Multi-factor authentication is one of the best defenses a contractor can deploy, and attackers know it. Rather than breaking it, many now try to wear people down. They obtain a stolen password, try to sign in and trigger a push notification on the employee's phone. If the employee taps approve, the attacker is in. If the first prompt is ignored, the attacker keeps sending them. This is commonly called MFA fatigue or prompt bombing.
The fix is not to abandon MFA. It is to choose stronger methods and train people on one simple rule.
Why this works on busy crews
A foreman who is driving, running a pour or answering a dozen calls will often tap an unexpected prompt just to make the buzzing stop. Late-night prompts can be especially effective, because a half-asleep person wants the phone quiet. Attackers have also been known to follow up with a phone call or text pretending to be IT support, saying the prompts will stop if the person approves one.
None of this requires clever technology. It exploits attention and habit.
Step one: know your current method
Find out which type of MFA your company uses, because they are not equal.
- Simple push approval: tap yes or no. Most vulnerable to fatigue.
- Push with number matching: the user must enter a number shown on the sign-in screen into the app. This blocks blind approvals.
- One-time codes from an app or text message: better than nothing, but codes can be phished or intercepted in some cases.
- Phishing-resistant methods: hardware security keys or device-bound passkeys, which verify the real website and are much harder to trick.
Ask your IT provider which applies to which accounts. Administrators and finance staff should be on the strongest option available.
Step two: tighten the settings
Many platforms, including Microsoft 365, offer settings that reduce fatigue attacks. Work with your provider to consider these.
- Require number matching or similar context for app-based approvals.
- Show the application name and sign-in location in the prompt, so an unexpected request stands out.
- Limit the number of failed or unanswered attempts before an account is temporarily locked or flagged.
- Block sign-ins from countries where you do no business, and flag unusual travel.
- Use conditional access rules that require a compliant, managed device for sensitive systems.
- Disable older sign-in methods that skip MFA entirely.
Each setting adds a layer, and none requires employees to change much.
Step three: give everyone one rule
Training works best when it is short enough to remember.
If you did not just try to sign in, do not approve. Deny, then report it.
Reinforce these points.
- Approving a prompt you did not start gives a stranger access, even for a moment.
- IT will never call or text asking you to approve a prompt.
- Repeated prompts mean someone has your password. Report them immediately, even at night.
- Reporting is never punished. Employees who tapped approve by mistake should say so right away so the password can be reset and sessions revoked.
Put the rule on a card for the truck or a line in the safety meeting. Crews already know the habit of stop and think before an unsafe action. This is the same idea.
Step four: make reporting easy
Provide a single number or email for reporting suspicious prompts, and make sure someone answers it. Decide in advance what happens when a report arrives: reset the password, sign out all sessions, review the account's recent activity and check for forwarding rules or new devices.
Step five: watch for the signs
Ask your provider to alert on repeated MFA denials, sign-ins from unfamiliar places and new device registrations. A burst of denied prompts is a useful early warning that a password has leaked, even if nobody approved anything.
Fix the underlying problem too
MFA fatigue only happens after a password is stolen. Reduce that risk by using unique passwords with a password manager, blocking reuse of exposed passwords where your platform allows and training people to spot phishing sites that capture credentials.
What to do after an approved prompt
If someone approves in error, move fast.
- Reset the password.
- Revoke active sessions and tokens.
- Review sign-in logs and mailbox rules.
- Check for new MFA methods the attacker may have added.
- Look for sent messages that could be fraud attempts.
Next step
Ironfield Cyber helps contractors choose and configure MFA that holds up in the field, then train crews on it in plain language. If you are not sure which type your company uses, ask us for a quick configuration review.