Decision-first exercise

Unexpected MFA prompt: approve, deny, or wait?

Practice the immediate response to an uninitiated authentication prompt without assuming what caused it.

By

Synthetic scenario · Content reviewed
Synthetic authenticator notification

What you receive

Synthetic example
Channel
Authenticator push
Sender
Work account

Approve sign-in?

Application: Microsoft 365

Location: Seattle, Washington

This is the fourth request in two minutes. You are not trying to sign in.

Decision 1 of 1
What should you do first?

Choose before revealing the explanation.

The reasoning appears after you lock this decision. Your choices remain only in this page and are not sent anywhere.

Text version for assistive technology and automated testing (includes the answers)
Exercise: Unexpected MFA prompt: approve, deny, or wait?
Scenario: Synthetic authenticator notification
Channel: Authenticator push
Sender: Work account
Message: Approve sign-in?
Message: Application: Microsoft 365
Message: Location: Seattle, Washington
Message: This is the fourth request in two minutes. You are not trying to sign in.
Question: What should you do first?
Decision 1: What should you do first?
Option: Approve one prompt so the repeated notifications stop
Option: Deny it, then review account activity and report through a known channel
Option: Contact the caller who said they are support and read them the code
Preferred option: Deny it, then review account activity and report through a known channel
Rationale: The uninitiated prompt is enough to reject the request. It does not prove why the prompt appeared or that a sign-in succeeded, so use account activity and an official support channel for the next decision.
Answer: Deny an authentication request you did not initiate.
The uninitiated prompt is enough to reject the request. It does not prove why the prompt appeared or that a sign-in succeeded, so use account activity and an official support channel for the next decision.
Signals:
- Strong evidence: You did not initiate the sign-in. There is no legitimate reason to approve your own authentication factor for an action you did not start.
- Strong evidence: Repeated prompts. The repetition increases the risk of an accidental or pressured approval. It is not a reason to approve.
- Contextual signal: Displayed application and city. These labels may help an investigation but do not authenticate the request. Location may be imprecise.
Safe actions:
- Deny the request or let it expire; never share a code.
- Open the account portal independently and review recent activity.
- For an organization account, report the time and prompt details to IT/security through the normal channel.
Reviewed: 2026-07-28
Evidence

Authoritative references

Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.