NARU perspectives · Enterprise technology

Rethinking the moment of login.

A NARU perspective on why the credential matters as much as the number of authentication steps.

01 / THE PERSPECTIVE

The problem is the reusable secret.

A password works because a person and a service share a secret. That secret can be reused, disclosed or entered into the wrong place. Adding a second step improves some scenarios, but the details still matter. A one-time code can be handed to a convincing fake login page while it remains valid. The right question for a sensitive application is therefore more precise than whether MFA is enabled. Ask what the factor proves, how it is bound to the service and what an attacker could obtain by imitating the login experience. Those questions make differences between authentication methods easier to evaluate.

02 / THE PERSPECTIVE

FIDO changes what the service receives.

In a FIDO-based flow, an authenticator protects a private key while the service holds the corresponding public key. The service issues a challenge, the authenticator signs it and the service verifies the result. A fingerprint or another supported local verification method can unlock the credential. The biometric is part of proving presence at the authenticator; it is not a password sent to the website. Binding the authentication to the legitimate service is what makes the approach resistant to credential phishing. The security benefit is a property of the complete flow, so browser, device, application and policy compatibility still need to be checked.

03 / THE PERSPECTIVE

A deployment is a user journey.

A security key does not arrive with an organisation’s enrolment and recovery policies already designed. Decide who registers a key, how identity is checked during enrolment, whether a spare is needed and how a user recovers access. Test those procedures with the people who will use and support them. A mobile employee and an administrator at a fixed workstation may prefer different formats. Shared devices introduce another set of design decisions. Accessibility and exceptions should be part of the plan from the beginning. Recovery deserves particular attention because a weak fallback can undermine a strong everyday authentication method.

04 / THE PERSPECTIVE

Start where stronger assurance matters most.

Inventory the applications and accounts where a compromised login would have the greatest consequence. Administrators, financial approvers and other high-risk roles are useful candidates for an initial assessment. Confirm the interfaces each application supports, then run a bounded pilot that covers enrolment, ordinary use, recovery and support. Measure user effort and operational issues alongside the security objective. Some legacy applications will require additional work or a different path. A phased programme lets the organisation learn without assuming every password can disappear at once. The aim is a sustainable authentication policy that gives people a workable experience while reducing dependence on credentials an attacker can copy or persuade them to disclose.

05 / THE PERSPECTIVE

Explore the next step.

01

Continue exploring

See the related capabilities and start with a question relevant to your environment.

Explore further
BUILD WHAT COMES NEXT

Your next chapter
starts with a conversation.

One workflow. One access challenge. Let’s find the right place to begin.

Let’s talk possibilitiesRequest a proof of concept
Book a consultationExplore solutions