Repeated prompts increase risk because they create fatigue, normalise approval behaviour, and turn authentication into a pressure test. A system that depends on a user to reject every hostile request can be worn down, especially when the attacker already has valid first-factor credentials and only needs one mistake.
Why repeated MFA prompts become a weak signal
Repeated prompts stop behaving like a security check and start behaving like a social pressure mechanism. If a user sees enough prompts, the request feels routine, so one accidental approval can override the intended protection. That is why repeated MFA can reduce trust in the signal even while the system looks “more secure” on paper. Attackers often count on that erosion.
Once an attacker has a valid first factor, the remaining control is often a human decision under interruption, urgency, or fatigue. At that point the defender is no longer relying on a strong second factor alone, but on the user’s ability to reject a stream of plausible prompts without making a single mistake.
Controls such as phishing-resistant MFA and passkeys change the mechanism by reducing prompt-based approval risk and binding sign-in more tightly to the authentic device and challenge. NHIMG’s MFA Guide and Passwordless and Passkeys Guide show why prompt-heavy methods are easier to exhaust or abuse than stronger authentication flows.
How attackers turn prompt fatigue into account compromise
The attacker objective is simple: get one approval, one token, or one careless response. Prompt bombing works because it converts a technical control into a volume problem. The more times a person is interrupted, the more likely they are to accept to make the notifications stop, especially if the attacker is also using stolen credentials, vishing, or help desk pressure to make the login attempt feel legitimate.
This is also why repeated prompts can be worse than a single well-designed challenge. A single clear challenge gives the user a meaningful decision; repeated challenges create habituation. In practice, that makes the control easier to bypass through persistence rather than sophistication.
NHIMG’s Uber breach 2022 and Cisco Yanluowang breach 2022 are useful reminders that MFA fatigue is not theoretical, it is a practical access path when the user is the final gate.
What stronger MFA actually needs to do instead
Stronger MFA should reduce both guessability and repetition. The best outcome is not “more prompts”, it is fewer prompts that are harder to spoof, harder to relay, and easier for the user to trust. That usually means phishing-resistant methods, careful step-up design, and policies that avoid prompting for low-value actions that train users to approve reflexively.
Repeated prompts are especially risky when the account already has broad access, because the blast radius of one mistaken approval grows with the privilege attached to the session. In that sense, prompt fatigue is both an authentication problem and an authorization problem: if the account can do too much after one successful sign-in, the attacker only needs one successful push.
For practitioners, the relevant comparison is not “MFA versus no MFA”, but “what kind of MFA resists user fatigue, token relay, and social engineering under real attack pressure”. NIST SP 800-63 Digital Identity Guidelines is a useful reference point for phishing-resistant authenticators and assurance levels, while NHIMG’s Workforce Identity Security Guide ties that choice to day-to-day identity operations.
Risk and Threat Considerations
Repeated prompts create a reliability problem in the control itself. The more often a user is asked to decide under interruption, the more the control depends on attention, memory, and resistance to annoyance rather than on cryptographic strength or device-bound assurance. That makes the environment easier to social-engineer and harder to defend consistently at scale.
Failure mechanism: attackers exploit prompt fatigue, habituation, and notification overload until a user approves an unexpected request or stops treating the prompt as exceptional.
Impact: a single mistaken approval can convert stolen first-factor access into full account compromise, session establishment, and downstream lateral movement, especially when the account has privileged or high-impact access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant auth and authenticator assurance directly address MFA fatigue risk. |
| Recommendation — Prefer phishing-resistant authenticators and raise assurance for high-risk sign-ins. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Repeated MFA prompts concern how users are authenticated and challenged. |
| Recommendation — Strengthen user authentication flows to reduce approval fatigue and spoofable prompts. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Prompt fatigue becomes dangerous when access decisions are overly broad or repetitive. |
| Recommendation — Limit access exposure so one mistaken approval cannot grant excessive reach. | ||
Practitioner Guidance
What to verify: check whether repeated prompts are happening because of poor session duration, broken device trust, or a policy that asks for MFA on every minor action. If users are seeing prompts multiple times a day for ordinary work, the control is probably teaching compliance fatigue rather than improving assurance.
Decision rule: if the sign-in method allows simple approval of a push notification, treat repeated prompts as a weakening signal and prioritise phishing-resistant authentication, tighter step-up logic, and shorter-lived high-value sessions instead of adding more prompts.
What good looks like: users should see authentication only when risk or context changes materially, and the challenge should be hard to replay, relay, or guess. The control should feel rare, specific, and explainable, not noisy.
Practitioner takeaway: security improves when authentication becomes harder for the attacker, not merely more annoying for the user; if repeated prompts are your main defense, the human is doing too much of the control’s job.
What to measure: track repeated prompt frequency, denied-versus-approved challenge rates, and any burst patterns that suggest an active fatigue attack. A rising approval rate after prompt bursts is a warning sign, not a success metric.
Related resources from NHI Mgmt Group
- Why do repeated login prompts create more risk instead of more security?
- Why can prompting users too often for MFA increase security risk instead of reducing it?
- Why do repeated MFA prompts create account takeover risk?
- Why does authentication complexity increase security risk even when controls are stronger?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org