011 887 3900 info@primeworks.co.za
Primeworks Networking (Pty) Ltd
  • Home
  • Managed IT Services
    • IT Support
    • Data Protection
    • Endpoint Security
    • Microsoft 365
    • Domain & Email Security
  • About Us
  • Resources
  • Contact Us
  • Existing client? Get support
Select Page

Security Brief #003 — Unexpected MFA Prompts: Don’t Approve the Attack

by Chat GPT | 28 Sep, 2026 | All Articles, Microsoft 365, Primeworks Security Briefs

Primeworks Security Brief #003 graphic showing repeated MFA prompts marked Deny.

Your phone lights up with a request to approve a sign-in. You are not signing in. A few minutes later, it happens again. Then someone calls, says they are from IT and asks you to approve the next request so they can “fix” your account.

Primeworks Security Brief #003 graphic showing repeated MFA prompts marked Deny
Do not approve it. An MFA prompt is a request to help complete a sign-in. If you did not start that sign-in, approving it could give someone else access to your account.

MFA means multi-factor authentication: the extra check, often on your phone, that helps protect an account after a password is entered. It remains an important defence. The attacker in this scenario is trying to persuade you to perform the extra check for them.

The threat: repeated prompts and a convincing call

An attacker may attempt to sign in with your username and password, triggering an approval request on your phone. They may try repeatedly, hoping you approve one to make the notifications stop. This is often called MFA fatigue or prompt bombing.

A second tactic is to call or message while the prompts arrive. The caller may claim to be from your company or Primeworks, say an account is being repaired, and insist that you approve the next request. A caller's title, familiar name or displayed telephone number does not prove who they are.

Repeated, unexpected prompts may mean that someone knows your password. They are not proof on their own: a delayed request or an application retry can have another explanation. Either way, treat them as a security incident until your IT team checks the sign-in activity.

Warning signs anyone can recognise

  • A sign-in approval appears when you have not opened a sign-in page or an app requiring you to sign in.
  • Requests arrive repeatedly, particularly after you have rejected one.
  • Someone claiming to be IT tells you to approve an unexpected prompt, read out a one-time code or enter a number that appeared in a sign-in you did not start.
  • The caller asks you to use a link, number or chat they supplied instead of your company's normal support route.
  • You feel pressed to approve “just this once” to stop the alerts or prevent an account from being locked.

What to do immediately

  1. Reject the request. Choose Deny, No or Reject as your app presents it. If it offers Report suspicious activity, use that option too. Never enter a matching number or share a code for a sign-in you did not initiate.
  2. End the suspicious support call. A person claiming to be from IT must not ask you to approve a sign-in you did not start. Call your company's IT team or Primeworks using a number already in your records or on the official Primeworks website. Do not call back a number supplied by the caller.
  3. Change your password promptly. Open your usual company sign-in or password-change route yourself. If your organisation manages password resets, ask its verified IT team to do it. Do not follow a link sent in the suspicious call or message. Use a new, unique password.
  4. Report it immediately. Tell IT when the prompts started, how many you received, whether you approved any, and whether a caller contacted you. Existing Primeworks clients can email support@primeworks.co.za or call 011 887 3900 through their known support details.

If you accidentally approved a prompt or gave someone a code, say so when you report it. Quick reporting lets IT reset the password, revoke active sign-ins, review the account and check whether any unauthorised access occurred. Do not wait for visible evidence of misuse.

How Primeworks helps

Primeworks helps South African businesses secure Microsoft 365 accounts, review suspicious sign-ins, improve account monitoring and give staff a clear route to report unusual requests. A simple habit can prevent a great deal of damage: approve only the sign-in you started yourself.

Key takeaway: An unexpected MFA prompt is a reason to pause, even if a caller says they are from IT. Deny. Change. Report. Verify the caller through a known contact route.

Sources and further reading

  • Microsoft Entra: Configure multifactor authentication settings – report suspicious activity
  • Microsoft Entra: Protect identities and secrets – authentication fatigue and prompt bombing
  • CISA: Implementing Phishing-Resistant MFA
  • CISA: Teach Employees to Avoid Phishing

Categories

  • AI & Emerging Threats
  • All Articles
  • Data Protection
  • Domain and Email Security
  • Endpoint Security
  • IT Support
  • Microsoft 365
  • Primeworks Security Briefs
  • Scams & Payment Fraud

Primeworks

Managed IT services for South African businesses that want technology to work—securely, reliably and without unnecessary complexity.

Managed IT Services

OverviewIT SupportData ProtectionEndpoint SecurityMicrosoft 365Domain & Email Security

Explore

About UsResourcesContact Us

Contact

011 887 3900Send an enquiry

Johannesburg · Serving South Africa

© Primeworks Networking (Pty) LtdPrivacy Policy