Inclusive authentication: why the best MFA doesn’t treat everyone the same
14 July 2026 - Stephen Denning
Multi‑factor authentication (MFA) has quickly become a cornerstone of digital security. Whether you’re logging into your bank, accessing healthcare records or signing into a workplace system, you’re increasingly being asked to prove who you are using more than just a password.
For organisations, the benefits are undeniable. MFA reduces the risk of fraud, protects sensitive information and helps build trust with customers. As cyber threats continue to evolve, strong authentication is no longer a nice‑to‑have – it’s an essential part of doing business.
But as MFA becomes more widespread, another challenge is emerging. The very security measures designed to protect users can also create barriers that prevent legitimate people from accessing the services they need.
Security shouldn’t come at the expense of inclusion
No single authentication method works for everyone.
Some people don’t own a smartphone. Others work in secure environments where mobile phones aren’t permitted. Some rely on screen readers or voice control, while others may have limited dexterity or cognitive impairments. Poor mobile reception, low digital confidence or English as a second language can also make authentication more difficult. Even temporary situations can create barriers – someone with a broken wrist may struggle to use a fingerprint reader, while recovering from eye surgery could make reading one‑time passcodes difficult.
“If the only way to prove your identity is through a method you can’t use, you’ve effectively been locked out.”
This isn’t simply an accessibility issue; it’s an inclusion issue. People arrive with different abilities, technologies and circumstances, and authentication needs to recognise that diversity. If the only way to prove your identity is through a method you can’t use, you’ve effectively been locked out.
The consequences extend well beyond user frustration. Failed authentication journeys can lead to abandoned transactions, increased demand on customer support teams, more manual identity verification and exception handling, and ultimately lost revenue. At the same time, organisations are facing growing expectations to demonstrate that their services are inclusive. Legislation such as the European Accessibility Act (EAA), alongside regulations including the FCA’s Consumer Duty in the UK, is placing greater emphasis on designing digital services that are accessible, inclusive and fair.
Thinking beyond accessibility
When organisations think about accessibility, it’s easy to focus on individual technologies.
“Is our authenticator app accessible?”
“Does our SMS journey meet accessibility guidelines?”
These are important questions, but they only address part of the problem.
A more useful question is:
“Who might struggle with this approach, and what equivalent alternative can we offer?”
This shift in thinking changes the conversation completely. Rather than expecting everyone to use the same authentication method, the focus becomes ensuring that everyone can achieve the same level of security assurance through methods that work for them.
That’s the difference between accessible authentication – focusing on individual technologies – and inclusive authentication, which designs the whole journey so everyone can achieve the same level of security assurance.
Designing the whole authentication journey
An inclusive approach to multi‑factor authentication doesn’t begin and end with the moment someone enters a code or approves a notification. It considers the complete authentication journey.
That includes how users enrol for MFA, the authentication methods available to them, the day‑to‑day experience of signing in, what happens when they lose access to a device, and how they recover their account or request support if the default approach doesn’t work.
Looking at the journey as a whole often reveals barriers that wouldn’t be identified by reviewing individual technologies in isolation. An authenticator app might be fully accessible, for example, but that doesn’t help someone who isn’t allowed to use a mobile phone at work. Equally, a straightforward sign‑in process is of little value if the account recovery journey relies on inaccessible verification steps.
Independent accessibility consultancy and audits can help organisations see those patterns, rather than focusing only on single technologies.
Thinking in terms of journeys, rather than individual technologies, helps organisations identify where people are most likely to struggle and where reasonable adjustments can have the greatest impact.
Inclusion is good business
Making authentication more inclusive isn’t about lowering security standards or adding unnecessary complexity. It’s about recognising that legitimate users have different needs and providing equivalent, secure ways for them to prove who they are.
Organisations that embrace this approach are likely to see benefits that extend well beyond compliance. Removing unnecessary barriers can reduce customer effort, improve completion rates, lower support costs and strengthen trust in digital services. Just as importantly, it demonstrates that accessibility has been actively considered, that reasonable adjustments have been identified where appropriate, and that decisions have been made consciously rather than by default.
As authentication technologies continue to evolve, inclusive design should become part of the conversation from the outset, not something that’s considered after deployment or in response to complaints. Building inclusive authentication into training and development helps teams design journeys that consider different needs from the start, rather than retrofitting inclusion later.
At User Vision, we help organisations take this broader view of authentication by combining inclusive design, accessibility expertise and user research with disabled users. Usability testing with users with disabilities helps reveal where authentication journeys unintentionally exclude people. Whether reviewing an existing MFA solution or supporting the design of a new authentication journey, we help organisations understand where barriers exist, identify practical improvements and build confidence that security and inclusion are working together, not in competition.
You might also be interested in...
Why positionality matters in UX research
29 July 2026Positionality is the lens every UX researcher brings to their work. This article explores how who is asking the questions shapes what users share, how insights are interpreted, and why recognising our own perspective leads to better, more inclusive research.
Read the article: Why positionality matters in UX researchB Corp web accessibility requirements: what organisations need to know
27 July 2026B Corp’s updated standards now require organisations to assess the accessibility of public-facing websites. Here’s what that means, why it matters, and how to approach it properly.
Read the article: B Corp web accessibility requirements: what organisations need to knowNothing About Us Without Us: What CRPD at 20 Means for UX
16 June 2026As the Convention on the Rights of Persons with Disabilities turns 20, this article asks what “Nothing About Us Without Us” should mean for UX in practice. It argues that accessibility is not just about testing whether something works for disabled people, but involving disabled people earlier in shaping what gets built.
Read the article: Nothing About Us Without Us: What CRPD at 20 Means for UX