Are you receiving Microsoft Authenticator or MFA requests that you did not initiate yourself? This article explains what this might mean, what you should do immediately, and when you should contact FLEXAMIT.
What does an unexpected MFA request mean?
Microsoft Authenticator is used to verify that you are indeed the person trying to sign in.
If you receive such a request while you are not trying to sign in anywhere, it may mean that someone or something is attempting to sign in with your account.
This does not automatically mean that your account has already been hacked. An unexpected request can also be caused by an old session, an application trying to sign in again, or another device where your account is still configured.
What should you do immediately?
- Do not approve the request.
- Choose Deny if Microsoft Authenticator asks you to.
- If the option to report the request as suspicious is offered, use it.
- Optionally, note the time when you received the request.
- If you receive multiple unexpected requests or do not trust it, contact your IT administrator.
Why do I receive multiple requests in a row?
Attackers may repeatedly try to sign in hoping that you will eventually approve the request out of habit, confusion, or frustration.
This attack technique is often called MFA fatigue or MFA push bombing.
The principle is simple:
- An attacker tries to sign in with your account.
- Microsoft requests confirmation of the sign-in via Authenticator.
- You unexpectedly receive a notification.
- The attacker repeats this until someone accidentally approves it.
This would actually confirm the attacker’s sign-in attempt.
What is number matching?
For many Microsoft 365 sign-ins, Microsoft shows a number on the sign-in screen. In Microsoft Authenticator, you then need to enter or confirm the same number.
This is called number matching.
If you suddenly receive an Authenticator request asking for a number, you will normally not know that number. Deny the request.
Reporting suspicious activity
Microsoft Entra can be configured so that users report suspicious MFA requests directly from Microsoft Authenticator.
If your organisation has enabled this feature, you can indicate that you do not recognise the activity when you receive an unexpected verification request.
Microsoft has introduced the modern feature Report suspicious activity to replace older MFA fraud features.
Check your recent sign-ins
Do you use a Microsoft work or school account? Then you can check yourself which recent sign-ins Microsoft has registered for your account.
Check if you recognise the recent activities.
Pay attention to, for example:
- sign-ins from unknown devices;
- countries or regions you have not visited;
- sign-ins at unusual times;
- many failed sign-in attempts;
- activities that do not match what you have done yourself.
A location in the sign-in history is not always exact. VPNs, mobile connections, and internet providers can cause a valid sign-in to appear as if it comes from another city or region.
Do you need to change your password?
If you receive one unexpected request and can clearly explain where it came from, changing your password is not always necessary.
However, change your password as soon as possible when:
- you receive multiple unexpected MFA requests;
- you have recently entered your password on a suspicious website;
- you have opened a phishing email and then signed in;
- you see unknown sign-ins;
- you think someone knows your password;
- you accidentally approved an unexpected MFA request.
You can change your password via:
Did you accidentally press Approve?
If you approved an MFA request that you did not initiate yourself, treat your account as possibly compromised.
If possible, change your password and contact your IT administrator right away.
Changing your password alone is not always sufficient in such a situation. An IT administrator may also need to:
- revoke active Microsoft 365 sessions;
- check the sign-in logs;
- review your registered MFA methods;
- remove suspicious devices or verification methods;
- check if any other suspicious changes have been made to your account.
Also check your security info
Check which verification methods are currently linked to your Microsoft account.
Check if you recognise all registered methods, for example:
- Microsoft Authenticator;
- phone numbers;
- security keys;
- passkeys;
- other verification methods allowed by your organisation.
Contact your IT administrator immediately.
Not sure if the request was really from you?
If you doubt whether a Microsoft Authenticator request was legitimate, do not approve it and have it checked first.
If you receive unexpected MFA requests, have accidentally approved a request, or are unsure if your Microsoft 365 account is still secure,
contact our service desk via:
support@flexamit.com
If possible, mention when you received the suspicious request and whether you denied or approved it.
In summary
- Never approve an MFA request that you did not initiate yourself.
- Use the option to report suspicious activity if available.
- Check your recent Microsoft sign-ins.
- Check your registered MFA methods.
- Change your password if you think it is known or stolen.
- If you approved a suspicious request, report it immediately.
- When in doubt: contact your IT administrator.
Comments
0 comments
Please sign in to leave a comment.