How can adaptive authentication improve customer sign-in journeys?
Imagine youβre the security guard at an apartment building. Residents badge in and out every day, saying βhi.β Over time, you get to know whoβs who β their names, voices, and even when they walk their dogs.Β
So when you see Harvey from 10B wearing that same old red coat, tangled in his beagleβs leash and fumbling with his key, you buzz him right in. What about when a new face shows up? Well, then you ask for ID, confirm theyβre on the guest list, and make them sign the log.Β
When you move that metaphor online, everything gets harder. Your customer identity and access management (CIAM) system becomes your proverbial security guard β except they canβt see whoβs on the other side of the keyboard.
If youβre running a consumer app or website, what can you do to let your Harveys in and keep imposters out? Thatβs where adaptive authentication comes in.
What is adaptive authentication?
Like its name suggests, adaptive authentication modifies the security hoops a customer needs to jump through to sign into their account based on how risky they seem and how sensitive the actions are that theyβre trying to take. Itβs also sometimes called βadaptive trustβ or βrisk-based authentication,β and is considered to be a type of multi-factor authentication (MFA).Β
MFA has gone mainstream over the last few years in response to regulatory standards and risk-averse CISOs, but many brands currently implement it as a binary. Itβs either on or itβs off. No in between.Β
True adaptive authentication β like the risk it mitigates β operates on a spectrum. It opens up lots of new βin betweenβ options by giving brands the flexibility to step security up or down based on their specific risk tolerance at any point along the customerβs journey.
How does adaptive authentication work?
Adaptive authentication works behind the scenes to figure out whether it knows the customer whoβs logging in and to determine what the risk is before the customer actually signs in. Thatβs a tall task when youβre working in an online world. In order to make the call, most adaptive authentication systems use four types of signals:
- Device data β Has this phone or desktop logged in before?Β
- Network data β Is the login coming from a reputable IP address?
- Location data β Is the login coming from a trusted locale?
- Behavioral data β Is the activity happening during a day/time when this user tends to log in?Β
β

β
By analyzing this information and weighing it against the type of access the customer is requesting, the system comes up with a risk score. Based on that score, it might let the customer connect without a password at all β say, to browse items in an ecommerce experience. Or they may be prompted for a password β say, to update their credit card information on their account.Β
When enough flags get triggered, the customer may be asked to re-authenticate with a more secure method like two-factor authentication.
How adaptive authentication can improve the customer journey
Itβs pretty easy to see how adaptive authentication can lower sign-in friction for customers β especially when theyβre visiting low-risk areas on your website like shopping or bill pay. Eliminating hurdles makes it more likely the customer will fill their cart or pay their bill.
But adaptive authentication should really be applied throughout the customerβs online journey, introducing more friction as customers perform riskier actions. For example:
- Registration β Taking advantage of device biometrics like Face ID and fingerprint recognition can prevent identity fraud and also make authentication easier for future sign-ins.
- Authentication β Checking every userβs passwords against databases of known-stolen passwords and forcing password changes when necessary can prevent imposters from using password spraying attacks to break into your customersβ accounts.Β
- Password recovery β Stepping up security by requiring two-factor authentication when customers reset or recover their passwords guards against account takeovers.
- High-risk transactions β Requiring your highest level of authentication β like Face ID or even voice ID β when your customers perform their most risky transactions (like changing the beneficiary on an account or transferring large sums of money) prevents fraud.

β
Done right, adaptive authentication helps make both your security and marketing teams happy by keeping friction as low as possible while still mitigating risk. Since it evaluates risk based on signals that require no additional clicks or actions, customers face new security hurdles only when absolutely necessary.
The secret to adaptive auth: balancing user experience vs. riskΒ
When mapping out your own adaptive authentication approach, itβs important to think critically about when, where, and why you need to place those security hurdles.Β
In addition to the four signals we talked about above (device, network, location, behavior), consider also what the user can do once they authenticate. For example, the risk is pretty low that a human attacker would log in and pay someoneβs bill. So you can make that action easy, perhaps even allow customers to do it without logging in at all (assuming you confirm that the userβs not a bot).
Compare that scenario to a customer whoβs trying to update their direct deposit account. In that case, the risk is higher so itβs appropriate to require another, more rigorous authentication.
One final factor to consider is your customersβ expectations. Not surprisingly, they vary by industry. Retail customers expect a fast and easy ecommerce experience, whereas healthcare and finance consumers expect β and may even appreciateΒ β a more rigorous authentication process that reinforces their sense of trust in their online broker, bank, or health provider.Β
Settle for nothing less than β¦ forgettableΒ
Done right, adaptive authentication offers enormous ROI for marketing and customer experience teams that want more security but donβt want the sign-in friction that comes with always-on MFA.Β
Breaking away from the βall or nothingβ approach is also a great way to stand out from the competition. Adaptive auth delivers an experience that reassures your customers in the right places while offering an utterly forgettable (aka simple) sign-in experience whenever possible.
At Strivacity, we think Harvey β from 10B, remember? β deserves a welcoming experience every time he comes home. If youβd like to learn more about how our platform enables adaptive authentication, you can read more here.
Weβd love to help you make your customersβ day.
β
