Your phone buzzes. Microsoft Authenticator is asking you to approve a sign-in. Thing is, you’re not trying to sign in.
Maybe you assume someone typed the wrong username. You tap Deny and go back to work.
Then another request appears.
And another.
Then your phone rings.
The caller says they are from IT. They explain that the company is updating its security system and need you to approve the next notification.
Stop. Do not approve anything. Contact your real IT or security team through a trusted method.
An unexpected multi-factor authentication request is not something employees should ignore. It can be a sign that somebody is actively trying to obtain—or already has—part of the information needed to access the account.
Repeated requests are sometimes called MFA fatigue or MFA prompt bombing. Attackers generate authentication prompts hoping the employee eventually approves one out of habit, frustration, or confusion. And attackers have become increasingly good at making the next step sound legitimate.
Why Would You Receive an MFA Request You Didn’t Start?
Multi-factor authentication, or MFA, adds another verification step after a password.
That might be:
- An authenticator notification
- A one-time code
- A security key
- A biometric check
- Another approved authentication method
The purpose is straightforward. Even if somebody steals your password, they should not automatically be able to access your account.
That is a powerful security control.
Instead of always trying to bypass it technically, they may try to convince you to complete the authentication for them.
If an attacker has your username and password and tries to log in, you may receive an MFA request. The attacker then needs you to approve it.
That is where social engineering begins.
Attackers Are Impersonating IT Support
This is not hypothetical.
In September 2026, Microsoft described active cloud intrusions that began with attackers impersonating an organization’s IT help desk. Employees received calls or messages telling them that their passkey, MFA, or single sign-on configuration needed to be updated immediately.
Victims were directed through fake or manipulated authentication experiences that could result in cloud-account compromise.
The lesson extends beyond that specific campaign. An attacker does not necessarily need to “hack” MFA if they can persuade the employee to cooperate.
The conversation may sound like:
- “We’re seeing an issue with your account.”
- “Your MFA registration is expiring.”
- “You may receive a security prompt. Approve it so we can finish the update.”
The employee believes they are helping IT. In reality, they may be helping the attacker log in.
Step 1: Do Not Approve the Request
If you did not initiate the login, do not approve the MFA request.
That sounds obvious when written on a page. It can be harder when the notification appears in the middle of a busy workday.
Employees get accustomed to clicking: “Approve. Allow. Continue. Accept.”
Attackers depend on that habit. So, once again: If you did not initiate the authentication, do not approve it.
Do not approve it because someone calls and asks you to.
Do not approve it because a text says your account will be disabled.
The MFA system itself may be legitimate, but the login behind the request may not be.
Step 2: Do Not Simply Deny It and Forget About It
Denying the request is the right first action. It should not always be the last one.
An unexpected MFA request may indicate that somebody is actively attempting to authenticate as you.
Your IT or security provider may need to investigate:
- Recent login attempts
- Unfamiliar devices or locations
- Password compromise
- Existing sessions
- Authentication-method changes
- Other unusual account activity
This is why employees should report unexpected MFA requests.
A denied prompt gives your security team information they might otherwise never receive. If employees quietly dismiss unusual authentication attempts, the company loses an early warning.
Step 3: Contact IT Using a Trusted Method
If someone calls claiming to be IT and tells you to approve the prompt, do not rely on the contact information that person gives you. Use the phone number, ticketing system, email address, or support method your company already uses.
If your organization has a tray icon, help-desk portal, internal directory, or known support number, use that.
Do not call a number from an unexpected text, suspicious email, pop-up, or webpage someone directed you to.
Verify the person through a channel the attacker did not provide.
A legitimate IT provider should understand why you are verifying the request.
Step 4: Do Not Give Anyone Your MFA Code
An attacker may not always ask you to press Approve. They might instead ask for a code.
Do not provide authentication codes to another person unless your organization’s established process specifically requires something different and you have independently verified the request.
A one-time code is designed to prove that you possess the second authentication factor. Giving the code to someone else can defeat the protection MFA is supposed to provide. Treat authentication codes like passwords.
Step 5: Be Suspicious of Urgency
Social engineering attacks often create pressure.
The caller may say:
- “Your account is about to be locked.”
- “We have to complete this right now.”
- “You’re holding up the security update.”
Urgency works because it changes how people think. Instead of evaluating whether the request makes sense, the employee focuses on solving the problem quickly.
A legitimate IT request should survive verification. Taking a couple of minutes to contact your normal support resource is a reasonable security step.
What If You Accidentally Approved It?
Report it immediately.
Do not wait to see whether anything happens. Fast reporting gives your IT or security team more opportunity to contain the account.
Depending on the situation, they may need to:
- Reset the password
- Revoke active sessions
- Review sign-in logs
- Remove unauthorized authentication methods
- Check mailbox rules
- Review cloud activity
- Look for evidence of data access
- Investigate other accounts
Microsoft’s guidance for confirmed compromise includes revoking sessions and removing unauthorized authentication methods as part of the response to identity-based attacks.
The exact response depends on what happened.
The employee’s job is not to investigate. It is to report quickly and accurately.
What If the Requests Keep Coming?
Repeated MFA prompts are another warning sign.
Attackers may generate one request after another hoping the employee eventually approves one because they are tired of seeing it.
If prompts continue:
- Do not approve them.
- Stop interacting with unexpected authentication messages.
- Contact IT or security.
- Follow their instructions regarding account changes.
- Be alert for calls or texts claiming to be support.
The repeated prompts and the follow-up “IT call” may be parts of the same attack.
MFA Is Still Worth Using
When people hear about attacks involving MFA prompts, they sometimes reach the wrong conclusion— that MFA doesn’t work. That is not the lesson.
MFA remains an important protection because a stolen password by itself may not be enough for the attacker.
The fact that attackers sometimes need to trick the employee into completing the second step shows why that second step matters.
MFA is not simply pressing Approve when your phone asks. It’s verifying that you are the one initiating the login request.
If you did not initiate it, that is valuable information.
Give Employees an MFA Rule They Can Remember
Security guidance works best when it is simple.
If you receive an MFA request you did not initiate:
- Do not approve it.
- Do not provide anyone with an authentication code.
- Report it to IT or security immediately.
- Verify any IT contact through your normal support channel.
Employees do not need to understand cloud authentication architecture.
They just need to be able to recognize when something is wrong and know what to do next.
Explaining the “why” helps give importance to the information.
An unexpected prompt may mean somebody is testing stolen credentials. A follow-up phone call may be social engineering. A request to read a code aloud may be an attempt to complete the attack.
Now the employee understands the story behind the notification instead of simply memorizing another IT rule.
The Most Important MFA Button May Be “Report”
MFA gives businesses another layer of protection after the password, but employees are still part of that protection.
An unexpected authentication request should create a response.
Stop. Verify. Report.
At STS, we believe security tools work best when the people using them understand what they are seeing. Technology can block a tremendous amount of malicious activity, but employees also need clear guidance for the moments when an attacker tries to involve them directly.
So the next time your phone asks “Are you trying to sign in?” and the answer is no, remember:
The prompt is not an inconvenience. It may be your early warning.
