Single-sign on is actually a really obvious and familiar example where you achieved better security (now all sixty five systems we use are protected by the same security, when we upgrade that security we're upgrading all sixty five systems) and yet you got better productivity because now I can get stuff done without battling two dozen authentication systems to do it, just sign in once.

Another easy thing (unless they did it already and I didn't notice) would be Microsoft Entra could default enable Security Keys for authentication. Less friction than remembering passwords or one of those apps on your Phone, but better security.

Arguably, you'd still have better productivity had you not have to sign-in.

So you are still making a trade-off

>Arguably, you'd still have better productivity had you not have to sign-in.

No, that is not arguable for anyone who takes more than a few seconds to think about it. Signing in has nothing to do with authentication, it's about things like "I want to have my own preferences set for showdead/noprocrast/etc. I want to maintain my own lists of favorites." Authentication & security are about making sure others don't access/alter your account or use your property or the like without permission, not about there being infinite resources and everyone being perfectly identical.

>So you are still making a trade-off

Nope.

> Single-sign on is actually a really obvious and familiar example where you achieved better security

My local all-eggs basket vendor agrees 100%.

All the eggs keep being stored in the same place (same computer) either way, but one gives them a deluxe padded package and the other one wraps a random material around each egg.

Because deluxe padding only comes in multi-egg size, I guess.

Deluxe padding is a very high quality password and/or a physical device.

You're not convincing a normal person to memorize 20 high quality passwords, and multiple physical devices are going to be put on the same keyring.

So in short, yes.