Decision-first exercise
Unexpected MFA prompt: approve, deny, or wait?
Practice the immediate response to an uninitiated authentication prompt without assuming what caused it.
Synthetic scenario · Content reviewed
Synthetic authenticator notification
What you receive
The answer and signal-by-signal reasoning appear after you decide.
Text version for assistive technology and automated testing (includes the answer)
Exercise: Unexpected MFA prompt: approve, deny, or wait? Scenario: Synthetic authenticator notification Channel: Authenticator push Sender: Work account Message: Approve sign-in? Message: Application: Microsoft 365 Message: Location: Seattle, Washington Message: This is the fourth request in two minutes. You are not trying to sign in. Question: What should you do first? Option: Approve one prompt so the repeated notifications stop Option: Deny it, then review account activity and report through a known channel Option: Contact the caller who said they are support and read them the code Answer: Deny an authentication request you did not initiate. The uninitiated prompt is enough to reject the request. It does not prove why the prompt appeared or that a sign-in succeeded, so use account activity and an official support channel for the next decision. Signals: - Strong evidence: You did not initiate the sign-in. There is no legitimate reason to approve your own authentication factor for an action you did not start. - Strong evidence: Repeated prompts. The repetition increases the risk of an accidental or pressured approval. It is not a reason to approve. - Contextual signal: Displayed application and city. These labels may help an investigation but do not authenticate the request. Location may be imprecise. Safe actions: - Deny the request or let it expire; never share a code. - Open the account portal independently and review recent activity. - For an organization account, report the time and prompt details to IT/security through the normal channel. Reviewed: 2026-07-28
Evidence
Authoritative references
- CISA, NSA, FBI, MS-ISACPhishing Guidance: Stopping the Attack Cycle at Phase One
- Microsoft SupportView your work or school account sign-in activity from My Sign-ins
- Microsoft SupportProtect yourself from phishing
Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.