Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Adaptive MFA and fatigue attacks: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19841
Topic starter  

TL;DR: MFA fatigue is turning repeated prompts into a security and productivity problem, with Gartner, Forrester, and enterprise surveys cited in the SecureAuth article showing 68% of users frustrated by prompts and 156% growth in fatigue attacks. The case for adaptive MFA is no longer about convenience alone: static MFA assumes user attention is reliable, while attackers deliberately exploit the gap between prompt volume and human judgment.

NHIMG editorial — based on content published by SecureAuth: Adaptive MFA and the MFA Friction Crisis

Questions worth separating out

Q: How should security teams reduce MFA fatigue risk without weakening access control?

A: Security teams should reduce MFA fatigue risk by adding number matching, device binding, prompt throttling, and clear reporting paths for suspicious requests.

Q: Why do repeated MFA prompts create account takeover risk?

A: Repeated prompts work because they pressure the user into a fast decision.

Q: What are the warning signs that MFA is creating too much friction?

A: High prompt volumes, frequent approval times that look reflexive, rising help desk tickets, and users seeking workarounds all suggest the control is becoming counterproductive.

Practitioner guidance

  • Implement number matching for push notifications Require a user-entered code from the login screen so an approval must be tied to an active session, not just a vague notification.
  • Classify and reduce low-risk prompt volume Map where prompts are occurring most often, then remove unnecessary challenges for managed devices, trusted networks, and low-risk sessions.
  • Adopt phishing-resistant authentication for sensitive users Prioritize passkeys or other strong, phishing-resistant methods for administrators, finance users, and other high-impact accounts.

What's in the full article

SecureAuth's full article covers the implementation detail this post intentionally leaves in the source:

  • Step-by-step adaptive MFA rollout phases from baseline analysis through expansion and optimisation
  • The specific risk signals used to score authentication context, including device, geography, time, and behaviour
  • Method-by-method comparison of SMS OTP, email OTP, push, biometrics, and FIDO2 passkeys
  • Operational guidance on number matching, exception handling, and monitoring prompt fatigue metrics

👉 Read SecureAuth's analysis of adaptive MFA, fatigue attacks, and user friction →

Adaptive MFA and fatigue attacks: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19434
 

Adaptive MFA is a human identity control, not an authentication strategy in isolation. The article is right to frame MFA fatigue as an experience problem, because repeated prompts change user behavior. But for IAM practitioners, the deeper point is that the control only works when human judgment is still available. Once attackers turn the prompt into a nuisance, the control is being measured by its weakest interaction point, not its cryptographic strength. That means authentication policy has to be designed around how humans actually respond under pressure.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations replace traditional MFA with passkeys and adaptive controls?

A: For most programmes, yes for the primary path and no for everything else. Passkeys should become the preferred method where device support allows it, while adaptive controls decide when extra checks are needed. Traditional MFA can remain as fallback, but it should no longer be the default for every login.

👉 Read our full editorial: Adaptive MFA is a response to authentication fatigue and attack abuse



   
ReplyQuote
Share: