Category: Security · View source ↗
Security
MFA Fatigue Attack Response
A user is getting a flood of MFA push prompts they didn’t start (push bombing / MFA fatigue) — treat the password as already known, contain the account, and drive the tenant toward number-matching so approval spam stops working.
Connectors: none — works with Thread out of the box
Role: Security & Compliance Owner, Technician
Outcome: Faster Resolution & Response, Risk & Compliance
When to use: A user reports a burst of MFA push notifications they didn’t trigger; a “multiple MFA attempts” or “MFA fatigue” alert lands as a ticket; or a user says they “approved one by accident” to stop the prompts (treat as approval-until-proven-otherwise).
Run it: on one ticket (an MFA push-bombing report or alert).
Was this page helpful?
⌘I