Repeated Microsoft MFA prompts from foreign locations despite password resets. Is this a known attack pattern?
I've been looking into a recurring MFA prompt scenario on a personal Microsoft account and I'm curious how security professionals would classify and investigate this behavior. The pattern: User receives unsolicited Microsoft Authenticator push approval…
I've been looking into a recurring MFA prompt scenario on a personal Microsoft account and I'm curious how security professionals would classify and investigate this behavior. The pattern: User receives unsolicited Microsoft Authenticator push approval requests. Requests originate from foreign locations and rotate between countries. The user denies every request. Password resets do not appear to reduce the frequency. Consumer account sign-in history may show only successful logins, with limited visibility into denied authentication attempts. The interesting question is the authentication flow behind this. My initial assumption was that an attacker would need valid credentials before reaching MFA, meaning a password reset should disrupt the attempts. However, I've seen discussions suggesting that certain consumer authentication flows may allow attackers to trigger MFA prompts after identifying the account identifier, creating an MFA fatigue/push bombing scenario without necessarily having a valid password. For those working in identity/security: How would you classify this activity? MFA fatigue, credential stuffing fallout, passwordless abuse, or something else? What telemetry would you expect to see in an enterprise environment versus a consumer Microsoft account? Are there practical ways organizations can distinguish legitimate MFA challenges from attacker-triggered prompts? Does moving users away from push approval toward phishing-resistant authentication (FIDO2/passkeys/security keys) meaningfully eliminate this class of attack? Are there lessons from these consumer account scenarios that should influence enterprise MFA policy? I'm interested less in troubleshooting one account and more in understanding the identity-security implications of this pattern.
已收录讨论
I went through this with my personal Microsoft account too. I figured out what they were doing, turn off phone number associated password sign on option. The ppl trying to hack your Microsoft don’t know your email or password, they are attacking phone numbers. Microsoft has no idea how to prevent this problem. So just turn off phone number can sign on option
Interesting, I hadn't checked the phone number sign-in path yet. I'll look into disabling that and see if it stops the prompts.
I'm mainly trying to understand why MFA prompts continue after password changes and where those denied attempts are actually logged.
I'm curious whether they stop the MFA prompts entirely or just make them impossible to approve.
The passkey prompt is only shown to whoever is trying to log in. You, sleeping in your bed half a planet away, get nothing.
Try the actual flow. When you sign in with a Microsoft account, the default option is to get an MFA prompt. This is Microsoft working on replacing passwords with passkeys.
Exactly this. It happened to me too, even with MFA enabled. Even though none of the activity was authenticated, eventually MS locked my account and also blocked account recovery. MS support had no workable solutions. I lost all access until a few weeks later, when account recovery suddenly worked again. As soon as I regained access, I cycled the MFA, created an account alias, and also set up an auto-forward to a backup email account on another provider. No problems since.
Switch to passkeys and it's done.
Your suggestions wouldn't make any difference to this, you're mostly guessing what to do.
This is the one. Changed my primary sign-in address. No more MFA spam.
We’re all getting this. You can’t prevent someone from trying to brute force your account. If you put blocks on it it’ll just eventually lock you out. Maintain a strong, revoke all sessions often just incase and make sure MFA is enabled. You can’t stop people from knocking on your front door. To answer one of your questions, consumers don’t get the benefit of conditional access. Having a non-us sign in policy strengthens enterprise security by naming known locations or safe IPs.
Yup. This is the correct advice. Don't listen to everyone else saying switch to passkeys etc, it didn't help for shit. Create the alias and it will stop them trying since your email is no longer linked to the account. My personal Microsoft account was driving me nuts with this. Since I changed it, it worked perfect.
MFA prompts only get sent after a successful username:password credential pair is supplied. Also, CA isn't assessed until after successful completed login. Honestly it's a minefield.
I dealt with this back in January, and the solution was to create an alias and disable my main email address for sign in. Problem solved. Keep the alias extremely private. After that if someone tries to sign in using your old email, they’ll get a message saying, “This account doesn’t exist,” so they eventually stop trying. I was getting 3-4 sign in requests a day.
So... this happend to me and only days later I figured out why. All the sudden I got bunch of authenticator request for number matching on my personal MS account, from US which isn't where I am. I denied it a few time, then reset my password, then revoked all my session (I think I did if that choice exists for personal account), then even choose the new get rid of my password option, etc.. yet the MFA prompt continues and I figured I will just keep denying it. Then, few days later, as I get into office, I picked up my personal laptop that I left in office and to my surprise it was not fully off but in sleep mode. Then I realize it could be that laptop trying to sync one drive or something periodically. The office I work out of, has its IP classified as US. So I shutdown the laptop and the MFA request stopped coming. So, a stored token on device that get flagged for impossible travel continuously trigger MFA is the only reason I can think of for my case.
Lo que me llama la atención de este hilo es que hay gente diciendo "passkeys lo arregló" y gente diciendo "passkeys no sirvió de nada", y creo que la explicación está en qué parte del problema atacas. passkeys resuelve el "aprobar por error un push malicioso" porque ya no hay push que aprobar sin el dispositivo físico correcto. pero si el problema de fondo es que tu email está en tantas filtraciones que cualquiera puede iniciar el intento con solo saber tu correo, passkeys no evita que sigan intentando, solo evita que tú puedas fastidiarte solo aprobando algo por accidente. La solución del alias que mencionan un par de personas aquí ataca la causa raíz distinta: si el identificador (el correo) ya no existe como método de login público, no hay nada contra lo que iniciar el intento en primer lugar. es más brusco (tienes que reconfigurar todo) pero deja de depender de "espero no equivocarme aprobando un push a las 3am".
It’s dumb as rocks but you don’t need a password to send a mobile auth attempt. The password is useless, it’s not two factor, it’s two factors. Go to outlook sign in, put email, click ‘other methods’ click phone. No password needed.
For Enterprise accounts, the lesson is that you need to be on phish resistant MFA (passkeys, WHfB, CBA) for all users and enforce this via Conditional Access. But this isn't new, it's been in the CISA SCuBA recommendation since the first draft in '22. Other layers are also needed for token protection: https://learn.microsoft.com/en-us/entra/identity/devices/protecting-tokens-microsoft-entra-id Personal (MSA) accounts, when set to log in without password, can exhibit this behavior. I haven't experienced this, but I've seen advice that this can be silenced by setting up a complex second login for the account and turning off login rights for your main email. e. g. The answer by JG here: https://learn.microsoft.com/en-us/answers/questions/5691418/constant-sign-in-requests-on-mfa Changing to remove all Authenticator except passkeys is another option, but make sure you register multiple devices and ideally a hardware key stored at another location, as well as a printed copy of your recovery codes. It's pretty easy to permanently lose access to your Microsoft account by removing other validators.
I'd classify it as MFA fatigue unless there's evidence the attacker already has valid credentials. If password resets don't stop it, I'd want to know which auth flow is actually generating the prompts. Moving to FIDO2/passkeys pretty much removes this entire class of push spam.
We recently made passkeys mandatory. It has eliminated that fear
Yes, especially in the middle of the night. You only have to hit the wrong button once.
mine always come from the USA. And it started when the morons at my telco got themselves hacked. I just ignore it.
That's an attack bro reset the creds be safe
My Hotmail account is 27 years old and is in every leak and db passed around. Haveibeenpowned melts down when I look it up. I went passwordless quite a while ago but still got dozens of MFA requests a day. So I created a new account, attached it to my old account, set it to be the master account and turned login off on my OG. Instantly stopped all those notifications.
This is super common actually.