MFA fatigue attacks start after the attacker already has a password. They flood a user’s phone with approval prompts and wait for one tired or confused tap. Because the fix is mostly configuration and process, this is one of the more winnable fights in security.
What MFA fatigue attacks look like to the user
The user is at dinner, or asleep, and the phone starts buzzing. Each prompt asks them to approve a sign-in they did not start. After the tenth or twentieth prompt, some people approve just to make it stop.
Sometimes the attacker adds a phone call or text. They pose as the help desk and say, “We are fixing your account, please approve the next request.” That pairing is what makes the attack work on smart people.
CISA calls this push bombing. In its fact sheet, it describes an attacker who “bombards a user with mobile application push notifications until the user either approves the request by accident or out of annoyance.”
Why push approvals are the weak spot
Simple push approval asks one question: yes or no. The user has no context, so they cannot tell a real sign-in from a fake one. As a result, a single careless tap hands over the session.
The attack also scales cheaply. Passwords leak through phishing, reuse, and old breaches, so attackers can try many accounts at once. Then they only need one person to give in.
Uber’s September 2022 breach made this famous. According to Uber’s own security update, an attacker used a contractor’s stolen password and sent repeated MFA requests until the contractor accepted one. In other words, MFA was present and still failed.
MFA fatigue attacks also tend to arrive at bad moments. Attackers often start late at night or during a hectic workday, when people are distracted. So the timing is part of the trick, not an accident.
Number matching is the floor, not the finish line
Number matching changes the question. Instead of tapping approve, the user types a number shown on the sign-in screen into the app. So an attacker’s prompt is useless, because the user cannot see the attacker’s screen.
CISA recommends number matching as an interim step in its guidance on implementing number matching in MFA applications. Microsoft has enforced number matching for Authenticator push notifications since May 2023. Microsoft explains the setup in its number matching documentation.
Turn on the extra context too
Authenticator can also show the app name and the sign-in location. A user in Naperville who sees a request from another country has a clear reason to deny it. In addition, check any other MFA tools you use, such as VPN or payroll logins, because they may still allow plain push.
Move key accounts to phishing-resistant MFA
Number matching stops push spam. However, it does not stop an attacker who tricks the user into reading the number over the phone. For that reason, CISA calls phishing-resistant MFA the strongest option.
Phishing-resistant methods include FIDO2 security keys, passkeys, and Windows Hello for Business. These methods check the website itself, so a fake login page gets nothing useful. You do not need them for everyone on day one.
Start with the accounts that would hurt most:
- Global and billing administrators in Microsoft 365
- Anyone who approves payments or changes bank details
- Your IT provider’s admin accounts in your tenant
- Executives whose names appear on the website
Treat a denied prompt as an alarm
Here is the part most IT teams miss. A prompt the user did not start means the attacker already has a working password.
So a denied prompt is not the end of the story. It is the start of an incident.
In my experience running service delivery, the biggest gap is not the setting. Instead, it is the missing follow-up after a user says “I kept getting weird prompts.” When that report comes in, work through these steps:
- Reset the user’s password right away and revoke active sessions.
- Check sign-in logs for the source location and any successful logins.
- Look for new MFA methods the attacker may have registered.
- Review mailbox rules and forwarding settings for changes.
- Check whether the same password works on other systems.
- Thank the user publicly, so others report quickly next time.
Microsoft Entra ID also lets users report suspicious MFA prompts, which can flag the account as high risk. Turn that on, then make sure someone actually watches for the alert.
Tighten the rules around MFA itself
Attackers who get in often register their own MFA device. After that, a password reset alone will not lock them out. So control who can add or change authentication methods, and alert on every change.
Also, block sign-ins from legacy protocols that skip MFA entirely. Next, consider conditional access rules that require a compliant company device for sensitive apps. That way a stolen password plus an approved prompt still fails from an unknown laptop.
Watch prompt volume
A burst of denied requests on one account is one of the clearest signs of MFA fatigue attacks in progress. Some MFA platforms can flag or limit that kind of volume. Therefore, route the signal to someone who will act on it within minutes, not the next morning.
What to tell your employees
Keep the message short enough to remember. First, never approve a prompt you did not start.
Second, IT will never call and ask you to approve one. Third, report strange prompts at once, even at 2 a.m.
It also helps to show people what a real number matching prompt looks like. Then a strange one stands out right away. A two-minute demo at a staff meeting does more than a long email.
That third point matters most. People stay quiet because they worry about bothering anyone or looking foolish. Therefore, make reporting easy, and never punish the person who reported, even if they tapped approve first.
How WEBIT approaches this
We treat MFA as a set of settings to verify, not a box to check. That means number matching and context on every push, tighter rules for admins, and alerts for new MFA methods. It also means our cybersecurity team investigates every reported prompt as a possible compromise.
We also look at our own access first, because an IT provider’s admin accounts are a prime target. If your provider cannot tell you how their technicians sign in to your tenant, ask. Our managed IT services include that answer in writing.
Key takeaways
- MFA fatigue attacks mean the attacker already has a valid password.
- Number matching and sign-in context stop most push spam.
- Phishing-resistant MFA belongs on admin and finance accounts first.
- Every unexpected prompt should trigger a password reset and log review.
- Employees need one rule: never approve what you did not start.
Related from WEBIT: free Security Scorecard and cyber insurance readiness checklist.
Not sure how your MFA is actually configured? Talk to an owner and we will walk through it with you.





