Al Aida IT
Back to blog[ AIDAIT ] Knowledge base

MFA Fatigue Attacks: Why Approving That Prompt Could Hand Over Your Business

MFA fatigue attacks against UAE Microsoft 365 tenants are up 86% this quarter, and one tired employee tapping "Approve" is all it takes for an attacker to walk in.

Cybersecurity 3 August 2026 7 min read
// Contents+

An MFA fatigue attack is when a criminal who already has your stolen password spams your phone with repeated real MFA prompts until you approve one just to make the notifications stop — no hacking or malware required, just one tap in a moment of confusion. UAE Microsoft 365 tenants have seen an 86% quarter-on-quarter spike in these attacks, largely because most are still running basic Approve/Deny push notifications with no Conditional Access policies to block the attempt before it reaches the user's phone.

At a glance
  • 01MFA push-bombing attempts against UAE organisations are up 86% quarter-on-quarter, with Microsoft 365 tenants the primary target because of how widely the platform is deployed
  • 02Basic Approve/Deny push MFA gives users zero context to judge a prompt — number-matching MFA plus Conditional Access policies restricting location, device, and sign-in frequency are needed to actually stop the attack
  • 03A single approved prompt often leads to Business Email Compromise, with regional incident data putting average losses from one successful compromise at AED 150,000-500,000 for mid-sized firms
  • 04Al Aida IT's MFA hardening engagement (AED 2,500-6,000, 1-2 weeks) rolls out number-matching, Conditional Access, and Entra ID Protection alerting in report-only mode first so there's zero disruption to daily work
01

1. What Exactly Is an MFA Fatigue Attack?

Multi-factor authentication was supposed to be the thing that finally stopped stolen passwords from becoming full account takeovers. Attackers have found a way around it that doesn't require breaking any encryption or guessing any code — it just requires annoying a human being into clicking 'Approve'.

Here's how it plays out. A criminal buys or phishes a valid Microsoft 365 username and password (these circulate cheaply on dark web marketplaces after almost any data breach). They log in with those credentials, which triggers a push notification to the real employee's Microsoft Authenticator app. The employee didn't request a login, so they decline it. The attacker tries again. And again. Sometimes 20, 30, even 50 times in a row, often timed for 2am or during a meeting when the employee is distracted or half-asleep and just wants the notifications to stop.

Eventually, someone taps 'Approve' just to make it go away — or because they assume IT is running a test, or because a follow-up call or WhatsApp message from 'IT Support' (actually the attacker) tells them to. That single tap hands over a live, authenticated session. No malware, no exploit, no password cracking. This is exactly the technique used in the 2022 Uber breach and the Cisco breach the same year, and it has since become the default playbook for credential-based attacks on Microsoft 365 tenants across the Gulf.

02

2. Why the UAE Spike Is Hitting Microsoft 365 Users So Hard

Regional threat intelligence reports point to an 86% quarter-on-quarter rise in MFA push-bombing attempts against UAE organisations, with Microsoft 365 tenants the overwhelming target because of how widely the platform is deployed across construction, engineering, industrial and professional services firms in the region. Attackers don't need to pick a niche target — they scrape breached credential lists, filter for UAE-registered domains, and run automated push-bombing tools against every match.

The reason this works so well on SMEs specifically comes down to three gaps we see constantly during onboarding assessments:

First, most Microsoft 365 tenants are still using basic 'Approve/Deny' push notifications rather than number-matching, which shows a code on the sign-in screen that the user must enter in the app. A plain Approve/Deny prompt gives the user zero context — no location, no app, sometimes not even a timestamp — so there's genuinely no way to tell a real login from an attack.

Second, there are no Conditional Access policies restricting where and how sign-ins are allowed. Without Conditional Access, Microsoft 365 will happily send an MFA prompt for a login attempt from an unfamiliar country, an unmanaged device, or at 3am — the exact scenario that should be auto-blocked before it ever reaches the user's phone.

Third, employees have never been shown what an attack actually looks like. Security awareness training in most SMEs covers phishing emails but rarely mentions push-bombing, so when it happens for the first time, staff have no reference point for 'this is an attack, not a glitch'.

03

3. The Real Cost When One Prompt Gets Approved

One approved push is rarely the end of the story — it's the beginning of a much more expensive one. Once inside a Microsoft 365 account, an attacker typically registers their own MFA method (so they can get back in even after the password is changed), sets up mailbox forwarding rules to silently copy incoming invoices and client emails, and starts scanning SharePoint and OneDrive for financial documents, project bids, and client contact lists.

For a construction or engineering firm, the follow-on attack is usually Business Email Compromise: the attacker waits for a real invoice thread, then sends a 'updated bank details' email from the legitimate, compromised account to a client or supplier. Because it comes from a real, trusted mailbox with a real signature and a real conversation history, these fraudulent payment redirects are approved far more often than cold phishing emails — regional incident data puts average BEC losses from a single successful compromise in the AED 150,000-500,000 range for mid-sized firms, before accounting for the cost of the investigation, client trust damage, and the regulatory exposure if personal data was involved.

There's also a slower-burn cost: once an account is compromised, it can sit dormant for weeks while the attacker studies invoicing patterns and vendor relationships before striking, which is exactly why detection speed — not just prevention — has to be part of the answer.

04

4. How Al Aida IT Locks This Down on Your Microsoft 365 Tenant

This is a solvable problem, and it doesn't require replacing anything you already pay for — Microsoft 365 and Azure AD (Entra ID) already include most of the controls needed. Al Aida IT's MFA hardening engagement, delivered as part of our Cybersecurity and Microsoft 365 management services, typically covers the following in a single engagement over 1-2 weeks:

We enforce number-matching MFA across the tenant, which replaces the vague Approve/Deny button with a code the user must read off the sign-in screen and type into the Authenticator app — this alone eliminates the 'tap it without thinking' failure mode, since there's no code to fake from outside the real login attempt.

We deploy Conditional Access policies tuned to your business: blocking sign-ins from outside the UAE and your other operating countries (or requiring extra verification when travel is expected), requiring a compliant, managed device for access to email and SharePoint, and enforcing sign-in frequency limits so a stolen session token can't be reused indefinitely.

We enable and monitor Microsoft Entra ID Protection risk-based sign-in alerts, so a burst of repeated MFA prompts to one user — the signature of an active push-bombing attempt — triggers an automatic block and an alert to our SOC, typically inside our standard 15-30 minute response SLA, rather than being left for the user to handle alone at 2am.

We also run a 30-minute staff briefing (included, not billed separately) so employees know exactly what to do if they get an unexpected prompt: decline it, don't call the number in a follow-up message, and report it. Pricing for the full hardening package — Conditional Access setup, number-matching enforcement, Entra ID Protection configuration and staff briefing — runs AED 2,500-6,000 depending on tenant size and existing licensing (Microsoft 365 Business Premium or E3/E5 is required for full Conditional Access; we'll tell you upfront if a licence upgrade is needed and what it costs).

05

5. Getting Started Without Disrupting Your Team

The biggest hesitation we hear from SME owners is fear that tightening security will lock out legitimate users or slow everyone down. In practice, we roll out Conditional Access policies in report-only mode first, watching real sign-in traffic for 5-7 days to catch any legitimate but unusual access pattern (a director travelling, a remote engineer on a site with a new IP) before switching policies to enforce mode. This staged approach means your team sees zero disruption, and you get a clear before/after picture of exactly what the policies are catching.

As part of the same engagement, Al Aida IT runs a free tenant risk check — a 20-minute review of your current MFA method, Conditional Access status, and any risky sign-ins logged in the last 90 days — so you know precisely where you stand before committing to anything.

// FAQ

Frequently asked questions

How is an MFA fatigue attack different from regular phishing?+

Phishing tricks a user into typing their password into a fake site. MFA fatigue (push-bombing) starts after the attacker already has a valid stolen password — they use it to trigger repeated real MFA prompts on the victim's phone until the person approves one out of frustration or confusion, giving the attacker a live authenticated session without needing any fake website at all.

We already use Microsoft 365 MFA — aren't we protected?+

Basic Approve/Deny push MFA (the Microsoft default) is exactly what push-bombing exploits, since it gives users no context to judge a prompt. You need number-matching MFA plus Conditional Access policies restricting sign-in location, device, and frequency to actually stop this attack type — not just MFA turned on.

What does Al Aida IT's MFA hardening service cost and how long does it take?+

The full package — number-matching enforcement, Conditional Access policy design and rollout, Entra ID Protection alerting, and a staff briefing — runs AED 2,500-6,000 depending on tenant size, delivered over 1-2 weeks with a report-only testing phase first so there's no disruption to daily work.

What should an employee do right now if they get an MFA prompt they didn't request?+

Decline the prompt immediately, do not approve it 'just to make it stop', and report it to IT the same day even if it only happened once. Never trust a follow-up call or message telling you to approve it — that's the attacker, not IT support. If Al Aida IT manages your tenant, our SOC is alerted automatically and responds within 15-30 minutes of a suspicious sign-in pattern.

Next step

Need help applying this to your business?

Our Dubai-based engineers can audit your setup and recommend the right next steps.