How often do you think about maximizing productivity by minimizing your involvement, while getting the same result? Or about minimizing the actions you don’t like to do, the ones that cause you a headache, that require you to think, or that don’t spark joy?
Take logging in to your device, or logging in to access online resources. Something you actually do day in, day out. Did it ever happen to you that you wished you didn’t have to take out your phone and recall some password just to get through your IAM or operating system login?
At the same time, you might already have minimum effort at your first line of defense, BitLocker Full Disk Encryption. If your company is like most businesses, BitLocker is configured with “no Pre-Boot Authentication”, and you have “NO USER ACTION” there. At least this part is covered: maximum productivity by minimum user effort.
Until you hear about YellowKey
Again, another proof that NO USER ACTION is not what it’s made out to be. To achieve no friction, “no PBA” sacrifices the most important objective of disk encryption — protecting against compromise when the device is powered off.
“Again”, because you know these vulnerabilities exist. You just didn’t want to think about it. You hoped you could believe NO USER ACTION can be good in some cases.
And so it goes. NO USER ACTION cannot be good for authentication.
NO USER ACTION for the login you do every day
But here’s the point…It can.
Exactly for the authentication you perform day in, day out. The one you wished for and never imagined could be true.
Because there, the check is not missing. Your device already verified you this morning, with everything you had, and it has not left you since. It knows you are still the one sitting in front of it. So it can answer for you, every time, and you do nothing.
We were asked to write about it for Cyber Defense Magazine: “YellowKey and the Lesson to Learn about ‘No User Action’”, July 2026 edition, page 305. Read to find out when no user action is a good design and when it is not.




