American Journal of Advanced Multidisciplinary Innovation and Research

E-ISSN: XXXX-XXXX     Impact Factor: -

A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal

Call for Paper Volume 7, Issue 5 (September-October 2026) Submit your research before last 3 days of October to publish your research paper in the issue of September-October.

Human Factors in Passwordless Authentication Adoption

Author(s) Dr. Olivia M. Grant
Country United States
Abstract Passwordless authentication promises to reduce dependence on reusable passwords while strengthening resistance to phishing, credential stuffing, and password-reuse attacks. Public-key approaches based on FIDO2 and WebAuthn increasingly allow users to authenticate through passkeys, platform authenticators, hardware security keys, device PINs, or locally verified biometrics. Technical strength, however, does not guarantee human adoption. Users must understand what a passkey is, trust where credentials are stored, anticipate what happens when a device is lost, move between devices confidently, interpret biometric prompts correctly, and recover accounts without falling back to insecure processes. Earlier FIDO2 usability research consistently identified device loss, account recovery, setup difficulty, unfamiliar workflows, and misconceptions about biometric data as barriers even when users recognized the security benefits of passwordless authentication. More recent real-world enterprise research continues to identify recovery, hardware compatibility, user guidance, and migration from established password habits as important deployment concerns.
The present study develops a human-centered adoption framework for passwordless authentication. A synthetic sample of 600 users was divided among four authentication conditions: password plus time-based one-time password, passkey authentication with minimal onboarding, passkey authentication with explicit recovery guidance, and a fully human-centered passwordless experience integrating staged onboarding, understandable terminology, recovery visibility, multiple authenticator options, accessibility support, and contextual education. he simulated human-centered condition achieved a mean adoption-readiness score of 86.3 compared with 65.4 for minimally explained passkeys and 56.3 for the password-plus-TOTP baseline. First-attempt success reached 97%, while modeled authentication time declined to nine seconds and recovery confidence reached 91.
The analysis suggests that passwordless adoption is not primarily a cryptographic problem once strong standards are technically implemented. It is a transition-management problem involving trust, habit, comprehensibility, recovery, device continuity, accessibility, and organizational support. NIST also notes that synced authenticators may support AAL2 subject to applicable requirements but cannot satisfy AAL3 non-exportability requirements. The study concludes that successful passwordless deployment requires organizations to design not only the login event but the complete credential lifecycle, including enrollment, explanation, multi-device use, loss, replacement, recovery, and fallback.
Keywords passwordless authentication, passkeys, FIDO2, WebAuthn, human factors, authentication usability, cybersecurity adoption, account recovery, phishing resistance, digital identity
Field Engineering
Published In Volume 3, Issue 4, July-August 2022
Published On 2022-08-22

Share this