Skip to content
Notifications
Clear all

Is the 'passwordless' push really ready for frontline workers on shared tablets?

1 Posts
1 Users
0 Reactions
3 Views
(@dragonrider)
Reputable Member
Joined: 1 week ago
Posts: 117
Topic starter   [#11683]

Okay, I need to get this out there because I've been running a real-world experiment for the last six months and the results are… messy. Everyone talks about going passwordless as this inevitable, secure nirvana, especially for scenarios with high turnover or shared devices. Microsoft's push with Entra ID (formerly Azure AD) and the Authenticator app for passwordless phone sign-in is super slick for *me*, a knowledge worker with my own phone. But frontline workers? On shared tablets? I'm not so sure anymore.

Here's my setup:
* A team of ~50 frontline warehouse associates.
* They share 10 ruggedized tablets mounted around the facility.
* They need to log into a custom inventory web app (protected by Entra ID) for each task—sometimes 20+ times a shift.
* The goal: Ditch shared PINs, increase security, and reduce login friction.

We rolled out passwordless using the **"Microsoft Authenticator app" method**, assuming they'd approve a notification on their personal phones. Big assumptions.

**The Problems We Hit (A Non-Exhaustive List):**

* **The Personal Device Hurdle:** "I don't want work stuff on my personal phone." "My phone's battery is dead." "I left it in my locker." The policy shift and BYOD concerns were immediate.
* **The Shared Tablet Dance:** Even when we got the Authenticator app on personal phones, the workflow on a shared tablet is clunky. User goes to site, enters email, picks up tablet, waits for notification, finds phone, unlocks it, opens notification, approves… for *every single task*. The context switching killed the promised friction reduction.
* **The 'Where's My Notification?' Mystery:** This was the biggest time-sink. Sometimes the notification is delayed. Sometimes it goes to the "Other" notifications on iOS. Associates would just stand there staring at the tablet, then at their phone, then give up and ask a supervisor for the old shared PIN.
* **Onboarding Chaos:** New hire's first day? Instead of just learning the inventory system, they now need to: 1) Get a company email, 2) Install Authenticator on their personal phone, 3) Go through the passwordless registration flow, 4) *Then* start learning the actual job. We saw a huge drop-off in initial adoption.

So we looked at **FIDO2 security keys** (like YubiKeys) as an alternative for shared devices. But the logistics of distributing, physically securing, and replacing lost keys for a rotating frontline workforce felt like replacing one problem with another.

**My burning questions for this community:**

* Has anyone actually made passwordless work at scale for a true shared-device, frontline scenario **without** issuing dedicated hardware (like phones or keys)?
* Are we using the wrong method? Is **Windows Hello for Business** on dedicated kiosk devices the only real path here?
* How do you measure the ROI on this? Our login times *increased* initially. Security posture improved (theoretically), but user frustration spiked.
* Is the real answer that "passwordless for frontline" just means moving to a **different form factor**—like a wearable badge that does NFC tap-to-sign-in—that isn't fully mainstream yet?

I love the *idea* and I'm a huge proponent of killing passwords, but I'm starting to think the "passwordless" playbook for knowledge workers doesn't translate at all to the frontline. The workflows and constraints are just too different. I'd love to hear your war stories and data.

🔥


Try everything, keep what works.


   
Quote