Join our Newsletter — 33% off our NHI Course

MFA fatigue attacks: are your approval controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: MFA fatigue attacks use repeated push prompts, stolen credentials, and user annoyance to turn approval-based MFA into a bypass path, according to WorkOS, while defenders need number matching, rate limits, context-aware checks, and phishing-resistant authentication. Human approval is not a dependable security boundary when attackers can force the decision loop.

Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Understanding MFA fatigue attacks: How they work and how to defend against them”.

Key questions

Q: How should security teams reduce the risk of MFA fatigue attacks?

A: Security teams should remove approval-based MFA from high-risk access paths, replace it with cryptographic authentication, and reduce the privileges attached to any successful session.

Q: Why do repeated MFA prompts create account takeover risk?

A: Repeated prompts work because they pressure the user into a fast decision.

Q: What are the warning signs that MFA fatigue is in progress?

A: Look for many MFA requests in a short time, repeated denials or cancellations, unusual access geography, and a successful approval after a burst of failures.

Practitioner guidance

  • Enforce number matching on push MFA Replace blind approve or deny prompts with number matching so a user must see and confirm the login challenge.
  • Rate-limit repeated authentication prompts Cap the number of MFA requests per identity in a short window and suspend or challenge accounts that trigger excessive failures.
  • Move high-risk users to phishing-resistant MFA Use passkeys, platform authenticators, or hardware security keys for users who face frequent credential theft or elevated access exposure.

Bottom line: MFA fatigue works because attackers can turn a legitimate approval step into a pressure campaign against the user.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Human approval is not a stable authentication boundary: MFA fatigue succeeds because the control assumes a person can act as a reliable verifier under pressure. That assumption breaks when attackers can shape timing, repetition, and annoyance until approval becomes a relief action rather than a trust decision. The implication is that approval-based MFA must be treated as a user interface control, not a durable security boundary.

A few things that frame the scale:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

A question worth separating out:

Q: Should organisations replace traditional MFA with passkeys and adaptive controls?

A: For most programmes, yes for the primary path and no for everything else. Passkeys should become the preferred method where device support allows it, while adaptive controls decide when extra checks are needed. Traditional MFA can remain as fallback, but it should no longer be the default for every login.

👉 Read our full editorial: MFA fatigue attacks expose the limits of human approval checks


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.