How to Enable MFA Number Matching and Stop Push Fatigue Attacks
Retrospective: this article looks back at events from March 2022, written in 2026 with the benefit of hindsight.
MFA fatigue (or push bombing) floods a user with approval requests until they accept. Number matching and additional context make blind approvals much harder. Here is how to configure them in Entra ID.
Step 1: Confirm number matching is on
Microsoft enforced number matching for Microsoft Authenticator push notifications for all users in 2023. Users must type a number displayed on the sign-in screen into the app. Confirm this is in effect in the Authentication methods policy → Microsoft Authenticator settings.
Step 2: Enable additional context
In the Microsoft Authenticator configuration, enable:
- Show application name in push notifications.
- Show geographic location in push notifications.
Users then see which app and roughly where the sign-in comes from.
Step 3: Report suspicious activity
Enable Report suspicious activity in authentication methods settings so users can report unexpected MFA prompts. Reported users can be marked high risk in Identity Protection, triggering risk-based policies.
Step 4: Use phishing-resistant MFA for high-value users
Number matching stops blind approvals but not real-time phishing proxies. Require passkeys or FIDO2 keys for administrators and high-risk roles via Conditional Access authentication strengths.
Step 5: Educate users
A short message: "If you get an MFA prompt you didn't start, deny it and report it. IT will never call you and ask you to approve a prompt or read out a code."
Step 6: Monitor
Alert on repeated MFA denials for a user in a short period and on reports of suspicious activity.
Verify
Check sign-in logs for authentication details showing number matching and for MFA denial patterns.