Entra ID & IdentityHow-To & HardeningRetrospectives

How to Enable MFA Number Matching and Stop Push Fatigue Attacks

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2022, written in 2026 with the benefit of hindsight.

MFA fatigue (or push bombing) floods a user with approval requests until they accept. Number matching and additional context make blind approvals much harder. Here is how to configure them in Entra ID.

Step 1: Confirm number matching is on

Microsoft enforced number matching for Microsoft Authenticator push notifications for all users in 2023. Users must type a number displayed on the sign-in screen into the app. Confirm this is in effect in the Authentication methods policy → Microsoft Authenticator settings.

Step 2: Enable additional context

In the Microsoft Authenticator configuration, enable:

  • Show application name in push notifications.
  • Show geographic location in push notifications.

Users then see which app and roughly where the sign-in comes from.

Step 3: Report suspicious activity

Enable Report suspicious activity in authentication methods settings so users can report unexpected MFA prompts. Reported users can be marked high risk in Identity Protection, triggering risk-based policies.

Step 4: Use phishing-resistant MFA for high-value users

Number matching stops blind approvals but not real-time phishing proxies. Require passkeys or FIDO2 keys for administrators and high-risk roles via Conditional Access authentication strengths.

Step 5: Educate users

A short message: "If you get an MFA prompt you didn't start, deny it and report it. IT will never call you and ask you to approve a prompt or read out a code."

Step 6: Monitor

Alert on repeated MFA denials for a user in a short period and on reports of suspicious activity.

Verify

Check sign-in logs for authentication details showing number matching and for MFA denial patterns.

mfa number matchingLapsus$2022

More on this story