Decision-first exercise
Unexpected MFA prompt: approve, deny, or wait?
Practice the immediate response to an uninitiated authentication prompt without assuming what caused it.
Synthetic scenario · Content reviewed
Synthetic authenticator notification
What you receive
Decision 1 of 1
The reasoning appears after you lock this decision. Your choices remain only in this page and are not sent anywhere.
Text version for assistive technology and automated testing (includes the answers)
Exercise: Unexpected MFA prompt: approve, deny, or wait? Scenario: Synthetic authenticator notification Channel: Authenticator push Sender: Work account Message: Approve sign-in? Message: Application: Microsoft 365 Message: Location: Seattle, Washington Message: This is the fourth request in two minutes. You are not trying to sign in. Question: What should you do first? Decision 1: What should you do first? Option: Approve one prompt so the repeated notifications stop Option: Deny it, then review account activity and report through a known channel Option: Contact the caller who said they are support and read them the code Preferred option: Deny it, then review account activity and report through a known channel Rationale: The uninitiated prompt is enough to reject the request. It does not prove why the prompt appeared or that a sign-in succeeded, so use account activity and an official support channel for the next decision. Answer: Deny an authentication request you did not initiate. The uninitiated prompt is enough to reject the request. It does not prove why the prompt appeared or that a sign-in succeeded, so use account activity and an official support channel for the next decision. Signals: - Strong evidence: You did not initiate the sign-in. There is no legitimate reason to approve your own authentication factor for an action you did not start. - Strong evidence: Repeated prompts. The repetition increases the risk of an accidental or pressured approval. It is not a reason to approve. - Contextual signal: Displayed application and city. These labels may help an investigation but do not authenticate the request. Location may be imprecise. Safe actions: - Deny the request or let it expire; never share a code. - Open the account portal independently and review recent activity. - For an organization account, report the time and prompt details to IT/security through the normal channel. Reviewed: 2026-07-28
Evidence
Authoritative references
- CISA, NSA, FBI, MS-ISACPhishing Guidance: Stopping the Attack Cycle at Phase One
- Microsoft SupportView your work or school account sign-in activity from My Sign-ins
- Microsoft SupportProtect yourself from phishing
Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.