Leadde Logo

Preventing MFA Fatigue Attacks: A Guide for Users and Security

Explains the mechanism of MFA fatigue attacks, outlines correct user response protocols, and details organizational defense strategies.
LBy Leadde Updated August 27, 2026

How an MFA Fatigue Attack Actually Works

An MFA fatigue attack does not defeat multi-factor authentication; it waits for a person to approve it. The attacker already holds a working password and triggers push prompts repeatedly, often late at night, until the account holder taps approve to stop the noise. Ten prompts in a minute is a common pattern.

The design of the attack is social rather than technical, which is why it defeats employees who have passed every phishing test. Nothing on the screen is fake, the prompt is genuinely from the company's own identity provider, and the only wrong element is that the person did not start it. Kept out of the video entirely is the defensive configuration: which conditional access rules are enforced, which accounts are exempt, and what the lockout thresholds are should stay in the security runbook rather than in a video sent to everyone.

The attack is set out across eight scenes: two on how the attacker gets the password in the first place, two on the prompt sequence as the employee experiences it, one on the phone call that often follows pretending to be IT support, one on the correct response, one on how to report it, and one on what the organisation does afterwards.

How to Make Deny and Report the Automatic Response

Security awareness on this topic fails in a specific way: people learn that unexpected prompts are bad and then approve one at two in the morning because they assume a background app is misbehaving. The video's only job is to install a reflex that survives being half asleep.

Teach one rule with no exceptions

Teach one rule with no exceptions

If you did not just start a login, deny it. No judgement about which app, no waiting to see if it stops. Exceptions in a rule this small are what produce hesitation at the moment it matters.

Say plainly that denying is not enough

A denied prompt means the password is already stolen. Employees who deny and move on leave the attacker holding valid credentials to try again tomorrow, which is why the report step carries more weight than the denial.

Cover the phone call that follows

Attackers frequently ring afterwards, posing as IT and asking the employee to approve "to clear the queue". Naming this in advance is what prevents it, because the call sounds helpful rather than threatening.

Remove the cost of reporting

Nobody reports a prompt they suspect they mishandled. Stating explicitly that reporting a mistake is faster than reporting an incident is the sentence that changes reporting rates.

The rollout guide already contains the screens

Upload the MFA rollout guide, the identity provider's user documentation, or the incident reporting procedure, in PDF, DOC, DOCX, PPTX, or TXT under 200 MB. The returned scenes are editable and the source file is untouched.

Putting Your Own Login Flow on Screen

Show the prompt your staff will actually see

Show the prompt your staff will actually see

Push prompts differ between providers, and an employee shown an unfamiliar screen learns nothing they can act on. Replace the generic prompt with screenshots of your own so recognition is immediate.

Name the reporting channel in the scene, not the description

Name the reporting channel in the scene, not the description

A reporting route mentioned in a paragraph is not used at midnight. Put the channel and the words to send directly into the scene text so it can be read from a paused video.

Put a recognisable person in front of it

Put a recognisable person in front of it

Choose a presenter from the built-in avatars that matches how your organisation communicates, and keep the same one across the whole awareness series. Security messages delivered by a consistent figure are read as policy; a different presenter each quarter reads as marketing.

MFA Fatigue FAQ

Deny it, then report it the same day. The denial stops that attempt; the report is what triggers a password reset, because an unexpected prompt means the password is already compromised regardless of whether anyone approved anything.

Because judgement is worst and the incentive to make the noise stop is highest. Attack tooling schedules prompt bursts deliberately outside working hours, and awareness material that only shows a daytime scenario trains for the easy case.

Screenshots can be uploaded to My Media and placed in a scene. Leadde has no screen capture of its own, so they have to be taken and reviewed by your security team first, with any tenant identifiers and usernames removed before upload.

It reduces it substantially, because approving now requires reading a digit from the login screen rather than tapping a button. It does not remove the underlying problem, which is a working stolen password, so the report step stays necessary even where number matching is enforced.

Deny the Prompt You Did Not Start

Point it at the MFA rollout guide the security team already issues and edit what comes back before the next awareness cycle.

avatar

Start With This Template. Finish With a Video Ready to Share.

Add your onboarding guide or help-center pages and generate an editable draft in minutes.