Login friction can push some employees toward unsafe workarounds—or to postpone, delegate, or abandon a task. That pattern is documented across usability studies and surveys, but it is not a claim about every worker. The strongest recent workplace figures come from a September 2022 1Password survey of 2,000 full-time employees in the United States and Canada, while older NIST studies explain why these coping behaviors arise.
What employees report doing when authentication becomes a barrier
In 1Password’s 2022 survey, respondents described work and security consequences associated with difficult sign-ins:
- 44% said logging in and out harmed their mood or reduced productivity.
- 26% said they had given up doing something at work to avoid a login hassle.
- 62% said they regularly missed parts of meetings because of login issues.
- 41% said remembering multiple logins heightened stress and strained their mental health.
- 38% said they had procrastinated, delegated, or skipped work-related security-app setup.
These are self-reported findings from 2,000 full-time workers in the U.S. and Canada who primarily used a computer, worked at organizations with more than 250 employees, and were surveyed for a vendor-sponsored study published September 15, 2022. They are not independently verified incident rates or a census of all employees. 1Password’s survey summary presents the results.
The practical implication is straightforward: when authentication consumes scarce time or attention, some people optimize for getting the immediate job done rather than for the safest procedure.
Why password reuse and memory aids appear
NIST’s Authentication Diary Study describes authentication as a portfolio problem. People manage multiple user IDs, passwords, and PINs across systems, so they develop ways to reduce the effort of remembering and entering them. NIST summarizes this behavior as: “Users have developed various coping strategies for minimizing or avoiding the friction and burden associated with managing and using their portfolios of user IDs and passwords or personal identification numbers (PINs).” The 2014 report discusses password reuse, memory aids, and password-management software as examples; it does not provide a current prevalence rate for each behavior. NIST IR 7983
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The burden is a lifecycle, not just a forgotten password
Authentication work includes creating credentials, changing them, satisfying composition rules, handling expiration, finding recovery codes, enrolling a second factor, and signing in on another device. Each additional system increases the chance that an employee will write a credential down, reuse one that is easier to remember, or ask someone else to complete a step.
What the federal employee study found
A separate NIST study collected responses from 4,573 Department of Commerce employees. It reported that employees were juggling multiple passwords and felt overwhelmed by password-management lifecycle tasks. The later analysis found statistically significant links between more positive attitudes toward the rationale for cybersecurity policies and stronger password choices, less frequent writing of passwords down, and less frustration. This is a 2014 U.S. federal case study, so its relationships should not be treated as prevalence estimates for every workforce. NIST IR 7991 and the related publication page provide the study context. NIST publication
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The finding also points to an organizational factor: explaining why a requirement exists may improve cooperation, but explanation cannot compensate for a process that is needlessly difficult or unreliable.
Recommended Free Tools
Do stronger login challenges create a security-usability trade-off?
Yes. A challenge can block an attacker while making a legitimate user prove access through an unfamiliar device, a second factor, or a recovery path. Google’s 2019 account-takeover case study measured this trade-off in Google’s own service environment. It tested 14 challenge types against more than 350,000 hijacking attempts and evaluated usability with 1.2 million legitimate users.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Measure in Google’s case study | Reported result | How to interpret it |
|---|---|---|
| Device-based challenges blocking phishing-rooted hijacking attempts | More than 94% | Strong protection in the tested Google setting |
| Device-based challenges blocking automated hijacking attempts | 100% | Complete blocking of the automated attempts measured |
| Legitimate users who failed to sign in because of friction | 52% | A substantial access cost during the measured challenge flow |
| Those legitimate users who eventually accessed the account shortly afterward | 97% | Most recovered access, but not necessarily without delay or disruption |
The study demonstrates the direction of the trade-off, not a universal rate for every identity provider, employer, or authenticator. A control can be highly effective against takeover and still cause a worker to miss a meeting, defer a task, or seek an unsafe workaround. Google Research’s study contains the methods and qualifications.
Are passkeys easier for employees?
Passkeys are becoming a significant workforce direction because they can replace memorized passwords with a cryptographic credential unlocked through an approved device or platform mechanism. They may reduce repeated password entry and phishing exposure, but deployment does not automatically remove enrollment, device-change, shared-device, or account-recovery friction.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
In an April 2026 FIDO Alliance survey, 68% of surveyed organizations said they were deploying, piloting, or rolling out passkeys for employee authentication. The sample consisted of 1,400 decision-makers at organizations with at least 500 employees across ten countries. That figure measures organizational activity, not employee satisfaction, successful task completion, or proof that passkeys solve every usability problem. FIDO Alliance’s 2026 workforce report describes the sample and timing.
How to reduce risky coping without weakening security
Authentication changes should be evaluated as an access workflow, not only as a control on a security diagram. Compare the options against the conditions employees actually face:
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
| Criterion | Questions to answer before deployment |
|---|---|
| Identity-provider and device compatibility | Does the method work with the employer’s identity provider, operating systems, browsers, managed phones, and offline or remote-access scenarios? |
| Enrollment and recovery | How long does setup take, what happens after a lost phone or replaced laptop, and can help-desk recovery verify identity without creating a bypass? |
| Phishing resistance | Does the authenticator resist credential interception, and are fallback methods weaker than the primary method? |
| Shared and managed devices | Can employees use the method on tightly managed hardware, shared workstations, or multiple approved devices without exposing another person’s credential? |
| Administration | Can administrators enroll, suspend, revoke, rotate, and audit authenticators when roles or employment status change? |
Password managers
An enterprise password manager can reduce memorization and make unique credentials practical where legacy applications still require passwords. Its value depends on reliable integration, rapid recovery, and controls that prevent unsafe sharing or emergency workarounds.
Passkeys
Passkeys can reduce password reuse and phishing exposure when the organization’s devices and identity platform support them. Pilot the complete journey—including new-device enrollment and recovery—rather than measuring only the first sign-in.
Security keys
A FIDO2 security key is an optional physical authenticator for compatible deployments. Before buying or standardizing one, confirm employer support, device and browser compatibility, enrollment and revocation procedures, spare-key policy, and recovery for a lost key. The evidence above concerns device-based challenges generally; it does not endorse a particular brand or model. A workplace-authentication study is available in the SOUPS 2025 proceedings, but that research context should not be read as a product recommendation.
Free tools Windows power users keep installed
One-click scans. No signup required.
What managers should watch for
- Employees keeping credentials in visible notes or reusing a password across systems.
- Repeated help-desk requests after device changes, factor resets, or account lockouts.
- Meeting interruptions caused by delayed codes, unavailable phones, or failed challenge prompts.
- Security-app enrollment that is repeatedly postponed, delegated, or abandoned.
- Requests for informal bypasses that indicate the approved path is too slow or unavailable.
These signals call for workflow fixes rather than automatic blame. Simplifying enrollment, offering tested recovery paths, and removing redundant prompts can preserve strong controls while reducing the incentives to bypass them.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

