When every login requires a phone interaction, the user experience becomes slower and less convenient, especially for frequent access. That friction can reduce adoption, encourage workarounds, and make password-only behaviour more attractive. A stronger design should preserve the security benefit of two-factor authentication while reducing the number of manual steps the user must complete.
Why Phone-Dependent Second Factors Feel Heavy in Real Use
A second factor that requires a phone interaction on every login adds a predictable step to the access path, and that step is not trivial when people authenticate many times a day. The security control may still be effective, but the user experience becomes more interruptive, which changes how consistently the control is tolerated and followed.
That trade-off matters because authentication is not only about proof of possession, it is also about the practical cost of proving it. If the friction is high enough, users start delaying logins, batching work, or pushing for exceptions. In practice, the control can become more visible than the security benefit it is meant to deliver.
Phone-dependent factors also tend to introduce variability. A prompt may arrive quickly one time and slowly the next, or fail because the device is unavailable, out of battery, offline, roaming, or not immediately reachable. The more the workflow depends on manual approval, the more reliability issues become part of the authentication experience.
How Friction Changes User Behaviour and Security Outcomes
When a second factor is tedious, users often look for the shortest path to productivity. That can mean favouring remembered sessions, asking for longer-lived access, resisting rollout, or choosing fallback methods that are easier but weaker. A control that is annoying enough may create demand for exceptions that reduce the overall security gain.
The right comparison is not “phone interaction versus no protection,” but “stronger authentication with acceptable friction versus stronger authentication that people try to bypass.” For frequent access, the best design is usually one that keeps the assurance level while reducing how often the user must actively intervene. MFA Guide is a useful reference point for weighing SMS, app prompts, number matching, and phishing-resistant options.
That is why many organisations move toward phishing-resistant sign-in methods or step-up models, where a second factor is not required with the same intensity on every single login. Passwordless and Passkeys Guide shows how reducing repetitive phone interaction can improve usability without abandoning strong authentication.
Designing for Strong Authentication Without Constant Manual Approval
A better design usually separates initial proof from repeated routine access. If a user is already authenticated on a trusted device and the risk is low, forcing a phone prompt every time may add little security relative to the usability cost. If the session is sensitive, high-risk, or newly untrusted, step-up verification is more defensible than blanket repetition.
Phishing-resistant methods also matter because a phone-based step can still be socially engineered or abused through push fatigue, relay attacks, or token theft. The point is not to remove the second factor, but to choose a factor and a policy that remain effective without creating unnecessary operational drag. NIST SP 800-63 Digital Identity Guidelines is helpful here because it frames authenticator strength and assurance rather than treating every extra prompt as equally valuable.
In many environments, the practical answer is a layered approach: strong MFA or passkeys for primary sign-in, risk-based step-up for unusual conditions, and sensible session management so users are not forced back through the same manual check more often than needed. That model preserves assurance while reducing the number of times the phone becomes a bottleneck.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Covers authenticator strength and assurance for repeated login challenges. |
| Recommendation — Use assurance levels to avoid forcing manual verification on every routine login. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Applies to workforce sign-in controls and repeated authentication prompts. |
| IA-5 — Authenticator Management | Relevant because phone-based second factors depend on managed authenticators and lifecycle choices. | |
| Recommendation — Tune organizational authentication to preserve security without unnecessary login friction. Manage authenticators so second-factor use stays secure and operationally sustainable. | ||
| OWASP ASVS | V6 — Authentication | Covers authentication design choices, including repeated second-factor checks and usability trade-offs. |
| Recommendation — Design authentication flows that resist bypass without overusing interactive challenges. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Supports decisions about when users should be reauthenticated and under what conditions. |
| Recommendation — Set access-control rules that balance assurance with practical sign-in usability. | ||
Practitioner Guidance
What to prioritize: separate “must re-verify every time” from “must re-verify when risk changes.” If the user is being challenged on every routine login, check whether the policy is compensating for weak sessions, weak device trust, or an overly rigid access model rather than a genuine need for continuous re-proofing.
What to verify: confirm whether the phone step is actually improving assurance or simply adding friction. If users are bypassing it through longer sessions, exception requests, or fallback recovery flows, the control may be degrading into a compliance gesture rather than a meaningful security barrier.
Decision rule: if the same person signs in repeatedly during the day, prefer a design that limits manual prompts to first access, high-risk events, or step-up scenarios. If the workflow is already high-risk, keep the stronger factor, but look for a less intrusive implementation.
Practitioner takeaway: the goal is not to eliminate friction at all costs, but to place it where it improves security decisions and remove it where it only drives workarounds.
Related resources from NHI Mgmt Group
- What happens when teams treat passwordless methods as a second factor instead of the primary authentication flow?
- What is the difference between one-time passwords and true second-factor authentication?
- Why is it crucial to adopt new authentication methods in MCP usage?
- How should security teams use one-time passwords as part of multi-factor authentication without creating avoidable friction?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org