An Approval You Did Not Request Deserves Attention
You are working when your phone displays a message asking you to approve a sign-in. You did not just try to log in, and you are not sure why the request appeared.
Do not approve it.
An unexpected login approval request can be a simple mistake, such as someone entering the wrong email address or a delayed notification from an earlier attempt. It can also mean that someone has your password and is trying to use it. Multifactor authentication, or MFA, may be stopping the login at the next step, but the request still deserves attention.
The right response is calm and practical: deny or ignore the request, change the affected password from a trusted device, review account activity, and notify your IT or security contact if it is a business account.
What an Unexpected Approval Request Can Mean
Push-based MFA sends a notification to your phone after a sign-in reaches the verification stage. If an attacker has obtained your username and password, they may be able to trigger that notification even though they cannot complete the sign-in without your approval.
This technique is often called MFA fatigue or push-notification abuse. CISA explains that MFA checks occur after the first factor, such as a password, has been satisfied. It recommends investigating denied or unknown push requests because they may indicate that a password has been compromised.
A prompt by itself does not prove that someone successfully entered the account. It does mean that you should not assume the password is still private. It is also possible that a legitimate sign-in attempt was delayed or that another person mistyped an address. Reviewing the account’s sign-in history can help distinguish those situations.
For more information, see CISA’s guidance on implementing number matching in MFA applications.
What to Do Right Away
Follow these steps when an approval request was not yours:
- Do not approve the request. Choose Deny when that option is available. If the notification does not identify the account clearly, do not respond to it.
- Capture useful details. Note the time, account, approximate location, device, application, and any number shown in the prompt. A screenshot can help your IT provider investigate.
- Change the password through the normal account portal. Open the service directly using a trusted device or a known bookmark. Do not use a link in an unexpected email, text message, or chat.
- Use a new, unique password. If the old password was used anywhere else, change it on those accounts too. A password manager can help create and store distinct passwords.
- Review and revoke access. Use the account’s security page to sign out other sessions or revoke active sessions when that option is available.
- Report the event. For a work account, contact your internal IT team or managed service provider. Reporting a denied prompt gives them an opportunity to look for related attempts across the organization.
Changing the password is an appropriate precaution when you think someone may know it. It is not a substitute for reviewing the account if there are signs that access succeeded.
Check More Than the Password
An account investigation should look for changes an intruder might make after signing in. Depending on the service, review:
- Recent sign-ins, locations, devices, and applications
- Registered MFA methods and recovery email addresses or phone numbers
- New users, delegates, connected applications, and consented permissions
- Email forwarding rules, inbox rules, and sent messages you did not create
- Files accessed, shared, downloaded, or deleted unexpectedly
- Password reuse on other accounts
Microsoft’s compromised-identity response guidance includes resetting the password, requiring fresh sign-in for active sessions, removing unauthorized inbox rules and application consent, restoring approved authentication methods, and reviewing permissions.
The exact controls differ by provider, so follow the account vendor’s instructions or ask an IT professional to help. You can review Microsoft’s guidance in Create a compromised identity incident response SOP.
If the account is an administrator, executive, finance, payroll, or mailbox account, escalate quickly. These accounts may provide access to sensitive information or enable convincing business email compromise attempts.
A Familiar Business Example
Illustrative example: An employee at a small accounting firm receives three Microsoft 365 approval prompts during a busy afternoon. The employee denies each one and changes the password using the firm’s normal sign-in page.
The IT provider then reviews sign-in activity, checks for unfamiliar authentication methods and mailbox forwarding rules, and signs out active sessions.
The review finds repeated attempts from an unfamiliar location but no evidence that a prompt was approved. The firm still treats the event seriously because the password may have been exposed. It also checks whether the same password was used for another service and reinforces the reporting process with staff.
The lesson is not to panic or assume the worst. The lesson is to treat an unexpected prompt as a useful security signal and follow a consistent response.
Common Mistakes to Avoid
Approving the request to make it stop
This can give the other person access. If prompts continue, deny them when possible and report the pattern.
Changing only one copy of a reused password
An exposed password can put multiple accounts at risk. Change every account that used it, beginning with email and other accounts that can reset passwords.
Using a link from the notification
Attackers may combine a fake alert with a lookalike sign-in page. Navigate to the account through a known address or approved application instead.
Assuming MFA makes investigation unnecessary
MFA is an important layer, but it can be weakened by stolen sessions, unauthorized authentication methods, phishing, or an accidental approval. Strong controls reduce risk without eliminating the need for review.
Keeping the event private
A denied request may be part of a larger campaign against your organization. Your IT or security team cannot connect the dots if nobody reports it.
When to Involve an IT Professional
Contact an IT professional promptly when:
- You approved a prompt accidentally.
- You entered your password into a suspicious page.
- Sign-in history shows an unfamiliar successful login.
- Recovery details, MFA methods, mailbox rules, or permissions changed unexpectedly.
- The affected account has administrative, financial, customer, health, legal, or confidential information.
- Multiple employees receive unexpected prompts.
- You cannot sign in or the attacker appears to be changing account settings.
For a business account, the response may need to include session revocation, endpoint review, mail-flow checks, permission review, credential rotation, and communication with affected users.
Avoid making changes that could destroy useful evidence if your IT or security team is actively investigating, but do not delay containment when an account is clearly at risk. Your provider can help balance those needs.
Treat Unexpected Prompts as Useful Signals
An unrequested login approval is not something to approve, ignore permanently, or explain away without checking. It may be harmless, but it may also indicate that someone has your password.
Deny the request, change the password through a trusted path, look for unauthorized account changes, and report the event.
Cross Link Consulting helps businesses review Microsoft 365 practices, strengthen cybersecurity awareness, and respond thoughtfully when account activity looks unusual. If your team needs a clear process for suspicious sign-ins, we would be glad to help you evaluate the approach that fits your systems and responsibilities.
Humbly and Faithfully Serving Through Technology


