TL;DR: Repeated breaches tied to MFA fatigue, phishing, and social engineering show why mobile push is an easy-to-bypass lock and why phishing-resistant MFA based on asymmetric cryptography better fits cloud identity, according to Axiad. The decisive shift is from user-persuasion controls to authentication methods that remove approval abuse from the attack path.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Identity is the Key to SaaS Security, and You Need a Better Lock”.
Key questions
Q: What is the difference between push-based MFA and phishing-resistant authentication?
A: Push-based MFA asks a person to approve a login request, which attackers can abuse through fatigue or social engineering.
Q: Why do MFA fatigue attacks still work when MFA is already deployed?
A: They work because MFA often assumes a legitimate user will distinguish a real prompt from an attacker-generated one.
Q: Should organisations replace MFA or improve it with stronger factors?
A: They should improve it with stronger factors rather than abandon it.
Practitioner guidance
- Standardise phishing-resistant MFA for privileged and high-risk access Reserve push-based approval for low-risk scenarios only, and move administrative, remote, and SaaS access to cryptographically bound authentication methods that cannot be replayed through prompt bombing.
- Map authentication methods to attack resistance Review where your current MFA mix still depends on user approval, then rank those paths by exposure to phishing, fatigue, and help desk impersonation.
- Eliminate approval-based bypass paths Remove workflows that let attackers use repeated prompts or urgent support stories to drive a manual tap, especially where access leads to email, ERP, or cloud consoles.
Bottom line: Mobile push MFA remains vulnerable because attackers can combine fatigue, impersonation, and repeated prompts to push users into approving access.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Push-based MFA is an approval-abuse problem, not a user-training problem. Repeated prompts turn the human into the last line of defence, which means attacker persistence can eventually outrun user attention. The relevant governance failure is the assumption that a user can reliably distinguish legitimate demand from coercive pressure in the moment. Practitioners should treat approval-based MFA as a control with an inherent social-engineering failure mode.
Approval-based authentication is now a governance liability. When a control can be exhausted through repeated prompts or urgent impersonation, the programme is no longer measuring identity assurance, only user endurance. The right question is not whether MFA exists, but whether the chosen factor can resist coercion at the point of approval.
A question worth separating out:
A: Security teams should move beyond SMS OTP as the primary second factor and use phishing-resistant methods such as passkeys, WebAuthn hardware tokens, or app-based authenticators. Add device fingerprinting and step-up authentication for unusual logins or high-risk actions. The goal is to make interception harder while limiting extra prompts to situations where the risk signal justifies them.
👉 Read our full editorial: Phishing-resistant MFA is the lock identity security now needs