Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do password complexity rules and number matching…
Governance, Ownership & Risk

Why do password complexity rules and number matching often increase authentication risk instead of reducing it?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Governance, Ownership & Risk

They increase risk when users respond with workarounds, repeated retries, lockouts, or other bypass behaviour. The article points to frustration, more password resets, and account lockouts as predictable outcomes of added friction. Controls that are harder to use often push people toward weaker habits, which can undermine the security outcome the rule was meant to achieve.

Why Added Friction Can Raise Authentication Risk

Password complexity rules and number matching often fail because they optimise for policy compliance, not user behaviour. When a control is harder to complete than the user expects, people look for the fastest path through it, which can mean password reuse, predictable patterns, repeated retries, help desk calls, or abandoning the control mentally while still satisfying it mechanically.

The security problem is not the rule itself, but the predictable reaction to friction. If a login step creates confusion or delay, the user population starts to treat it as an obstacle to route around, and the organisation inherits more resets, more lockouts, and more opportunities for unsafe recovery paths.

That dynamic is visible in real compromise paths. In the Microsoft Midnight Blizzard breach, access was gained through an account path that had weak or insufficiently enforced authentication protection, showing how control gaps become entry points when the surrounding experience is brittle. The broader lesson is that authentication controls must be usable enough to be followed consistently, not just strict enough to look strong on paper.

How Complexity Rules and Number Matching Backfire in Practice

Complexity requirements can increase variance in user behaviour. Instead of producing stronger secrets, they often produce more predictable secrets, stored secrets, or repeated use of the same secret across services because the user has fewer cognitive options when every password must satisfy arbitrary rules.

Number matching adds a different kind of risk. It is intended to reduce accidental approval and push users to verify the challenge, but it also trains users to respond quickly to prompts with less context. If the organisation has weak anti-phishing hygiene or poor authentication education, a “confirm the number” habit can still be abused when users are conditioned to approve under pressure. NHI Mgmt Group’s Uber Breach analysis is a useful reminder that repeated prompt pressure and fatigue can break otherwise legitimate MFA workflows.

Friction also changes the shape of support demand. More failed logins create more password resets, and password resets are often less secure than the original control if recovery channels are weak. That means the apparent strengthening of the login step can shift risk into adjacent processes such as help desk verification, recovery email compromise, or fallback authentication paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Access ControlAuthentication friction affects access decisions and safe access enforcement.
PR.AC-7 — Identity Management, Authentication and Access ControlThe topic directly concerns authentication usability and access control effectiveness.
Recommendation — Design authentication to preserve reliable access control without pushing users into unsafe workarounds. Tune authentication mechanisms so they improve assurance without increasing failure-driven risk.
CIS Controls v86 — Access Control ManagementPassword policy and MFA choices are access-control controls that must work in practice.
5 — Account ManagementLockouts, resets, and recovery flows are part of the account-management risk described.
Recommendation — Use access control settings that reduce compromise risk without creating excessive login friction. Review account recovery and lockout handling so they do not become the weak link in authentication.
NIST SP 800-63IAL — Identity Assurance LevelThe question concerns how authentication choices affect assurance versus user burden.
AAL — Authentication Assurance LevelNumber matching and password rules influence achieved authentication assurance.
Recommendation — Align authentication strength with assurance needs instead of adding complexity that users cannot sustain. Select authentication methods that raise assurance without driving predictable bypass behaviour.

Practitioner Guidance

What to prioritise: Treat user completion rate, retry rate, lockout rate, and reset volume as control health signals. If any authentication control increases those metrics sharply, assume the control is creating compensating behaviour and review it before calling it effective.

What to verify: Check whether the control reduces actual account compromise paths or simply increases enforcement pressure. A stronger rule that pushes users into predictable workarounds is weaker in practice than a simpler control that users can complete reliably.

Common mistake: Teams often assume that more steps automatically mean more security. In authentication, the better question is whether the added step improves the attacker’s cost more than it increases the user’s likelihood of bypassing, forgetting, or resetting the secret.

Practitioner takeaway: Good authentication design reduces both attacker opportunity and user failure modes; if a rule makes legitimate users less reliable, it may be transferring risk rather than removing it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org