Web's Biggest All articles
UX & Design

Locked Out and Leaving: What Amazon, GitHub, and Microsoft's Login Flows Reveal About Why You're Losing Users at the Front Door

Web's Biggest
Locked Out and Leaving: What Amazon, GitHub, and Microsoft's Login Flows Reveal About Why You're Losing Users at the Front Door

Here's a number that should make you uncomfortable: roughly 1 in 5 users who hit a login wall never come back. Not because your product is bad. Not because your price is wrong. Because signing in was annoying enough that they just... bailed.

We spent some time crawling through the authentication flows of some of the web's heaviest hitters — Amazon, Microsoft, GitHub, Apple ID — and what we found is a lot more nuanced than "big sites do it right." Some of their choices are genuinely brilliant. Some are surprisingly user-hostile. And smaller sites that treat these giants as gospel are making a very expensive mistake.

The "Security Theater" Problem

Let's start with what's actually happening when a user tries to log in to a major platform.

Microsoft's sign-in flow is a masterclass in layered security — and also in friction. You enter your email on one screen, your password on the next, then potentially a verification code, then an authenticator app prompt, then a "stay signed in?" modal. That's five decision points before you've done anything productive.

For enterprise users managing sensitive infrastructure? Totally worth it. For someone just trying to check their Xbox achievements? That's a lot of gates.

The problem isn't that Microsoft made bad choices — those choices make sense for their primary customer base. The problem is when a mid-size e-commerce site or SaaS startup looks at that flow and thinks, "Well, if Microsoft does it, we should too."

You are not Microsoft. Your users are not IT administrators. And every extra step you add to your login flow is a conversion you're quietly murdering.

What Amazon Actually Gets Right (And What It's Hiding)

Amazon's login experience is deceptively simple on the surface — email, password, done. But underneath that simplicity is an enormous amount of infrastructure working to make friction disappear.

Amazon leans heavily on device recognition and behavioral signals. If you're logging in from a device you've used before, from a location that matches your history, at a time that fits your patterns, Amazon lets you through with minimal friction. The system is doing the security work invisibly.

When something does look off — new device, unusual location, different browser — that's when the OTP texts and verification emails show up. The friction scales with the actual risk level.

This is the insight most smaller sites completely miss. They apply maximum security friction to every login, every time, regardless of context. Amazon applies it when it's warranted.

Replicating this kind of risk-based authentication isn't reserved for companies with Amazon's engineering budget. Tools like Auth0, Clerk, and WorkOS offer adaptive authentication out of the box, and they're within reach for most serious web projects.

GitHub's Lesson: Know Your User's Patience Level

GitHub's authentication flow is worth studying because it serves one of the most security-conscious user bases on the internet — developers — and still manages to keep friction relatively low.

GitHub pushed hard on passkeys and hardware security keys before most platforms even had a roadmap for it. Why? Because their users wanted that. Developers are comfortable with technical authentication methods. They find SMS codes clunky. They prefer a YubiKey tap or a biometric prompt.

The takeaway isn't "add passkeys to your site." The takeaway is match your authentication UX to your actual user's technical comfort level and expectations.

If you're running a recipe site, your users want to hit "Continue with Google" and get cooking. If you're running a platform for security researchers, they might appreciate a more robust flow. The mismatch — either direction — costs you.

The Password Reset Death Spiral

If login friction is bad, password recovery is where sites truly lose people for good.

Here's the pattern we see constantly: user forgets password, clicks "Forgot Password," waits for an email that takes three minutes to arrive, clicks a link that expires in ten minutes, lands on a page with confusing password requirements ("Must include one uppercase, one symbol, one hieroglyph"), fails twice, gives up, never returns.

Apple handles this better than almost anyone. Their password reset flow is tightly integrated with device trust — if you're on a recognized Apple device, recovery is nearly instant. The system already knows who you are.

For everyone without Apple's ecosystem, the bar is still achievable: send reset emails fast (under 30 seconds, ideally), use generous link expiration windows (an hour minimum, not ten minutes), and ditch the arbitrary password complexity rules in favor of length requirements and breach-detection checks via tools like the HaveIBeenPwned API.

NIST — the National Institute of Standards and Technology — actually updated their guidelines to reflect this. They now recommend against forcing regular password rotations and complex character requirements, because the research shows users just create weaker passwords to cope. Complexity theater doesn't make things safer. It just makes users angry.

The Social Login Trap (And When It's Actually Fine)

"Continue with Google" is everywhere, and for good reason — it dramatically reduces signup friction. But it comes with real risks that smaller sites often underestimate.

When Google, Apple, or Facebook is your authentication provider, you're one policy change away from a broken login system for your entire user base. It happens. Google has killed products that third-party sites depended on. Apple's "Sign in with Apple" requirements have caught developers flat-footed.

The smarter play: offer social login as an option, not the only option. Let users link a social account to a native account. Give them an exit ramp if the third-party provider changes its terms.

Also worth noting — "Continue with Google" performs very differently depending on your audience. For a US consumer product targeting 25–45 year olds? It's a conversion accelerator. For a B2B platform where users are logging in from work accounts that block Google OAuth? It's a liability.

Three Changes You Can Make This Week

You don't need to rebuild your auth system from scratch to stop losing users at the gate. Here's where to start:

1. Add "Remember this device" functionality. Users who trust your site shouldn't have to prove it every single time. Persistent sessions with smart expiration dramatically reduce login abandonment.

2. Audit your password reset flow end-to-end, on mobile. Sit down with your phone and walk through it like a frustrated user. Time how long the email takes. Check if the link works in Gmail's mobile app. Fix what's broken.

3. Stop requiring password changes on a schedule. Unless there's been a confirmed breach, forced rotation just trains users to add a "1" to the end of their existing password. It's security theater with a UX cost attached.

The web's biggest platforms got big partly because they understood that the login screen is a product decision, not just an IT decision. Every user who bounces at the front door is a customer you paid to acquire and then handed to a competitor.

Your login flow is the first real experience your users have with your product. Make it feel like you actually want them there.

All Articles

Keep Reading

Hooked by Design: The Manipulation Tactics Buried Inside the Web's Biggest Apps — And the Rebels Building Without Them

Hooked by Design: The Manipulation Tactics Buried Inside the Web's Biggest Apps — And the Rebels Building Without Them

Your Website Is Bleeding Users Every Second It Takes to Load — Here's What the Fastest Sites Do Differently

Your Website Is Bleeding Users Every Second It Takes to Load — Here's What the Fastest Sites Do Differently

Pay, Click, Done: How Stripe, Shopify, and PayPal Rewired the Way America Buys Online

Pay, Click, Done: How Stripe, Shopify, and PayPal Rewired the Way America Buys Online