Unexpected MFA Prompt? Don’t Approve It
Got an MFA prompt you didn’t request? It could mean someone has your password. Learn about MFA fatigue attacks and what you should do next.


That MFA Prompt Might Be a Hacker
You’re sitting on the couch watching TV when your phone buzzes.
Microsoft Authenticator: Approve sign-in?
You aren’t trying to log in.
A few minutes later, it happens again.
And again.
It might be tempting to hit Approve just to make the notifications stop.
Don’t.
That unexpected MFA prompt could mean someone already has your password — and that little Approve button may be the only thing standing between them and your account.
What Is an MFA Prompt?
Multi-Factor Authentication, or MFA, adds another layer of security beyond your password.
After entering your password, you may be asked to verify your identity using an authenticator app, text message, security key, passkey, or another method.
That way, stealing your password alone usually isn’t enough to access your account.
But there’s an important part of MFA that’s easy to overlook:
You still have to make sure it’s actually YOU requesting the login.
Why Am I Getting MFA Requests When I'm Not Logging In?
If an unexpected MFA request appears on your phone, someone may be attempting to sign in to your account.
And if they're reaching the MFA stage, there's a possibility they already know your password.
Attackers can obtain passwords through phishing emails, fake login pages, malware, data breaches, reused passwords, and other methods.
But MFA creates another obstacle.
The attacker has the password.
They still need you.
So they send the MFA request and hope you'll approve it.
What Is MFA Fatigue?
One technique attackers use is sometimes called MFA fatigue, MFA bombing, or push bombing.
Instead of sending one authentication request, an attacker may repeatedly attempt to log in, causing multiple approval notifications to appear on your phone.
Buzz.
Buzz.
Buzz.
Eventually, they're hoping you'll think:
"What is this thing doing? Fine. Approve."
And that's exactly what they're waiting for.
One accidental approval can potentially give the attacker the authentication they need to access the account.
What Should You Do?
If you receive an MFA request that you did not initiate, don't approve it.
Deny the request.
Then take the warning seriously.
Change the password for that account, especially if there's any chance the password has been compromised or reused somewhere else.
If the service provides recent sign-in or account activity, review it for locations, devices, or login attempts you don't recognize.
For a work or school account, contact your IT department.
And if you use that same password on other websites, change those passwords too.
What About Those Number-Matching Prompts?
Modern authenticator apps may use number matching instead of a simple Approve/Deny button.
For example, the login screen on your computer might display:
42
Your phone then asks you to enter that number before approving the login.
That's an important security improvement because it makes accidentally approving a random notification more difficult.
But the same rule still applies:
If you didn't start the login, don't complete the authentication.
Never enter a number supplied to you by someone over the phone, email, text message, or chat unless you independently know exactly what you're authenticating.
MFA Isn't the Problem
Sometimes people get frustrated with MFA.
"Why do I have to keep doing this?"
This is exactly why.
Your password can be stolen without you realizing it. MFA provides another barrier between an attacker and your email, files, photos, financial information, business systems, and other accounts.
That unexpected notification isn't MFA failing.
It may be MFA doing its job.
The MooseDenIT Tech Tip
Remember this simple rule:
If you didn't request the login, don't approve the MFA prompt.
Deny it, investigate it, and change your password if necessary.
That five-second decision could prevent an account takeover.
Need help securing your Microsoft 365 account, setting up MFA, reviewing suspicious sign-ins, or protecting your small business?
MooseDenIT provides local and remote IT support for homes and small businesses.
Visit MooseDenIT.com to learn more.
