Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What are the signs that a returning user…
Identity Beyond IAM

What are the signs that a returning user flow is creating too much friction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Identity Beyond IAM

Common warning signs include rising login drop-off, repeated authentication failures, increased support calls, complaint volume, and customers abandoning high-value actions. If trusted users are frequently challenged, the organisation may be overapplying controls or using weak risk signals. Measuring these patterns alongside fraud outcomes helps teams see whether the flow is protecting accounts or simply frustrating genuine users.

Why Friction Shows Up in Returning User Journeys

Returning users should usually move faster than first-time visitors, so friction often reveals a mismatch between the flow and the trust level the organisation thinks it has. The most common causes are repeated step-up checks, weak risk signals that trigger challenges too often, inconsistent device recognition, or a return path that has not been tuned for the user’s actual behaviour.

When a flow is designed for maximum gatekeeping instead of proportional trust, the system can force genuine users to prove themselves too often. That is especially noticeable when the user is already known, already authenticated recently, or is trying to complete a routine action rather than a sensitive one.

Trusted return paths should reflect the principle of proportionate friction, not blanket suspicion. If the experience feels identical for every session, every device, and every action, the flow is probably not differentiating well between low-risk repeat use and higher-risk events that really do deserve extra checks.

  • Repeated prompts for the same credential or factor within a short period
  • High challenge rates on low-risk actions
  • Users being treated like first-time visitors on every return
  • Support teams hearing that the process feels slow, confusing, or redundant

A useful way to think about this is that friction becomes a signal when it is no longer tied to measurable risk. The issue is not that controls exist, but that they may be firing too often, too early, or in the wrong places.

What to Measure When Returning Users Start Dropping Off

The clearest signs are behavioural: login completion declines, authentication retry rates rise, and users abandon the journey before they reach the action that matters. Those signals become more meaningful when you compare them across segments, such as known versus new users, trusted device versus unfamiliar device, or low-risk versus high-risk actions.

You should also watch for support and complaint patterns. A rise in “can’t log in” tickets, password reset requests, or complaints about repeated verification usually means the flow is creating operational friction, not just a minor inconvenience. In high-value flows, even a small increase in abandonment can become expensive if it blocks renewals, purchases, or account maintenance.

Measuring only security outcomes is not enough. A flow can suppress some fraud and still be too strict if it drives genuine users away. The best readout is a paired view: friction metrics on one side, fraud or abuse outcomes on the other. That gives you evidence for whether the control is creating net value or simply adding cost.

What to watch: compare drop-off, retries, challenge frequency, and complaint volume over the same time window, then look for spikes after policy changes, rule tuning, or product launches.

What good looks like: trusted users complete routine returns quickly, only unusual sessions get step-up checks, and high-risk actions are the main place where added friction appears.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementAccess friction here is driven by repeated authentication and challenge handling.
Recommendation — Tune access controls so routine returning users are not forced through unnecessary reauthentication.
NIST CSF 2.0PR.AA-01 — Identity Management, Authentication and Access ControlReturning-user friction often comes from authentication and access decisions that are too coarse.
PR.AA-02 — Identity Proofing, Authentication and Credential ManagementRepeated failures and resets point to poor credential and authenticator handling in the return flow.
DE.CM-01 — Anomalies and Events are MonitoredThe answer depends on tracking login drop-off, retries, complaints, and abandonment patterns.
Recommendation — Align authentication strength to user risk and action sensitivity instead of applying blanket step-up checks. Improve authenticator and credential handling so legitimate returning users can complete access with fewer retries. Monitor authentication and journey metrics together to spot when security friction is harming legitimate usage.
OWASP Agentic AI Top 10A2 — Tool Misuse and Excessive AuthoritySelected only because the subject is about access friction and repeated challenges, which can reflect over-applied controls.
Recommendation — Bound tool and access decisions to the minimum authority needed for the action.

Practitioner Guidance

Decision rule: If friction rises but fraud does not fall, treat the flow as over-tuned before you assume user behaviour has changed. The objective is not to maximise challenge rates, it is to concentrate controls where risk is highest and keep routine returns smooth.

What to verify: check whether the flow is overusing weak signals, such as generic device changes or broad IP reputation, when stronger context is available. In many teams, the problem is not the number of controls but poor signal quality and poor targeting.

Trade-off: every extra checkpoint buys a little more scrutiny, but it also raises abandonment risk and support load. If the same control is applied to low-value and high-value actions alike, the user experience often degrades faster than the security benefit improves.

Practitioner takeaway: a returning user flow is too friction-heavy when it creates measurable user loss without a corresponding improvement in fraud or account protection.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org