Because users respond to friction. When login is too cumbersome, they reuse passwords, write them down, delay resets, or seek easier workarounds that undermine the control. Security improves only when authentication design is both strong and usable enough that users follow it consistently instead of bypassing it in practice.
Why more authentication can backfire
Authentication does not exist in a vacuum, it sits inside a human workflow. If the control adds too many prompts, resets, exceptions, or recovery hurdles, people start optimising around it. That can mean password reuse, weaker self-service choices, unsafe “remember me” habits, or informal bypasses that reduce real assurance even when the policy looks stricter on paper.
What matters is not just the nominal strength of the factor, but whether users can complete sign-in reliably under normal pressure. A control that is technically stronger yet frequently bypassed, shared, or reset loses practical value. That is why usability is part of authentication security, not a separate convenience concern.
How friction changes user behaviour
When access becomes hard to remember or slow to obtain, users tend to choose the path of least resistance. Reuse increases because people manage too many accounts already, and recovery workflows become tempting targets because they are easier than the primary sign-in path. In practice, the weakest point is often not the login prompt itself, but the surrounding process for enrollment, reset, and exception handling.
Good authentication design therefore treats human workarounds as a security signal. If staff repeatedly request resets, write down secrets, or avoid using the control for routine tasks, the organisation has not really reduced risk, it has moved it. Stronger controls only help when the operational burden stays low enough that secure behaviour remains the default behaviour.
What “stronger” should mean in practice
Stricter should mean harder for an attacker to abuse, not harder for the legitimate user to complete safely. Phishing-resistant methods, clearer recovery rules, and fewer legacy exceptions usually improve both security and usability when they are rolled out well. The best designs reduce dependence on memorised passwords, minimise repeated interruptions, and keep recovery paths narrowly controlled.
That is why modern guidance emphasises stronger authenticators that are also practical to use at scale. A more usable control is often a more secure one because adoption is higher and workarounds are lower. For background on phishing-resistant sign-in and recovery design, see the NIST SP 800-63 Digital Identity Guidelines and NHIMG’s Passwordless and Passkeys Guide.
Risk and Threat Considerations
Overly strict authentication often pushes users into insecure adaptation, which creates exposure that the original control was meant to prevent. The most common failure mode is not immediate compromise of the factor itself, but a drift into reuse, shared access, unsafe recovery, or exception-heavy operations that attackers can exploit more easily than the intended control path.
Failure mechanism: Excessive friction makes users and support teams create shortcuts, weaken recovery, or reuse credentials, so the effective control strength drops below the policy strength.
Impact: Attackers gain more opportunities through password reuse, account recovery abuse, or social engineering of help desk and reset processes, while the organisation believes authentication has been tightened.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST SP 800-53 Rev 5, OWASP ASVS and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Covers authenticator assurance and phishing-resistant sign-in for usable strong authentication. |
| Recommendation — Adopt phishing-resistant authenticators and align recovery to the assurance level required. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Authentication friction often fails through weak lifecycle and recovery handling of authenticators. |
| Recommendation — Manage authenticator issuance, rotation, and recovery tightly to prevent bypass. | ||
| OWASP ASVS | V6 — Authentication | Authentication design must balance strength with user-completable flows to avoid insecure workarounds. |
| V7 — Session Management | Poor auth experience often shifts risk into sessions, remember-me, and reauthentication behavior. | |
| Recommendation — Verify authentication and recovery flows are strong, usable, and resistant to bypass. Review session and reauthentication rules so convenience features do not weaken assurance. | ||
| CIS Controls v8 | CIS-5 — Account Management | Credential and account lifecycle controls help reduce the friction-driven workarounds that weaken authentication. |
| Recommendation — Standardise account lifecycle and recovery so users do not resort to unsafe shortcuts. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control must remain enforceable in practice, not only on paper, or users will bypass it. |
| Recommendation — Design access control so secure use remains the easiest compliant path. | ||
Practitioner Guidance
What to prioritise: Start with the sign-in journeys that users touch most often, then look at recovery and exception paths. If the recovery process is easier to abuse than the login process is to use, the design is already imbalanced.
What to verify: Check whether the control reduces real-world account compromise or merely increases reset volume, lockouts, and support tickets. If users are bypassing the intended path, the implementation needs redesign rather than more enforcement.
Decision rule: If a stricter method increases abandonment or fallback use, simplify the flow before adding more friction. If a method is strong and low-friction, push adoption there first because consistency usually beats theoretical hardness.
Practitioner takeaway: The goal is not maximum authentication friction, it is durable authentication behaviour, strong enough to resist attackers and simple enough that users keep using it correctly.
Related resources from NHI Mgmt Group
- Why does high-frequency authentication sometimes make identity security worse?
- Why do stricter payment authentication rules sometimes reduce sales even when they improve security?
- How should security teams authenticate AI agents in enterprise environments?
- How should security teams implement Client ID Metadata Documents?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org