workarounds, such as shared devices, delayed enrolment, or repeated approval fatigue.

  • Weak second factors are the norm rather than the exception.
  • Coverage is uneven across departments, contractors, or privileged populations.
  • Exceptions persist longer than intended and become the effective standard.
  • Users rely on prompts or codes, but do not understand why the control matters.

That pattern is especially visible when privileged access still depends on passwords as the primary gate. A programme can look “deployed” while leaving the most valuable accounts under the least resilient authentication model. For that reason, the question is not just whether MFA exists, but whether it is anchored to the accounts, systems, and workflows where compromise would do the most damage.

Why Usability and Coverage Failures Matter More Than the Checkbox

Poorly adopted MFA often fails because the rollout optimises for compliance optics rather than operational fit. If the enrolment process is cumbersome, the second factor is unreliable, or the policy feels optional in practice, users learn to minimise the control instead of internalising it. Over time, that erodes both adoption quality and trust in the security programme.

Coverage gaps matter because they create inconsistent protection across the organisation. A narrow rollout that excludes non-IT staff, legacy systems, or certain access paths leaves the environment with uneven assurance, which is exactly where attackers look for easier entry. This is why MFA should be assessed as a population-wide control, not only as a tool for the security team or the help desk.

Implementation guidance also needs to account for the type of factor used. SMS and basic OTP may be better than nothing, but they often reflect a compromise between convenience and resistance to phishing, replay, and prompt abuse. If the business is depending on those factors for high-value access, the question becomes whether the control meaningfully improves resilience or simply satisfies a policy line item. For broader control expectations, teams often align MFA rollout with NIST Cybersecurity Framework 2.0 and use implementation guidance from OWASP Cheat Sheet Series to keep authentication design and session handling consistent.

Risk and Threat Considerations

Poor MFA adoption creates real exposure because it leaves predictable exceptions, weak factors, and frustrated users that attackers can exploit. The control fails most often not when it is absent, but when it is unevenly deployed or easy to bypass, which gives adversaries a smaller set of stronger paths to target.

Failure mechanism: Attackers exploit fallback authentication, fatigue, social engineering, or password-first privileged workflows to route around the MFA layer, especially where rollout has left gaps in high-value accounts or legacy access paths.

Impact: The result is account takeover, broader lateral movement, and a false sense of protection, because the organisation believes it has added a barrier that is not consistently resisting real-world abuse.

Recent incident patterns make this clear. In cases involving mfa fatigue or bypass, the operational weakness is rarely the factor itself, but the combination of human friction, incomplete coverage, and weak privilege design. That is why poor adoption should be treated as an active security weakness, not a user-experience annoyance. The repeated lesson from the Uber Breach and the Microsoft Midnight Blizzard breach is that weak or bypassable authentication paths can become the entry point for much broader compromise.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Access ControlMFA adoption quality directly affects access control enforcement and assurance.
Recommendation — Enforce access control consistently across all user populations and high-risk accounts.
CIS Controls v86 — Access Control ManagementPoor MFA rollout exposes gaps in account access governance and privilege protection.
Recommendation — Apply access control management to eliminate password-only paths for critical accounts.
NIST SP 800-63AAL — Authentication Assurance LevelMFA quality depends on whether the factors and rollout meet the needed assurance level.
Recommendation — Match authentication strength to the assurance needs of the protected access path.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementWeak authentication programmes often leave privileged credentials and fallback paths too exposed.
Recommendation — Reduce fallback credential exposure and ensure stronger authentication for sensitive access.
MITRE ATT&CKT1110 — Brute ForceWeak MFA adoption often leaves password and fallback paths easier to abuse.
Recommendation — Hunt for abuse of weak or fallback authentication paths in login telemetry.

Practitioner Guidance

What to prioritise: Start with the populations and access paths that carry the highest blast radius, privileged users, admins, contractors, and any workflow that can reach production data or security tooling. If those paths still rely on passwords or soft fallback, the programme is not yet protecting what matters most.

What to verify: Confirm that enrolment is complete, enforcement is real, and bypasses are bounded and reviewed. If users can delay registration, skip the second factor under pressure, or keep a password-only path for critical access, treat that as an implementation defect rather than a training issue.

Common mistake: Teams often judge success by rollout percentage alone. The better measure is whether users can complete normal work without resorting to exceptions, while high-risk accounts are genuinely required to use stronger, phishing-resistant authentication where feasible.

Practitioner takeaway: A well-adopted MFA programme should feel routine to users but restrictive to attackers, if it feels optional, confusing, or narrow, the control is probably present in name only.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org