MFA That People Actually Use: Why Security Fails When the Login Experience Is Terrible
Multi-factor authentication has become a standard part of modern cybersecurity. And for good reason.
Passwords alone are no longer enough to protect business systems, especially when employees access applications from different devices, locations and networks. MFA adds an extra layer of protection by asking users to verify their identity in more than one way. In theory, this is simple. In practice, it can become frustrating very quickly. If logging in feels slow, confusing or unnecessarily complicated, users may start seeing security as an obstacle instead of protection. And when that happens, even the best security policy can lose effectiveness.
Security only works when people use it
A strong MFA solution is not only about technical strength. It is also about adoption. If users regularly struggle to access the tools they need, they may look for shortcuts. They may delay logging in, avoid certain systems, ask colleagues to help, reuse weaker methods or pressure IT teams to create exceptions. These behaviours are not usually caused by bad intentions. Most employees are simply trying to do their work. That is why user experience matters. Security controls that are difficult to use can create friction, frustration and resistance. Security controls that fit naturally into the working day are more likely to be accepted and followed.
The problem with “one-size-fits-all” authentication
Not every login carries the same level of risk. An employee accessing a low-risk internal tool from a trusted office device is not the same as someone trying to access sensitive business data from an unknown location. A finance user approving payments is not the same as a general user reading company announcements. When MFA is applied in exactly the same way to every user, every application and every situation, it can create unnecessary friction.
A more practical approach considers context. This may include the user’s role, device, location, application sensitivity or access behaviour. The goal is not to weaken security. The goal is to apply the right level of security where it is needed most.
The best authentication strategy supports both. It protects access to important systems while keeping the login experience manageable for everyday users. This balance is especially important in hybrid work environments, where employees may move between offices, home networks, mobile devices and cloud applications. A reliable MFA process helps organisations maintain stronger protection without slowing people down unnecessarily.

