ITIT Lunchroom
When it's already happened

I approved an MFA prompt I didn't start. What now?

You tapped Approve to make the buzzing stop, then realized you were not signing in to anything. Here is what that actually granted, what to do in the next twenty minutes, and why the people you tell will be glad you told them fast.

An MFA prompt you did not start means your password is already gone. Tell IT, change your password, and sign out everywhere — all three, inside ten minutes.

Last reviewed 2026-08-18 by Grayson Dodson. Free, plain-English guidance for everyday work technology.

What you'll be able to do

walk through the exact recovery steps in the right order, on Microsoft or Google, and report it to IT in one clear sentence without dreading the conversation

mfa fatigue, also called prompt bombinga session, and why it outlives a password changenumber matching in microsoft authenticator, duo and okta verifysign out everywhere, and who can force itrecent activity and sign-in history pagesmail forwarding rules and inbox rules you did not createpassword reuse as the usual root cause

You were targeted, not careless

Take a breath. What happened to you has a name, and security teams see it constantly. It is called MFA fatigue, or prompt bombing. An attacker who already has your password tries to sign in over and over, and each attempt fires another push notification at your phone. Ten of them at 11pm. Twenty during a meeting. The whole design of the attack is to wear you down until one tap looks like the fastest way to make your phone stop buzzing. That is not a lapse in judgment. That is the attack working exactly as intended, on a human being who was busy and tired, which is all of us. Microsoft, Google, Duo and Okta all changed how their prompts work specifically because so many careful, competent people tapped Approve under exactly this pressure. So put the self-blame down. You are not the first person at your company to do this, and the people who handle security have almost certainly read about this exact scenario in a vendor advisory. What matters now is the next twenty minutes, not the last thirty seconds.

What that one tap actually granted

Here is the part nobody says plainly, and it is the real headline. The prompt only appeared because someone had already typed your username and your correct password. Multi-factor authentication is the second lock. The first lock was already open. So there are two separate problems now, and only one of them is about the tap. Problem one: your password is known to someone else. It may have leaked in a breach at an unrelated site where you reused it, or been captured by a fake sign-in page, or guessed. Problem two: your Approve completed the sign-in, so that person very likely now has a live session. A session is a signed-in state that keeps working on their device. It does not ask for the password again on every click, and depending on the setting it can survive for hours or days. That is why simply ignoring the next prompt is not enough. Changing your password alone is not enough either, because an existing session can outlive the password change until it is explicitly ended. You need to close both doors, and the order matters.

The first three moves, in this order

Move one, change the password, and change it from a device you trust. If you tapped Approve on your work phone and you are not certain your laptop is clean, use another device you trust, or sit down next to a colleague and do it on theirs. For a personal Microsoft account, go to account.microsoft.com, then Security, then Password security. For a work or school Microsoft 365 account, go to myaccount.microsoft.com and choose Password. For Google or Google Workspace, go to myaccount.google.com, then Security, then Password. Choose something genuinely new. Do not reuse a variation of the old one, because whoever has the old one will try the obvious variations first. Move two, end every session that is currently signed in, and the exact screens for that are just below. A password change on its own does not always kick out a session that is already open. Move three, tell IT now, not once you have tidied up. Send the message while you are still changing the password. Speed is the whole game here.

Exactly where to look and what to revoke

On Google, open myaccount.google.com/device-activity. That page lists every device signed in to the account, with location and last-used time. Anything you do not recognize, click it and choose Sign out. Then open myaccount.google.com/security-checkup and read Recent security activity. Also check Gmail under Settings, See all settings, then the Forwarding and POP/IMAP tab and the Filters and Blocked Addresses tab. Attackers commonly add a quiet forwarding rule so they keep receiving your mail after they are locked out. Screenshot anything you did not create before you delete it, so IT has the evidence. On a personal Microsoft account, go to account.microsoft.com, then Security, then Recent activity. It lists successful and failed sign-ins with approximate location, device and app, and lets you mark an entry as This wasn't me. For a work or school account the equivalent page is mysignins.microsoft.com, and in Outlook you check Settings, Mail, Forwarding and Settings, Mail, Rules. For work accounts the most complete fix is not yours to click: an administrator can revoke every session centrally in seconds. One more reason to message IT first.

Why the newer prompts make you type a number

You may notice that the prompt looks different from now on, and that difference is deliberate. Microsoft Authenticator now uses number matching: instead of a bare Approve and Deny pair, the sign-in screen displays a two-digit number and the app asks you to type that number in. If you did not start the sign-in, you have no number to type, so there is nothing to tap by reflex. Duo does something similar with Verified Push, showing a code on screen that you enter in Duo Mobile. Google's phone prompt shows you a number on the device asking to sign in and three numbers in the app, and you tap the matching one. Okta Verify offers the same style of challenge. Treat the extra detail as information, not friction. A good prompt tells you the app, the approximate location and the device. If it says a city you have never visited, or an app you were not opening, that is your answer. And if you are ever genuinely unsure, tapping Deny costs you thirty seconds of signing in again. Tapping Approve can cost your employer a great deal more.

Speed beats embarrassment, every time

The single biggest factor in how bad this gets is how many minutes pass before someone who can act knows about it. Attackers who get a session move fast, and what they do first is usually boring: read your mailbox, set up forwarding, look for invoices, and send messages to colleagues from your address because your address is trusted. Every minute you spend deciding whether this is embarrassing enough to mention is a minute they get for free. So say it plainly, in whatever channel your workplace uses. Something like: I approved an MFA prompt at about 9:40 this morning that I did not start. I have changed my password and signed out of my sessions. Can you check my account. That is the whole message. You do not need to explain or apologize. Nobody competent is going to shout at you, because a fast report is what lets them contain it. In Microsoft Authenticator you can also tap No, it's not me on a prompt you did not request, which flags it to your administrators. If your workplace has never told you who to contact for this, ask that question today, while nothing is on fire.

Common questions

I accidentally approved a login request that wasn't me. What do I do first?

Change your password from a device you trust, then sign out of all sessions, then tell IT. In that order, and all within a few minutes. For Google use myaccount.google.com, Security, Password, then myaccount.google.com/device-activity to sign out unknown devices. For a personal Microsoft account use account.microsoft.com, Security. For a work account use myaccount.microsoft.com and mysignins.microsoft.com. Do not wait until you have worked out how it happened. Your IT team can end every session centrally in seconds, and they can only do that once they know.

Does approving an MFA prompt mean someone already has my password?

Almost certainly, yes. An MFA prompt only appears after a correct username and password have been entered, so the prompt itself is evidence that someone already had your password. That is the more serious half of the problem, and it is why changing the password is step one rather than an afterthought. It also means you should change that password anywhere else you used it or something similar, because password reuse across sites is the most common way it got out in the first place.

Why do I keep getting MFA notifications I didn't request?

Because someone is deliberately spamming them, hoping you will tap Approve to make them stop. It is called MFA fatigue or prompt bombing, and it works often enough that Microsoft, Google, Duo and Okta all redesigned their prompts around it. Repeated prompts you did not start mean your password is already known to someone else. Deny every one, then change the password and tell IT. Do not turn notifications off and hope it passes, because that just removes your only warning that someone is trying.

Will I get in trouble for approving an MFA prompt by mistake?

Very unlikely, and much less likely if you report it fast. Security teams plan for this exact scenario, because prompt bombing is designed to catch attentive people. What they need from you is the timestamp, roughly what the prompt said, and confirmation of what you have already changed. Reporting late is what causes real damage, since an attacker with a live session spends that time reading mail and messaging your colleagues. If you are worried about the conversation, remember that from their side a fast report is the best possible version of this news.

Is changing my password enough after I approved a login I didn't start?

Not on its own. A session that is already signed in can keep working after a password change, depending on how the account is configured, so you also need to end those sessions. On Google, open myaccount.google.com/device-activity and sign out anything unfamiliar. On a personal Microsoft account, use account.microsoft.com, Security, Recent activity to see what happened, and sign out of devices you do not recognize. On a work account, ask IT to revoke your sessions centrally, which is faster and more thorough than anything you can click yourself. Then check for mail forwarding rules you did not create.

Practice it hands-on

Reading is a good start — now try a short, interactive version. Never Approve an MFA Prompt You Did Not Start lets you make the real decision in a safe practice run, no login needed.

Make it stick

Create a free account to save your place across all the free lessons. Work through an interactive track and you earn a shareable certificate you can add to a résumé or job application. No payment, no catch.