Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What are the signs that a login experience…
Identity Beyond IAM

What are the signs that a login experience is creating avoidable abandonment or support friction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Identity Beyond IAM

Common signs include repeated login failures, abandoned carts or sessions at sign-in, frequent password resets, and users bypassing security features whenever possible. When those signals cluster around returning customers, the issue is often excessive friction rather than weak intent. Teams should review the authentication journey, device signals, and step-up rules to see where legitimate users are being slowed down.

Why a login flow becomes friction rather than protection

A login journey creates avoidable abandonment when the security steps are out of proportion to the user’s intent, context, or familiarity. The problem is not “too much security” in the abstract, it is a mismatch between the risk decision and the user’s path back into the product. That mismatch usually shows up as extra retries, recovery detours, and users choosing the least resistant path back to access.

One useful way to interpret the pattern is that the system is asking for proof too often, or too late, in ways that interrupt normal return visits. Teams should separate genuine security friction from product friction by looking at where legitimate users stall, not just whether authentication technically succeeds. If the same step repeatedly interrupts returning users, the flow is probably over-rotating on one signal or challenge type.

For organisations that manage large identity populations, this often becomes a visibility problem as much as a UX problem. NHIMG research finds that only 5.7% of organisations have full visibility into their service accounts, which is a reminder that friction often hides behind incomplete operational observability. When teams cannot see the full path, they tend to compensate with more prompts, more resets, or more manual review.

Signals that the login experience is causing avoidable abandonment

The clearest signal is concentration: when failures cluster around the same screens, the same device types, or the same step-up event, the user journey is likely too brittle. Repeated password resets, repeated MFA retries, and sessions that die before the user finishes a task all indicate that the login sequence is consuming more effort than the session is worth. A healthy login flow may be strict, but it should not be repeatedly self-defeating for known-good users.

Another signal is behavioural workarounds. If users begin copying passwords into notes, reusing easier credentials, disabling remembered devices, or avoiding protected features altogether, the login process is no longer acting as a clean control. It has become a barrier that users route around. That is especially visible when support tickets mention “I just need to get in” more often than “I think my account was compromised.”

Abandonment can also appear as silent drop-off rather than explicit complaint. Users may reach the login page, start a reset or MFA flow, and simply disappear. The best indicators are therefore not only authentication failure rates, but also completion rates for sign-in, recovery, and step-up sequences. When those metrics fall without a corresponding increase in genuine risk events, the problem is usually control design, not user resistance.

What practitioners should inspect before changing the control

Start with the authentication journey itself: first-time login, returning login, device re-recognition, password reset, and step-up rules. Most avoidable friction comes from treating all users and all sessions as equally uncertain. The practical question is whether the control is being triggered by meaningful risk, or by a coarse rule that ignores context such as device continuity, recent success, or low-risk transaction intent.

Then review support patterns and recovery cost. If help desk volume rises around password resets, lockouts, or MFA enrollment, the login experience is probably externalising its complexity into support. That is a design failure, not just an operations issue. In many teams, the real measure of sign-in friction is not only abandonment, but how often support has to compensate for failed authentication design.

Where relevant, compare the cost of friction against the benefit of the challenge. For lower-risk returning users, reducing one unnecessary prompt can improve completion without materially weakening security. For higher-risk contexts, the correct fix is often not fewer controls, but better-targeted controls that only trigger when the risk signal justifies the interruption.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementAccess control governs how login friction is introduced and limited.
Recommendation — Review access conditions and reduce unnecessary authentication steps for low-risk returning users.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlAuthentication friction sits directly in identity and access control outcomes.
Recommendation — Tune authentication paths to preserve user completion while maintaining required access assurance.
NIST SP 800-63IAL — Identity Assurance LevelAssurance should match the actual identity proofing need of the login journey.
Recommendation — Match assurance requirements to the transaction and reduce over-challenging low-risk sign-ins.
OWASP Agentic AI Top 10A2 — Agentic Access ControlAccess friction often appears when authorization or challenge logic is too coarse.
Recommendation — Constrain high-friction checks to the sessions or actions that truly need them.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementPassword resets and credential handling are central to abandonment and support friction.
Recommendation — Reduce avoidable resets by improving credential lifecycle handling and recovery design.

Practitioner Guidance

What to prioritise: Review the highest-friction branch first, usually password recovery or step-up authentication, because that is where legitimate users most often abandon the session and support cost accumulates fastest.

What to verify: Confirm whether the users who fail are known customers on familiar devices, because that distinction tells you whether the issue is genuine risk pressure or an unnecessarily strict login rule.

Common mistake: Teams often respond to sign-in complaints by adding another challenge, when the better fix is usually to remove an unnecessary one, narrow the trigger condition, or improve device recognition and recovery flow quality.

Practitioner takeaway: A login experience is too friction-heavy when it forces legitimate users into repeated recovery or support paths more often than it blocks risky access; the goal is selective challenge, not universal suspicion.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org