Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What are the warning signs that MFA fatigue…
Threats, Abuse & Incident Response

What are the warning signs that MFA fatigue is in progress?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: Threats, Abuse & Incident Response

Look for many MFA requests in a short time, repeated denials or cancellations, unusual access geography, and a successful approval after a burst of failures. Those signals show the attacker is probing the human decision loop rather than exploiting a technical flaw.

How to recognise MFA fatigue while it is unfolding

mfa fatigue usually looks noisy before it looks successful. Repeated prompts, denials, and cancellations are the core pattern, but practitioners should also watch for timing anomalies, repeated prompts outside normal working patterns, and access attempts from unusual geographies or devices that do not fit the user’s usual profile.

A useful way to interpret the signal is that the attacker is testing whether the user will eventually approve under pressure. The warning signs are therefore behavioural and temporal, not just technical, and they often appear before any account is actually compromised.

Why the approval pattern matters more than a single push

A lone MFA prompt can be benign, but a burst of requests followed by a successful approval is a strong indicator of social-engineering pressure rather than a password or token flaw. That is why defenders should treat the sequence as the unit of analysis: frequency, persistence, and eventual consent together tell you more than any one event.

The same logic applies when the prompt stream is paired with sign-in anomalies such as impossible travel, unfamiliar IP space, or a device that has not been seen in the user’s normal access history. When those signals line up, the issue is no longer just alert noise, it is an active attempt to wear down the user’s judgment.

For broader context on how attackers abuse push-based approvals and weak sign-in workflows, the MFA Guide and Workforce Identity Security Guide show why phishing-resistant MFA and recovery controls matter when the sign-in channel itself becomes the target.

What the pattern usually tells an investigator

Once the warning signs appear, the immediate question is whether the user was merely annoyed or whether the account was already being tested for downstream access. A sustained denial pattern, especially if it ends in one acceptance, can indicate the attacker had valid primary credentials and was waiting for the second factor to be approved.

That is why responders should review the entire access chain, not just the MFA event stream. Correlating repeated prompts with sign-in logs, help desk contact, session creation, and any follow-on privileged activity helps distinguish nuisance activity from the early stage of a real compromise.

Real-world incidents show how this plays out. In Uber breach 2022, Cisco Yanluowang breach 2022, and Twilio 0ktapus breach 2022, the human approval path was part of the attacker’s access strategy, not a side effect of a technical failure.

Risk and Threat Considerations

MFA fatigue is dangerous because it turns a control designed to resist credential theft into a pressure point. If the attacker can generate enough prompts, the defense can fail without malware, exploitation, or a broken cryptographic mechanism, which makes the threat easy to underestimate in noisy environments.

Failure mechanism: The attacker uses valid credentials or an existing sign-in flow to trigger repeated MFA prompts until the user approves, cancels less often, or accepts out of confusion or urgency.

Impact: Once a prompt is approved, the attacker can establish a session, move laterally, access mail or SaaS data, and sometimes reach privileged systems before the compromise is recognised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63, NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesCovers phishing-resistant MFA and authenticator assurance for repeated sign-in prompts.
Recommendation — Prefer phishing-resistant authenticators and step-up rules that resist approval fatigue.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Applies because the warning signs concern user authentication and MFA sign-in events.
AU-6 — Audit Record Review, Analysis, and ReportingNeeded to correlate prompt bursts, geolocation, and follow-on session activity.
AC-7 — Unsuccessful Logon AttemptsRelevant because repeated denials and cancellations reflect repeated failed sign-in attempts.
Recommendation — Monitor authentication anomalies and require stronger verification for suspicious sign-ins. Review sign-in telemetry quickly and correlate MFA events with session and privilege logs. Alert on repeated failed or denied sign-in attempts within a short time window.
OWASP ASVSV6 — AuthenticationAuthentication controls must withstand repeated prompts and approval abuse.
Recommendation — Require phishing-resistant authentication paths that do not depend on user fatigue tolerance.
MITRE ATT&CKT1621 — Multi-Factor Authentication Request GenerationMaps directly to adversaries repeatedly generating MFA prompts to wear down the user.
Recommendation — Detect repeated MFA request generation and investigate it as active adversary activity.

Practitioner Guidance

What to verify: Do not stop at the count of prompts. Verify whether the requests came from one source, whether the same user saw repeated prompts across a short window, and whether a successful approval immediately preceded token issuance, new session creation, or privilege use.

What good looks like: The account owner should be able to challenge an unexpected prompt, the SOC should see the full prompt burst in telemetry, and the organisation should be able to correlate the event with device, geolocation, and session history fast enough to contain it before lateral movement begins.

Decision rule: If the prompt burst is paired with an unusual geography, an untrusted device, or a successful approval after repeated denials, treat it as a probable live attack and escalate as an identity incident, not a help desk nuisance.

Practitioner takeaway: MFA fatigue is identified by sequence and pressure, not by a single alert, so the operational priority is to detect prompt storms early and respond before a tired user becomes the attacker’s approval channel.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org