Unlimited retries let an attacker keep generating prompts until a user gives in or makes a mistake. Without challenge-rate controls, the system turns repeated authentication attempts into a harassment loop, which is exactly what push fatigue attacks depend on.
Why unlimited retries make push fatigue attacks easier
Unlimited MFA retries remove the natural break that would slow down abuse. That means an attacker can keep triggering prompts until the target stops paying attention, approves a request out of annoyance, or loses track of which alert is legitimate. The control failure is not just inconvenience, it is the removal of friction that normally interrupts social engineering.
Once the system allows repeated prompts with no throttling, the attacker can pace the harassment around the user’s routine, making the attack feel persistent rather than unusual. That is why push fatigue is effective: it converts authentication into a repeated nuisance event and relies on the user eventually choosing relief over caution.
Unlimited retries also weaken user judgement because each prompt looks like another routine login challenge. Without rate limits, lockouts, or escalating verification steps, the system gives the attacker more opportunities to exploit confusion, urgency, and alert overload. The risk grows when the same account can be targeted across long periods or across multiple devices.
How retry abuse turns authentication into harassment
Push fatigue is fundamentally a control-design problem. The attacker does not need to break the authenticator; they only need enough retries to wear down the person receiving the prompts. A well-designed MFA flow should make repeated denial cheap for the defender and expensive for the attacker. Unlimited retries invert that relationship.
From the user’s perspective, repeated prompts create three failure modes: prompt blindness, accidental approval, and desensitisation. Prompt blindness happens when people dismiss alerts without reading them. Accidental approval happens when users tap through alerts too quickly. Desensitisation happens when a stream of prompts makes the event feel normal, which is exactly the condition an adversary wants.
For that reason, retry limits are not a cosmetic anti-abuse setting. They are part of the authentication boundary itself, because they shape whether repeated challenge traffic remains a signal of possible compromise or becomes a tool for coercion.
What good MFA retry controls should change
The right response is to limit the attacker’s ability to spam the user while preserving a reliable path for legitimate access. That usually means challenge-rate controls, step-up checks after repeated failures, and detections that treat prompt bursts as suspicious rather than routine. The surrounding sign-in design matters too, especially whether the method resists phishing and whether the user can distinguish one request from another.
Useful supporting guidance is to compare this pattern with stronger sign-in options and attack paths in the MFA Guide, which covers fatigue, relay, and phishing-resistant methods. For a broader identity hardening approach, the Workforce Identity Security Guide ties push fatigue to recovery flows, federation, and help desk controls that often determine whether an attacker can keep pressure on the user.
Attackers also benefit when the victim’s environment has weak fallback controls. If repeated prompts can be paired with social engineering, stolen credentials, or session theft, the retry loop becomes one part of a larger compromise chain rather than an isolated annoyance. Public incidents such as the Uber breach 2022 and the Cisco Yanluowang breach 2022 show how fatigue can be paired with other access paths to turn a nuisance into valid access.
Risk and Threat Considerations
Unlimited MFA retries create a direct abuse path because the attacker can sustain pressure until the user makes a mistake or the organisation misses the activity. The more permissive the retry policy, the more the control behaves like a harassment channel instead of a security check.
Failure mechanism: The system allows repeated push prompts with no meaningful throttle, so the attacker can keep the target in a state of alert fatigue until an approval, dismissal mistake, or secondary compromise occurs.
Impact: This increases the likelihood of account takeover, especially when push approval is the only step standing between the attacker and a valid session, internal access, or downstream privilege escalation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant authentication and retry behavior affect sign-in assurance. |
| Recommendation — Prefer phishing-resistant authenticators and bound challenge attempts to reduce prompt-fatigue abuse. | ||
| CIS Controls v8 | CIS-5 — Account Management | Retry abuse is an account-access control issue that depends on limiting harmful sign-in patterns. |
| Recommendation — Limit repeated authentication prompts and monitor abnormal account access attempts. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Unlimited retries weaken organizational user authentication assurance and allow coercive sign-in abuse. |
| AC-7 — Unsuccessful Logon Attempts | Retry throttling directly addresses repeated failed or denied sign-in attempts. | |
| Recommendation — Apply bounded authentication controls that prevent repeated prompt abuse. Enforce limits on consecutive failed authentication attempts and related lockout behavior. | ||
Practitioner Guidance
What to verify: Check whether the MFA flow enforces prompt-rate limits, temporary lockouts, or escalating verification after repeated denials. If the user can receive endless prompts from the same source, the control is already too permissive.
Decision rule: If the sign-in method depends on a simple approve-or-deny push, treat unlimited retries as a material weakness and prefer a phishing-resistant method or a step-up path for repeated attempts. If retries are bounded but still noisy, tune the threshold based on how long a real user can safely wait without losing access.
What to measure: Track repeated-denial events, prompt bursts per account, and time between first prompt and final approval. A spike in these signals usually indicates abuse, not normal user behaviour.
Practitioner takeaway: The important design choice is not whether MFA exists, it is whether the retry policy makes abuse cheaper than resistance. If repeated prompts can continue indefinitely, the attacker owns the user’s attention budget.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org