The smell of MFA fatique

Vu Nguyen 0 Reputation points
2026-05-18T16:44:42.6166667+00:00

I got like 2 sign-in requests from my Authenciator app. Changed my password twice and did not enable passwordless mode at all. I also did not download any malicious craps. (checked via Windows Defender and Malwarebytes)

I searched the Internet to look for reasons and ways to prevent it. Did see some posts with the same situations but the answers were kinda disappointing.

Should I just ignore the request and move on or there's a better way to prevent it? I'm really tired of changing my password back and forth.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-05-18T16:44:56.85+00:00

    Unrequested MFA prompts should never be approved, and they are a signal to harden the account rather than something to just ignore.

    Actionable steps:

    1. Treat the prompts as possible attack attempts
      • Unrequested verification codes or prompts can mean:
        1. Someone is trying to access the account.
        2. Someone mistyped their email/phone.
        3. A delayed delivery of a code requested earlier.
      • Do not approve any MFA request or respond to any code that was not explicitly initiated.
    2. Turn on or strengthen MFA everywhere
      • Multifactor authentication is still one of the strongest protections. Password compromise attacks are responsible for most successful account hacks, and MFA can defeat almost all of them.
      • Use strong methods such as Microsoft Authenticator, Windows Hello, or a physical security key instead of just SMS where possible.
    3. Consider going passwordless instead of repeatedly changing passwords
      • Going passwordless removes the password and uses a passwordless method (Windows Hello, Microsoft Authenticator, SMS/Email codes, or physical security keys) to sign in.
      • Passwordless sign-in is more secure and convenient, and it reduces the impact of password-guessing or password-spraying attacks that can trigger MFA prompts.
      • See the guidance under “Go passwordless” for work or school accounts to reduce unwanted code prompts.
    4. Review sign-in activity
      • Check recent sign-in activity (for work/school accounts via My Sign-ins) and look for unfamiliar successful or unsuccessful sign-ins.
      • If any successful sign-in looks suspicious (wrong device, OS, browser, or location), immediately change the password and update security info.
      • If there are many unsuccessful sign-ins, that can indicate someone is trying to guess the password; MFA will block them, but it is still recommended to keep MFA enabled and consider a password change.
    5. If lockouts or repeated attempts continue
      • If there are many sign-in attempts, Microsoft Entra multifactor authentication may temporarily block additional attempts to counter threats.
      • If there is suspicion that someone else is actively trying to access the account, contact the organization’s IT administrator or Help desk so they can review Microsoft Entra sign-in logs and, if needed, reset MFA methods.

    In short: do not approve unrequested prompts, keep MFA enabled (or move to passwordless), review sign-in activity, and involve admin/support if suspicious activity persists. Repeated password changes alone will not stop attackers from trying, but MFA/passwordless will prevent them from getting in.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.