• Home
  • Blog
  • MFA Should Protect Employees, Not Prevent Them from Working
Blog Banners
MFA Should Protect Employees, Not Prevent Them from Working
8:08

For security teams, MFA is a standard part of daily operations. It remains one of the most effective ways to stop credential theft, phishing and account compromise. In most organisations, it is rightly seen as essential.

The problem is that employees often see it very differently.

What feels routine for security teams can be a real interruption for employees trying to join meetings, access business applications or meet deadlines. Each extra prompt or approval adds friction between people and the work that matters.

"Working in IT and working in cybersecurity, MFA just became a given. Whereas for your other end users, the ones that aren't technically aligned, MFA is a barrier."
— Daniel Bergner, Cyber Incident Response Lead, CyberOne

 

This highlights a challenge many organisations underestimate. Security controls only deliver value when people use them as intended. If authentication becomes a source of frustration, employees will look for shortcuts or ways to bypass it, undermining the protection you expect.

This is why many MFA projects succeed on paper but fail in practice. The technology works, but user adoption stalls.

The Disconnect Between Security Teams and Employees

Security professionals interact with authentication processes every day. Multiple logins, verification prompts and access requests become routine parts of the job.

Most employees don't operate that way.

A finance manager reviewing invoices, a marketing executive creating content or a warehouse worker accessing a business system doesn't spend their day thinking about identity security. They are focused on completing tasks, serving customers and meeting objectives.

From their perspective, authentication is not a security control. It is simply another action required before work can begin.

This gap in perception matters.

When authentication strategies are built around technical requirements alone, the impact of security friction on productivity is often missed. Employees do not resist security because they dislike protection. They push back against interruptions that disrupt how they work.

The result is a common but dangerous mindset: "Why do I have to do this again?" When that question appears often enough, user frustration begins to grow.

Why Employees Find MFA Frustrating

Most employee frustration with MFA is not about security itself. Instead, it tends to stem from operational inconveniences such as:

  • Frequent authentication prompts
  • Repeated logins across different applications
  • Poorly designed enrolment processes
  • Authentication requests at inconvenient times
  • Having to switch between devices repeatedly
  • Multiple authentication methods across different systems

For security professionals, these issues may seem minor. For employees focused on their work, they can feel like unnecessary barriers. The success of any authentication strategy depends as much on people as on technology.

The Hidden Cost of Security Friction

Many organisations assume that stronger security always leads to better outcomes. In reality, too much security friction can introduce new risks.

When people become frustrated by authentication requirements, they often develop compensating behaviours that reduce overall security.

Examples include:

  • Approving prompts without reviewing them properly
  • Sharing credentials between colleagues
  • Avoiding approved systems
  • Delaying important processes
  • Seeking unofficial ways to access information

These behaviours happen because people naturally seek convenience. This is not a user problem but rather a design problem.

Security programmes that overlook usability often create the conditions for risky behaviour. The goal is not to force compliance through frustration, but to make secure behaviour the simplest choice.

What Is MFA Fatigue?

One of the most significant examples of poor authentication design is MFA fatigue. This occurs when users receive so many authentication requests that they stop paying attention to them.

Instead of evaluating whether a prompt is legitimate, users become conditioned to approve requests automatically.

The worst part is that attackers have learned to exploit this behaviour.

In what's commonly referred to as an MFA fatigue or "push bombing" attack, threat actors repeatedly trigger authentication requests in the hope that an employee eventually approves one out of frustration or confusion.

The attack relies on a simple reality: Many people has become desensitised to repetitive interruptions.

MFA fatigue is both a security risk and a user experience challenge. When authentication becomes background noise, users stop paying attention. At that point, organisations lose the protection they expect from their investment.

Security Isn't the Problem. Friction Is.

A key shift in identity security is recognising that stronger protection does not have to create more inconvenience.

Modern authentication strategies focus on reducing unnecessary user interaction while keeping security strong.

The aim isn’t to add more authentication steps, but to make authentication smarter and more seamless.

This includes:

  • Risk-based authentication
  • Conditional Access policies
  • Single Sign-On (SSO)
  • Context-aware authentication
  • Passwordless authentication

When authentication is based on contextual risk, users see fewer unnecessary prompts and organisations keep robust security in place.

Employees work more efficiently, and security teams retain confidence in identity protection.

How Microsoft Is Improving the MFA Experience

Microsoft continues to invest in reducing authentication friction while maintaining strong security.

One example is Microsoft Authenticator. Rather than relying on traditional six-digit codes, Microsoft Authenticator enables faster and more intuitive authentication experiences through:

  • Push notifications
  • Number matching
  • Biometric verification
  • Passwordless sign-in options
 "Additional security measures need to be either user friendly or unnoticeable to user but must provide a strong level of security.
— Daniel Bergner, Cyber Incident Response Lead, CyberOne

 

These improvements tackle a core reason employees get frustrated with authentication: unnecessary complexity.

This principle is shaping the future of identity security.

Designing Authentication Around How Employees Actually Work

Successful organisations design authentication strategies around people, not just technology.

That means following several core principles:

  • Minimise unnecessary prompts - Only request verification when risk justifies it.
  • Standardise the user experience - Reduce confusion by using consistent authentication methods.
  • Educate users continuously - Help employees understand not only how authentication works, but why it matters.
  • Measure adoption, not just deployment - A successful rollout is not measured by activation rates alone. It is measured by long-term usage and acceptance.
  • Prioritise convenience alongside security - Strong protection and good user experience are not mutually exclusive goals.

When organisations get this balance right, security becomes something employees work with, not something they work around.

Conclusion: The Future of MFA Is Better User Experience

Authentication should protect people and support productivity. It should strengthen resilience without causing frustration, and encourage secure behaviour instead of driving workarounds.

This means combining strong security controls with practical implementation, user education and modern Microsoft-powered technologies such as Microsoft Authenticator, passkeys and FIDO security keys.

As organisations strengthen identity security, they face a clear choice. Treat authentication as a technical hurdle for employees to tolerate,

or recognise that security outcomes improve when authentication is designed around how people actually work.

"MFA is a security requirement, but it shouldn't hinder your employees in the organisation."

 

The future of MFA delivers intelligent, low-friction authentication that empowers employees to work naturally and securely without unnecessary prompts, complexity, or obstacles. The best security controls blend into the background, supporting productivity while safeguarding the organisation.

Book a 30-minute consultation and discover how to build a low-friction, high-security authentication strategy.

 

 

Share this post

Related Articles