Decision-first exercise

Unexpected MFA prompt: approve, deny, or wait?

Practice the immediate response to an uninitiated authentication prompt without assuming what caused it.

Synthetic scenario · Content reviewed
Synthetic authenticator notification

What you receive

Synthetic example
Channel
Authenticator push
Sender
Work account

Approve sign-in?

Application: Microsoft 365

Location: Seattle, Washington

This is the fourth request in two minutes. You are not trying to sign in.

What should you do first?

Choose before revealing the explanation.

The answer and signal-by-signal reasoning appear after you decide.

Text version for assistive technology and automated testing (includes the answer)
Exercise: Unexpected MFA prompt: approve, deny, or wait?
Scenario: Synthetic authenticator notification
Channel: Authenticator push
Sender: Work account
Message: Approve sign-in?
Message: Application: Microsoft 365
Message: Location: Seattle, Washington
Message: This is the fourth request in two minutes. You are not trying to sign in.
Question: What should you do first?
Option: Approve one prompt so the repeated notifications stop
Option: Deny it, then review account activity and report through a known channel
Option: Contact the caller who said they are support and read them the code
Answer: Deny an authentication request you did not initiate.
The uninitiated prompt is enough to reject the request. It does not prove why the prompt appeared or that a sign-in succeeded, so use account activity and an official support channel for the next decision.
Signals:
- Strong evidence: You did not initiate the sign-in. There is no legitimate reason to approve your own authentication factor for an action you did not start.
- Strong evidence: Repeated prompts. The repetition increases the risk of an accidental or pressured approval. It is not a reason to approve.
- Contextual signal: Displayed application and city. These labels may help an investigation but do not authenticate the request. Location may be imprecise.
Safe actions:
- Deny the request or let it expire; never share a code.
- Open the account portal independently and review recent activity.
- For an organization account, report the time and prompt details to IT/security through the normal channel.
Reviewed: 2026-07-28
Evidence

Authoritative references

Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.