Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

If you get an MFA request you did not start, tap Deny or Reject, then report it. Never approve a prompt just to make repeated notifications stop. The attacker may already have your password and be trying to wear you down into granting access. Repeated prompts can also signal a mistaken login or another account problem, so verify through a trusted channel.

What MFA fatigue means

MFA fatigue is the pressure and confusion caused by repeated multifactor-authentication (MFA) requests. In a common form called push bombing or prompt bombing, an attacker repeatedly triggers push notifications and hopes the user will approve one by mistake, out of annoyance, or after being persuaded by a convincing story. NIST uses the broader term authentication fatigue.

This is usually not a case of an attacker cracking MFA’s cryptography. The classic attack starts with a password the attacker has stolen, guessed, or obtained from another breach. The attacker then exploits a sign-in flow that offers a simple Approve button and the human uncertainty around an unexpected request. CISA describes how repeated prompts can lead to accidental approval; Okta explains the repeated-request pattern.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How a push-bombing attack unfolds

  1. The attacker obtains a username and password.
  2. They try to sign in to the real identity provider or application.
  3. The provider sends an MFA request to the account owner’s phone.
  4. If the user denies it, the attacker may try again—sometimes generating many requests in a short period.
  5. The user may approve accidentally, tap Approve to stop the interruptions, mistake a prompt for a delayed legitimate sign-in, or follow instructions from a fake help-desk caller.
  6. If approval succeeds, the attacker may gain an authenticated session.

An unexpected prompt is therefore worth treating as a possible warning that your password has been exposed, even if you deny every request. It does not prove an account was taken over: you might have triggered a delayed prompt yourself, or someone else may have mistyped a username. But it should not be dismissed.

#1 Best Overall
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Why repeated prompts can work

A prompt that once demanded careful attention can become background noise when it appears repeatedly. Users may also receive frequent legitimate requests because of short session lifetimes, multiple applications, a new device, VPN access, or overlapping sign-in policies. If every request looks alike and offers only Approve or Deny, it can be difficult to tell what is genuine—especially while multitasking or away from the sign-in screen.

Attackers can add pressure with a plausible explanation. A caller may claim to be from IT and say the prompts are caused by a migration, a device enrollment, or a security test. Do not approve a request at the direction of an unsolicited caller or message. Contact support using a number or internal channel you already trust.

Excessive legitimate prompts are not themselves proof of an attack. They can, however, train people to approve without checking. That makes prompt overload both a possible security signal and a policy-design problem—not a reason to blame the person receiving the alerts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What to do when a prompt appears unexpectedly

  1. Deny or reject it. Do not approve it, even if more requests arrive.
  2. Report it promptly to your organization’s security team or help desk. If you use a personal account, use the provider’s trusted security or account-recovery channel.
  3. Verify the account. From a known-safe device, review recent sign-ins for unfamiliar devices, locations, applications, or other activity, if your service provides that view.
  4. Follow the organization’s response instructions. This may include changing your password from a trusted device and signing out everywhere or revoking active sessions, where those controls are available.
  5. Check recovery methods and authenticators for devices or methods you do not recognize. Do not remove legitimate methods without ensuring you can recover the account.
  6. Use a trusted contact route. Do not call a number supplied in an unexpected message or follow a caller’s instructions to approve a request.

If you did approve a request you did not initiate, treat the account as potentially compromised and contact security or the provider immediately. A password change alone may not end access if an attacker has an active session, a refresh token, a newly registered authenticator, or another form of access.

What administrators should do after suspected prompt bombing

Contain access, investigate, and check for persistence rather than relying on a password reset alone. The exact controls depend on the identity platform, but a response commonly includes:

  • Contacting the user through a separate, verified channel and establishing whether they initiated or approved a sign-in.
  • Resetting the password and revoking active sessions and refresh tokens where supported. A password reset by itself may leave existing sessions or other access paths intact.
  • Temporarily disabling push authentication if practical, or requiring a stronger available method such as number matching, a one-time code, or FIDO2.
  • Reviewing sign-in logs, the source IP addresses, devices, applications, locations, and authentication-method changes; preserving relevant logs before making changes if an investigation may be needed.
  • Checking recovery methods, mailbox forwarding rules, OAuth grants and application consents, and any privilege changes for unauthorized activity.
  • Looking for other accounts receiving repeated prompts, and considering whether to block risky sign-ins or require a compliant, managed device while investigating.

If a user reports frequent prompts but has not approved one, investigate rather than assuming the issue is harmless or blaming the user. Repeated denials can be a useful alert signal; they are not proof of an attack on their own.

Rank #3
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

Number matching: a useful interim defense

In a basic one-tap flow, a user can approve a request without seeing whether it corresponds to their own login. With number matching, the sign-in screen displays a short number, and the user enters or selects that number in the authenticator app. The request can be completed only if the numbers match. This makes blind approval much harder: the user generally needs to be at the sign-in screen that generated the challenge.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Number matching is a meaningful improvement against classic push bombing, but it is not phishing-resistant authentication. An attacker using a phishing site or an adversary-in-the-middle proxy may relay a genuine sign-in and persuade the user to enter the displayed number. Social engineering can also continue. CISA treats number matching as an interim mitigation while recommending phishing-resistant MFA where feasible; its phishing-resistant MFA guidance explains the distinction.

Product behavior is not identical across apps or sign-in surfaces. For example, Microsoft says number matching applies to Microsoft Authenticator push notifications in supported MFA and account-registration or password-reset scenarios, while certain same-device sign-ins may show a Yes/No experience. Apple Watch and Android wearable push scenarios do not support number matching, so users must use their phone. Check the current behavior for your platform and keep the authenticator app up to date. Microsoft documents its number-matching behavior and exceptions.

Rank #4
Sale
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

Which MFA methods reduce this risk?

Method Stops blind push bombing? Phishing-resistant? Main trade-off
One-tap push No No Convenient, but easy to approve without checking.
Number-matching or verified push Usually mitigates it No Requires attention to a challenge; phishing and social engineering remain possible.
TOTP authenticator code Yes, there is no push to bombard No Still phishable if a user enters the code into a fraudulent site.
SMS or voice code Yes, there is no push approval No Weaker against phishing and risks such as SIM swapping; generally a fallback, not a preferred method.
Passkey or FIDO2 security key Yes Yes, when correctly implemented Requires compatible services and a well-designed recovery and replacement process.

MFA remains substantially better than password-only sign-in, but methods differ in how well they withstand phishing and social engineering. A one-time code is not automatically safe simply because it comes from an authenticator app. CISA’s MFA guidance and method comparison place phishing-resistant options above conventional push and codes for threats such as these.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why passkeys and FIDO2 are the stronger direction

Passkeys and FIDO2/WebAuthn security keys use cryptographic credentials bound to the legitimate website or service. Unlike a push approval or a code that a person can relay, they are designed to prevent authentication from completing on a lookalike phishing site. Platform authenticators—such as device-secured credentials protected by a PIN or biometric—can make this approach convenient; physical security keys can be a good fit for administrators and other high-value accounts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

They are not a guarantee against every account threat. A compromised device, weak account recovery, or an insecure help-desk reset can still undermine protection. Plan for lost or replaced devices, enroll backup credentials where appropriate, and ensure recovery is not weaker than the main sign-in method. Some legacy applications and remote-access systems may not yet support passkeys or FIDO2; shared workstations and cross-device sign-ins also need a tested plan. NIST’s Digital Identity Guidelines address authentication fatigue and phishing resistance, while CISA recommends phishing-resistant MFA as the preferred direction.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

How organizations can reduce prompt fatigue

Stronger MFA is only part of the solution. Organizations should reduce unnecessary prompts while preserving stronger checks for risky sign-ins and sensitive actions.

  • Reduce avoidable sign-ins. Use single sign-on where appropriate, tune session and sign-in-frequency policies, and look for duplicate prompts caused by overlapping application, VPN, and identity-provider policies.
  • Make challenges harder to approve blindly. Prefer number matching or verified push over one-tap approval while planning for phishing-resistant methods.
  • Apply risk-sensitive controls. Require stronger authentication for administrators, unfamiliar devices, risky locations, and sensitive applications. Use managed-device or compliance signals where appropriate.
  • Detect patterns. Alert when a user receives an unusual number of requests or repeated denials, and consider rate limits or automated response. A threshold is a configurable signal, not proof; Okta’s example workflow uses five denials in an hour as a default example, not a universal standard.
  • Make reporting easy. Give users a clear way to report suspicious prompts and teach them to deny and report, not approve or silently ignore.
  • Design enrollment and recovery carefully. Offer accessible enrollment paths, backup authenticators, lost-device procedures, travel contingencies where needed, and help-desk verification that cannot be bypassed by an impersonator.
  • Keep automation out of human push flows. Unattended service accounts should use appropriate workload identities or other machine-identity methods rather than depending on a person to approve a prompt.

For a small organization, a manageable first step is to enable stronger push protections, review basic sign-in logs, and establish a reliable recovery process. Larger environments should also plan for centralized alerting, conditional access, privileged-account protection, legacy application coverage, and automated containment. The right implementation depends on existing identity systems and application support; buying an MFA product alone does not ensure phishing-resistant authentication.

Bottom line

MFA fatigue turns repeated prompts into an opportunity to exploit a user’s attention; it does not mean every MFA method is equally weak. If a prompt arrives unexpectedly, deny it, report it, and verify the account. Number matching reduces blind approvals, but passkeys or FIDO2 security keys are the stronger long-term answer where supported—and sound recovery procedures remain essential.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.