Accountability is shared, but security leadership owns the control design and operating model. Organisations should define who monitors authentication anomalies, who responds to suspicious approvals, and who owns user readiness. If MFA fatigue is a known risk, governance should treat it as an access control weakness that requires policy, training, and technical safeguards.
Why This Matters for Security Teams
Fraudulent MFA approvals are not just a user mistake. They are a control failure that exposes gaps in authentication design, alerting, user training, and incident response ownership. When an attacker uses a prompt-bombing or fatigue tactic, the immediate question is not only whether the user clicked approve, but whether the organisation had enough friction, telemetry, and escalation paths to detect the abuse fast enough.
This is why NHI Management Group treats authentication as an operational control, not a one-time configuration. The real risk is that a valid approval can be indistinguishable from an exhausted, coerced, or inattentive user action unless the system is built to detect abnormal context. Guidance in the Top 10 NHI Issues and the OWASP Non-Human Identity Top 10 both reinforce that identity assurance is only as strong as the weakest approval path. In practice, many teams discover the control gap only after the attacker has already moved from the first prompt to the first privileged action.
How It Works in Practice
Accountability should be split by function, not blurred by blame. The employee is responsible for following policy and reporting suspicious prompts. Security leadership is responsible for designing MFA so that repeated approvals, unusual geolocation, device changes, impossible travel, or risky session elevation are visible and actionable. IT or IAM teams own the technical enforcement path, while managers and awareness owners support user readiness. That operating model should be documented before an incident, not negotiated after one.
Effective programs add layered safeguards: number matching, phishing-resistant authenticators where feasible, session binding, conditional access, and risk-based step-up checks. For higher-value accounts, controls should move toward NIST SP 800-53 Rev. 5 Security and Privacy Controls style authentication hardening and stronger identity assurance. Monitoring should also correlate approval events with endpoint posture and behavioural anomalies, because a prompt may be approved on a compromised device. NHIMG’s 52 NHI Breaches Report shows how quickly identity weakness becomes broader access abuse once trust is misplaced. External threat reporting such as the CISA cyber threat advisories and the MITRE ATT&CK Enterprise Matrix can help teams map this activity to credential access and lateral movement patterns.
Control ownership should also include response timing, because delayed investigation turns a single approval into a full compromise. These controls tend to break down in high-noise environments with frequent legitimate push prompts and weak signal correlation, because alert fatigue masks the attacker’s activity.
Common Variations and Edge Cases
Tighter MFA controls often increase user friction, requiring organisations to balance security strength against operational speed and support burden. Current guidance suggests that there is no universal standard for how many prompts is “too many,” so thresholds should be tuned to business context and risk appetite rather than copied from another programme. For some teams, the right answer is not more prompts, but fewer prompts combined with stronger device trust and phishing-resistant factors.
Edge cases matter. Shared devices, contractors, legacy applications, and executives with special handling can all weaken standard MFA workflows if exceptions are unmanaged. Another common failure mode is treating the issue as pure user negligence when the real root cause is a control design that allows repeated prompts without adequate suppression, verification, or escalation. NHI Management Group’s Ultimate Guide to NHIs — Why NHI Security Matters Now is useful here because the broader lesson is the same: identity controls fail when they assume ideal behaviour. For threat context beyond phishing, the Anthropic report on AI-orchestrated cyber espionage and NHIMG’s LLMjacking analysis both show how quickly attackers convert identity weakness into broader access misuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Maps to authentication assurance and verifying user interactions. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity misuse follows weak approval and credential abuse paths. |
| OWASP Agentic AI Top 10 | A1 | Autonomous abuse patterns inform alerting and control design. |
| CSA MAESTRO | GOV-02 | Governance must assign ownership for authentication risk and response. |
| NIST AI RMF | Risk governance needs accountability for human and automated decision points. |
Document accountability, monitor risk signals, and adjust controls when authentication abuse patterns emerge.
Related resources from NHI Mgmt Group
- Who is accountable for keeping access changes aligned when employees change roles?
- Who is accountable when an attacker uses IAM eventual consistency to regain access after revocation?
- Who should be accountable when a fraudulent hire gains internal access?
- Who is accountable when an attacker gains Microsoft 365 access through OAuth device code phishing?