The MFA Prompt You Approved Too Fast

Turning on MFA is not the finish line. Two attacks now walk straight past the approval prompt in Microsoft 365 and Google Workspace, and how phishing-resistant sign-in shuts both down.

A payroll administrator at a distribution company near Mississauga started her Tuesday the way she starts every Tuesday, with a coffee and a phone that would not stop buzzing. Her Microsoft Authenticator app kept throwing approval prompts at her, five of them inside a few minutes, and she had not tried to sign in to anything. She figured the app was glitching. Somewhere around the sixth prompt, wanting the buzzing to end so she could get on with her morning, she tapped Approve. That single tap handed a stranger a fully signed-in session on her account.

Nothing was glitching. A man she never met already had her password, pulled from a breach dump where she had reused it, and he was standing at the Microsoft login screen firing off sign-in attempts. Each attempt sent a fresh prompt to her phone. He was betting that if he sent enough of them, she would eventually clear one just to make them stop. She did, and that was all he needed.

The prompt is the weak point now

For years the advice was to turn on multi-factor authentication and you would be fine, and for a long time that was close enough to true. The trouble is that attackers went where the advice sent everyone. Passwords still leak by the billion through breaches and reuse, so a criminal buying a working password is cheap and common. The only thing standing between that password and your inbox is the approval prompt, which means the prompt itself has become the thing worth attacking. And the prompt has a soft spot, because a person holds it, and people get tired, distracted, and worn down.

The attack that got my payroll example has a plain name, push fatigue, sometimes called prompt bombing. It is exactly what it sounds like. The attacker has the password and simply floods the account with sign-in attempts until the real owner approves one out of habit or exhaustion. This is how Uber was breached in 2022. An attacker bought a contractor's credentials on the dark web, bombed the account with approval requests, and then messaged the contractor on WhatsApp posing as Uber IT, telling them to approve the prompt to make the noise stop. The contractor approved. From there the intruder moved deep into internal systems. A company with a serious security budget was undone by a tired person tapping a green button.

The careful people get caught too

Maybe you read that and think your team is too switched on to approve a prompt they did not start. That instinct is good, and there is a second attack built specifically to beat it.

It is called adversary-in-the-middle, and it does not rely on you making a mistake at the prompt. The attacker sends a convincing email with a link to a login page that looks perfect, because it is a live proxy sitting between you and the genuine Microsoft or Google sign-in. You type your password into the fake page, it passes your password straight to the real site, the real site asks for your MFA, and you complete it on your own phone the way you always do. Everything succeeds. You land on your real inbox and notice nothing wrong. While all that was happening, the proxy quietly copied the session cookie that the login handed back at the end.

That cookie is the part most people have never heard of, and it is the whole game. A session cookie is a wristband that says this browser already passed the check, so let it back in without asking again. The attacker imports your stolen cookie into their own browser and walks into your mailbox wearing your wristband. They never needed your password again. They never touched your phone. Your MFA worked flawlessly and protected nothing, because it was never the target. The cookie behind it was.

These kits are not exotic. They are sold as a service with names like EvilProxy and Tycoon, cheap monthly subscriptions that let someone with no real skill run a proxy phishing campaign from a template. Microsoft reported one adversary-in-the-middle campaign that targeted more than ten thousand organizations. The barrier to running this against a small firm in Oakville or Burlington is close to nothing.

What actually closes both doors

The fix is not more of the same MFA, because the phishable kind is the problem. There are a few settings that move you onto sign-in that these attacks cannot beat, and they are within reach of any firm on Microsoft 365 or Google Workspace.

Start with number matching, which is now the default in Microsoft Authenticator and available as an equivalent in Google's prompts. Instead of a plain approve-or-deny button, the login screen shows a two-digit number that you have to type into your phone. Push fatigue dies on the spot, because you cannot type a number you never saw, and a flood of blank prompts gives the attacker nothing to work with. If your tenant is a few years old and still shows simple yes or no approvals, that is the first thing to change.

The stronger move, and the one worth planning toward, is passkeys and hardware security keys, the FIDO2 standard that both platforms now support. These are phishing-resistant in a way approval prompts can never be, because the credential is cryptographically tied to the real website address. When you land on a proxy pretending to be Microsoft, the passkey checks the actual domain, sees that it is wrong, and refuses to sign. There is no code to read out, no prompt to approve under pressure, and nothing for a middleman to relay or steal. The adversary-in-the-middle attack simply has nothing to grab.

Two more settings finish the job. Block legacy authentication, the old mail protocols that ignore MFA completely and quietly wave attackers past every control you have set up, since many tenants built years ago still have that door propped open. And use conditional access, or Google's context-aware rules, to shorten how long a session cookie stays valid and to require that sign-ins come from a known, managed device. A stolen cookie that dies in an hour and refuses to work from an unfamiliar laptop is a much smaller prize.

Worth an hour this week

If turning on MFA was the moment you filed identity under handled, this is the gap that decision left open. Open your sign-in method settings and check whether you are still allowing simple approve-or-deny prompts, then look at whether legacy authentication is switched off. We covered how a single stolen session feeds directly into wire fraud in our piece on how invoice fraud starts in your inbox, and how attackers skip the login entirely in the app that walks past your MFA. The through-line across all three is that identity is where these fights are won or lost. If you want a second set of eyes on how your sign-in is configured, that is the ground our managed security and compliance work covers, and you can reach out any time.