Your phone buzzes: "Approve sign-in?" from Microsoft, Google, Duo, or another authenticator app. You're not signing in to anything — you're making coffee, or it's 11 p.m.
That prompt means someone, somewhere, just entered your correct username and your correct password. The only thing standing between them and your account is the button on your screen.
What to do
-
Tap Deny (or ignore it). Never approve to make it stop. Attackers count on people approving out of habit or annoyance — it works often enough that the technique has a name, "MFA fatigue." If prompts keep coming, keep denying. Some apps have a "No, it's not me" or "Deny and report" option — use that one.
-
Change that account's password, now, from a device you trust. The prompt is proof the current password is in someone else's hands. Don't reuse a variation of it. If the same password is used anywhere else, change it there too — that's usually how it was stolen in the first place.
-
Tell whoever handles your IT, even if you denied it. One unexpected prompt for one person is sometimes the visible edge of a bigger problem — a phishing email that went to the whole company, or a password list from a breached website being tried against everyone. Reporting it lets someone check sign-in logs and see where the attempt came from. If we manage your environment, this is exactly the kind of thing we want to hear about the same day.
-
If you approved it before realizing — say so immediately. No judgment; it happens, especially with a stream of prompts designed to wear you down. But it converts "attempt" into "they're in," and the response changes: sessions need to be signed out everywhere, the password reset, and recent account activity reviewed. Speed matters far more than embarrassment.
What it is not
An unexpected prompt is not your account being hacked through the prompt, and denying it costs you nothing. It's also usually not a glitch — treat "random" MFA prompts as real until proven otherwise. The one common benign cause: an old phone, tablet, or app you own trying to reconnect with a saved password. Your IT can tell the difference from the sign-in logs by looking at where the attempt came from.
One upgrade worth asking about
If your organization still uses plain approve/deny prompts, ask about number matching — the sign-in screen shows a two-digit number you must type into your phone. It makes the "spam them until they approve" attack essentially impossible, and it's a setting, not a product. Most business platforms support it now; it's one of the quiet, cheap wins in a security review.