Skip to content
F1 IT SolutionsF1 IT Solutions
0%

Your partner in tech

Under attack?Get emergency help now
All articles
20 July 2026F1 IT Solutions

MFA Fatigue Attacks: Why 'Just Add MFA' Isn't Enough Anymore

MFAIdentity SecurityCybersecurityPhishingManaged ITAccess Management
MFA Fatigue Attacks: Why 'Just Add MFA' Isn't Enough Anymore

For years, the advice was simple: turn on multi-factor authentication and most account takeover risk goes away. That advice hasn't aged well. Attackers have adapted, and one technique in particular, MFA fatigue, is quietly undoing the protection that push-based authentication was supposed to provide.

What an MFA fatigue attack actually looks like

The attacker already has a valid username and password, usually from a previous breach, a phishing kit, or credential stuffing against a reused password. That's normally where the attack stalls, because logging in also triggers a push notification to the user's phone asking them to approve the sign-in.

Instead of giving up, the attacker simply tries again. And again. Sometimes dozens of times in a row, often late at night or during a busy morning when the target is distracted. Eventually, out of irritation, confusion, or the assumption that it's a glitch, someone taps "approve". The attacker is in, with a legitimate, fully authenticated session.

Some variants add a social engineering layer: a follow-up call or message pretending to be from IT support, asking the user to "confirm" the prompt to "fix" the issue. This combination of technical pressure and a plausible human explanation is what makes the technique effective even against people who know better in theory.

Why this matters for ordinary businesses, not just big targets

MFA fatigue doesn't require sophisticated tooling. It relies on volume and patience, which makes it accessible to a wide range of attackers, not just well-resourced groups. Any business using push-based MFA on Microsoft 365, VPNs, or cloud admin consoles is a potential target, regardless of size.

It's also a technique that slips past the usual defences. Firewalls, spam filters, and endpoint protection don't see a login approval as malicious, because technically it isn't. It's a real user approving a real prompt. The failure point is human decision fatigue, not a software gap.

Moving beyond "just enable MFA"

The fix isn't to abandon MFA. It's to make the second factor resistant to being rubber-stamped under pressure. A few practical steps make the biggest difference:

Turn on number matching

Most major identity providers, including Microsoft Entra ID, support number matching as a setting rather than a simple approve/deny push. The user has to enter a number shown on the sign-in screen into their authenticator app, which breaks the "tap without thinking" reflex and stops blind approval in its tracks. If this isn't switched on in your tenant yet, it's one of the highest-value changes you can make this quarter.

Cap and throttle repeated prompts

Configure sign-in risk policies so that a burst of failed or repeated authentication attempts triggers a temporary lockout or an alert to IT, rather than simply generating more prompts for the user to deal with. A flood of requests should be treated as a red flag, not tolerated as normal traffic.

Move toward phishing-resistant authentication

Where it's practical, phishing-resistant methods such as FIDO2 security keys or platform passkeys remove the human approval step from the equation entirely. These methods are cryptographically bound to the legitimate site or service, so there's no prompt to fatigue someone into approving in the first place. Rolling this out fully across a business takes planning, but starting with high-privilege accounts, finance staff, and admins gives you the best return for the effort.

Train people on this specific scenario

General phishing awareness training often doesn't mention MFA fatigue by name. Make sure staff know that a flood of unexpected approval requests is not a technical fault to dismiss, it's a sign someone else has their password. The correct response is to deny every prompt and report it immediately, not to approve one to make the notifications stop.

Monitor and respond to anomalies

Sign-in logs will usually show the tell-tale pattern: repeated MFA prompts from the same session in a short window, often from an unfamiliar location or device. Continuous monitoring, whether through your identity provider's own alerting or a managed detection and response service, means someone is watching for that pattern even when the affected employee doesn't recognise it.

The takeaway

MFA remains one of the best security investments a business can make, but the "set it and forget it" version of MFA is no longer enough on its own. Number matching, sensible throttling, a path toward phishing-resistant authentication, and staff who know what an MFA fatigue attack looks like together close the gap that attackers are currently exploiting. None of these changes are dramatic on their own, but together they turn MFA back into the strong control it was always meant to be.

Want this handled for you?

Talk to the F1 team about managed IT, cybersecurity and cloud for your business.