Kill the Password. Slowly, and On Purpose.
I want passwords gone as much as anyone. But I’ve watched enough “passwordless by Q3!” initiatives crash into reality to know that killing the password is less a technology project and more a demolition job — and if you swing the wrecking ball too fast, you take out load-bearing walls. The vendor demo makes it look like a switch you flip. The actual environment is twenty years of accumulated dependencies, and some of them are holding up the building.
The password is terrible and everywhere
Passwords are genuinely bad security: reused across a dozen sites, guessable, phishable, endlessly leaked in breaches you’ll never hear about. Nobody defends them on the merits — there’s no security professional out there arguing passwords are a good idea. The problem isn’t that people are attached to them. The problem is they’re wired into everything: every app, every legacy system, every integration, every user’s two decades of habits and muscle memory. That ubiquity is exactly why you can’t rip them out in a sprint, no matter how much everyone agrees they’re awful. “This is bad and we all hate it” and “we can remove it quickly” are not the same sentence.
Layer first, remove later
The move that actually reduces risk on day one isn’t removing the password. It’s making the password not matter. Strong multi-factor authentication, everywhere you can put it, so a stolen or guessed password on its own is worthless — the attacker has one factor and still can’t get in. That single step neutralizes the vast majority of the risk passwords carry, and you can do it now, across almost everything, without waiting for a multi-year passwordless migration to finish. It’s the fast, boring, high-impact move, and it’s the one I always do first.
Then you migrate the systems that can go passwordless — passkeys, hardware security keys, platform authenticators — one at a time, starting with the highest-value targets. The admin accounts, the crown-jewel systems, the things an attacker wants most: those get the real passwordless treatment first, because that’s where it buys the most. The password dies slowly, on purpose, as the safer thing quietly takes over underneath it — and crucially, at no point in that migration is anyone less safe than they were the day before.
Watch for the walls that are holding up the roof
The reason the “overnight” approach fails isn’t ambition — it’s the load-bearing dependencies you didn’t see. The legacy application that can only speak password. The batch job that authenticates with stored credentials at 3 a.m. The partner integration, the field device, the service account buried in a script nobody’s touched in years. Try to remove passwords everywhere at once and you’ll find these the hard way, when something critical breaks and you’re rolling back at midnight. A patient migration finds them one at a time, on your schedule, with a plan for each — instead of all at once, in production, as a surprise.
Don’t forget the recovery path
Here’s the trap even good passwordless projects fall into: they harden the front door and leave the back door wide open. If your shiny new passkey system falls back to “forgot my key? here’s a password reset by email,” you haven’t killed the password — you’ve just moved it to the account-recovery flow, which is exactly where attackers will now aim. The recovery and enrollment paths have to be as strong as the primary one, or the whole effort is theater. Attackers don’t attack the strong door. They attack the weak one you built next to it and forgot about.
Anyone selling you overnight passwordless is selling you a headline. The real work is a patient migration where, at every step, users are safer than they were the day before — MFA first to make the password not matter, then a deliberate, prioritized retirement of the password itself, with the recovery paths hardened and the load-bearing dependencies handled one at a time. It’s slower than the slogan. It’s also the version that actually gets the password gone instead of getting you a broken login at midnight and a rollback. Demolition done right is careful. That’s not a compromise on the goal. It’s how you actually reach it.
Free download · field manual
They Log In. They Don’t Break In.
The plumbing underneath this post: twelve runbooks — identity inventory, MFA and phishing-resistance, recertification, joiner-mover-leaver, standing privilege reduction, break-glass, non-human identity discovery, secret rotation, workload identity migration, passwordless by system, recovery hardening and credential compromise response — plus nine templates including a JML matrix, an NHI register, privilege tiering and a recovery path assessment. Free, no email required.