Join our Newsletter — 33% off our NHI Course
Home FAQ Authentication, Authorisation & Trust What are the signs that an organisation is…
Authentication, Authorisation & Trust

What are the signs that an organisation is relying too much on passwords and one-time codes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Authentication, Authorisation & Trust

A common warning sign is recurring account compromise even when users have credentials and basic MFA in place. Another is repeated login attempts from known breached credentials, frequent password resets, or users approving unexpected MFA prompts. These patterns suggest authentication is being treated as a checkmark rather than a layered control that resists reuse, interception, and social engineering.

What the warning signs actually point to

Overreliance on passwords and one-time codes usually shows up when authentication is still easy to replay, phish, or fatigue, even though the organisation believes it has “MFA.” If users keep getting compromised, if the help desk keeps resetting access, or if attackers can reuse stolen credentials, the control is not providing enough resistance or assurance.

A stronger signal is that authentication events are not being treated as evidence of trust boundaries. When passwords remain the primary control and one-time codes are the main backup, the organisation often has no durable proof of device binding, phishing resistance, or step-up authentication for high-risk access.

Where password plus code strategies break down

Password and one-time code combinations fail for a few predictable reasons. Passwords are reusable and easy to harvest through phishing, credential stuffing, reuse across services, or breach reuse. One-time codes can be intercepted, relayed in real time, or worn down by repeated prompts until a user approves. That means the organisation may have MFA in name while still depending on a factor pair that is vulnerable to social engineering and session theft.

The problem becomes more visible when authentication is broad but not context-aware. If the same login pattern is accepted for low-risk and high-risk actions, or if every access request gets the same treatment regardless of device, location, or session history, the organisation is relying on a shallow checkpoint rather than a layered control. NHIMG’s Ultimate Guide to NHIs is useful here because the same pattern often appears in machine and workload access: broad trust, weak rotation discipline, and too much confidence in a single credential form.

Operational signs that the model is too weak

Practitioners usually see the weakness first in the operational noise. Frequent password resets, repeated MFA push approvals, tickets about locked accounts, and login attempts from known breached credentials are all signs that the organisation is compensating for weak authentication with friction. If the business keeps adding resets, exceptions, and recovery paths, that is often a symptom that the primary login method is no longer doing enough work.

Look for whether authentication failures are being investigated as abuse signals or merely cleared as user inconvenience. A healthy environment should be able to distinguish genuine user error from credential stuffing, prompt fatigue, and interception attempts. When those patterns are blended together, the organisation loses visibility into whether the control is actually resisting attack or just slowing it down.

For a broader identity perspective, the best-known failure mode is treating authentication as a one-time gate instead of a lifecycle control. That is why The State of Secrets in AppSec matters: it shows how credential sprawl, rotation gaps, and long-lived secrets tend to survive long after the original login event.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementPasswords, OTPs and long-lived secrets are central to the warning signs described.
NHI-03 — Phishing ResistanceThe question centers on passwords and one-time codes that can be phished or relayed.
NHI-05 — Authentication and AuthorizationThe page is about whether authentication is providing enough assurance beyond basic login checks.
Recommendation — Reduce reliance on reusable credentials and rotate or replace exposed secrets quickly. Prefer phishing-resistant authentication for high-value accounts and workflows. Require stronger assurance for sensitive access and step up verification when risk rises.
NIST SP 800-63IAL/AAL/FAL — Identity Assurance, Authenticator Assurance, Federation AssuranceAssurance level is the right lens for judging whether passwords and OTPs are sufficient.
Recommendation — Map sensitive access to higher assurance requirements instead of relying on basic factor combinations.
NIST Zero Trust (SP 800-207)1.2 — Policy Enforcement PointThe warning signs indicate authentication is acting as a shallow gate rather than a strong enforcement point.
Recommendation — Place stronger verification at enforcement points before granting access or privilege.
CIS Controls v86.3 — Access Granting and Revocation ProcessesFrequent resets and compromised accounts point to weak access lifecycle control.
6.8 — Unsuccessful Login AttemptsRepeated login attempts from breached credentials are a direct indicator described in the question.
Recommendation — Tighten access granting and revocation so compromised credentials do not remain usable. Alert on abnormal failed logins and investigate credential-stuffing patterns promptly.
MITRE ATT&CKT1110 — Brute ForceRepeated attempts with known breached credentials align with credential-stuffing and brute-force behavior.
T1204 — User ExecutionUnexpected MFA approvals and prompt fatigue rely on user interaction as the attack path.
Recommendation — Hunt for repeated authentication attempts and harden defenses against credential-stuffing abuse. Train and monitor for user-mediated approval abuse and reduce reliance on prompts alone.

Practitioner Guidance

What to prioritise: Treat repeated compromise, prompt fatigue, and reset churn as evidence that the current login pattern is too easy to bypass. The first question is not whether users can authenticate, but whether the organisation can resist replay, interception, and social engineering at the point of access.

What to verify: Check whether the environment can distinguish phishing-resistant access from simple code-based second factors. In practice, that means validating which applications, roles, and sessions still depend on password plus OTP as the only barrier, especially where privileged or high-impact actions are involved.

What good looks like: The authentication flow should make compromised passwords and intercepted codes insufficient on their own, and the control should be strong enough that repeated prompts, resets, and account recoveries are rare rather than routine.

Practitioner takeaway: If the organisation keeps seeing compromised accounts despite “MFA,” the issue is usually not that authentication exists, but that the chosen factors are too easy to reuse, relay, or socially engineer.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org