Blog Insights
MFA Fatigue at Work and What Actually Helps
Listen to this article
What MFA Fatigue Looks Like at Work and What to Do About It
Multi-factor authentication, or MFA, is supposed to make work safer. A password can be stolen, guessed, or reused from another breach. A second factor adds friction for attackers and reassurance for everyone else. Yet the same extra step that improves security can also wear people down when it appears too often, interrupts urgent work, or arrives in confusing ways across too many apps.
That wear and tear has a name people increasingly recognize, MFA fatigue. Sometimes it means employees are annoyed by endless prompts and start approving them without thinking. Sometimes it means attackers abuse push notifications and hope a tired user taps “approve” just to make the buzzing stop. Sometimes it shows up as slower work, more help desk tickets, or workers creating informal shortcuts because the official path feels punishing.
At work, MFA fatigue is rarely a single technology problem. It sits at the intersection of identity systems, device management, app design, shift work, remote access, policy choices, and human attention. A company may have excellent intentions and still create a login experience that trains people to stop noticing risk. Fixing that takes more than turning MFA on everywhere and calling the job done.
What MFA fatigue actually means
MFA fatigue is often described too narrowly as “too many prompts.” Volume is part of it, but the problem is bigger. Fatigue appears when authentication becomes so frequent, repetitive, or disruptive that users lose trust in the signal. The prompt stops feeling like a meaningful check and starts feeling like background noise.
That distinction matters. If a finance manager receives one carefully timed prompt after signing in on a new laptop, that usually feels understandable. If the same person gets challenged every few hours across payroll, expense tools, VPN access, and a CRM, the prompts blend together. The action becomes muscle memory.
There are two overlapping forms of MFA fatigue at work:
- Operational fatigue, when legitimate users are slowed down, distracted, or locked out by repeated checks.
- Security fatigue, when users become less able or less willing to distinguish a legitimate prompt from a malicious one.
Organizations tend to notice the first form because people complain. The second can be more dangerous because it hides behind apparent compliance. Employees may still complete MFA, but they do it automatically, with little scrutiny.
How it shows up during a normal workday
MFA fatigue is easy to miss if leaders only look at policy documents. On paper, requiring a second factor for every sensitive app can sound sensible. In practice, the experience can become chaotic.
Picture a sales representative starting the day from home. They sign in to a laptop, open email, connect to a VPN, launch a CRM, join a call in a collaboration suite, and pull pricing data from another portal. Each system may have different session lengths and different trust rules. Even if every individual prompt seems reasonable, the combined effect can feel relentless.
A hospital worker on a shared workstation may face a different version of the same issue. Short session timeouts protect patient information, but repeated reauthentication in the middle of clinical tasks can feel unsafe in another sense, because it interrupts attention. Staff may begin tapping through prompts with almost no pause.
Manufacturing environments often face yet another pattern. Supervisors move between floors, tablets, and administrative systems while wearing gloves or using spotty connectivity. If a second factor requires a personal phone that isn't practical to access at every station, people may start borrowing devices, sharing workarounds, or leaving sessions open longer than policy intends.
Common signs that your workplace has an MFA fatigue problem
Most organizations don't discover MFA fatigue from a single dramatic incident. They spot it through a cluster of warning signs that seem unrelated until someone connects them.
- Users approve prompts they didn't initiate. They may report, “I thought it was from the VPN,” or “I get those all the time.”
- Help desk tickets climb after MFA changes. Requests may mention looped prompts, expired codes, phone replacement issues, or confusion about which app to use.
- Teams create side doors. Shared accounts, remembered sessions on unmanaged devices, or unofficial exceptions become attractive.
- People delay critical tasks. A worker may put off logging into a protected app because they don't want another round of authentication.
- Push spam incidents appear. Attackers send repeated approval requests, hoping frustration wins.
- Managers ask for blanket exemptions. This often signals that the current experience is blocking work in a measurable way.
The key is not to treat these as user laziness. Repeated unsafe behavior usually points to a system that is teaching the wrong habit.
Why push notifications are especially tricky
Push-based MFA became popular because it's fast and convenient. A notification appears, the user taps approve, and work continues. Compared with typing six-digit codes, that feels smoother. The trouble is that convenience can remove the pause that gives MFA much of its security value.
If an employee sees a pop-up during a busy meeting, they may approve it reflexively. An attacker who already knows the password only needs one mistaken tap. This tactic, often called MFA push bombing or prompt bombing, relies less on technical wizardry than on persistence and timing.
Several public security incidents over the past few years have drawn attention to this risk. In many reported cases, attackers obtained credentials first, then flooded the target with MFA approvals until the person accepted one or responded to a follow-up message that sounded like internal IT. Not every case is identical, and public reporting often leaves out implementation details, but the broad pattern is well documented.
Push notifications aren't inherently flawed. They simply need guardrails. Number matching, device binding, context details like location and app name, and rate limits can make approval far less mindless.
The business costs go beyond irritation
Annoyance alone might not move budget or policy conversations. Measurable business effects usually do.
First, productivity drops in small increments that add up. A 20-second interruption repeated many times a day across hundreds or thousands of workers becomes expensive. The cost is even higher when those interruptions break concentration during high-value work such as coding, claims review, incident response, or patient documentation.
Second, support costs rise. Every lost phone, unenrolled device, dead battery, travel scenario, or SIM change can turn into account recovery work. Help desks then become part of the authentication flow, which is rarely ideal for users or security teams.
Third, poor MFA design can distort policy. If executives or frontline teams feel overburdened, they may pressure IT to weaken controls broadly instead of fixing the friction precisely. That can lead to blanket “remember me” settings, long-lived sessions for everyone, or informal exceptions that attackers eventually discover.
Finally, fatigue changes culture. People stop treating authentication as a meaningful security event and start seeing it as an obstacle imposed by another department. Once that mindset takes hold, awareness training becomes much harder because the lived experience contradicts the message.
Why organizations accidentally create MFA fatigue
Rarely does a company set out to overwhelm its workforce. MFA fatigue usually emerges from reasonable decisions made in isolation.
One team secures remote access. Another secures a cloud app. A third adds step-up authentication for sensitive actions. A merger brings in a second identity provider. Contractors use separate portals. Mobile and desktop experiences evolve on different timelines. Each control solves a specific problem, but the person signing in experiences all of them as one stack.
Session policies are a major factor. If tokens expire too quickly, users reauthenticate constantly. If trust isn't shared across apps through single sign-on, each service asks separately. If location or device signals aren't used well, the system may challenge a known employee on a managed laptop as aggressively as an unknown device from a risky network.
Security teams also face legitimate pressure from auditors, insurance questionnaires, and incident reports. Under that pressure, “more prompts” can look safer than “smarter prompts,” even though the opposite may be true in practice.
What better MFA looks like in practice
The goal isn't fewer security checks at any cost. The goal is to make checks meaningful, proportionate, and hard to abuse. Good MFA design asks for stronger proof when risk is higher and gets out of the way when confidence is already high.
Consider the difference between these two experiences. In the first, an employee on a managed laptop in a usual location receives five generic approvals before lunch. In the second, the same employee signs in once with a phishing-resistant method, then works across connected apps without repeated disruption. Later, when they try to access payroll from a new device in another country, the system asks for a stronger step. The second model often provides a better security outcome because users remain attentive when prompts do occur.
Practical steps to reduce MFA fatigue without weakening security
1. Audit the prompt journey, not just the policy
Start by mapping what workers actually experience. Follow a few common roles through a week of sign-ins: finance, engineering, call center, field service, clinicians, executives, contractors. Count prompts, note timing, and document which systems trigger them. This exercise often reveals overlapping checks that no single administrator sees.
A regional retailer, for example, might discover store managers are authenticating separately to scheduling software, inventory tools, HR portals, and remote support utilities, even though all sit behind the same identity provider. The issue isn't that any one control is wrong, it's that the cumulative design is exhausting.
2. Move away from simple approve-deny prompts
If your organization uses push approvals, add friction in the right place. Number matching requires the user to enter a number shown on the login screen. Contextual details, such as application name, approximate location, and device type, help people spot suspicious requests. Rate limiting and lockouts after repeated denied prompts can disrupt prompt-bombing attacks.
These changes don't eliminate risk, but they make accidental approval much less likely.
3. Prefer phishing-resistant methods for higher-risk access
Security keys and platform authenticators based on standards such as FIDO2 and WebAuthn can reduce both phishing risk and fatigue. Instead of approving a vague push, the user authenticates with a biometric or hardware-backed method tied to the legitimate site or app. Many organizations now support passkeys or security keys for administrators and other high-risk roles, and in many cases the method is faster than older MFA once deployed properly.
Adoption does require planning. Device compatibility, recovery paths, shared workstation scenarios, and contractor access all matter. Still, moving the most sensitive groups away from prompt-based MFA is often one of the strongest improvements available.
4. Use risk-based access policies carefully
Adaptive authentication can reduce unnecessary prompts by considering device health, network, user behavior, travel patterns, and resource sensitivity. A managed device on a normal schedule may need less reauthentication than an unknown phone at an unusual hour.
This works best when the signals are reliable and the logic is transparent enough to troubleshoot. If adaptive systems behave unpredictably, users feel arbitrary friction, which creates a new form of fatigue. Test with real roles before broad rollout.
5. Tune session length to the task
Not every app needs the same timeout. A shared kiosk in a public area should behave differently from a company-issued laptop with full disk encryption and screen lock policies. Sensitive actions inside an app may justify step-up authentication, while routine viewing may not.
Granularity matters here. Asking for reauthentication before every action can punish legitimate work. Asking only when risk changes can preserve attention for moments that matter.
6. Fix recovery and device change processes
Some of the strongest resentment toward MFA comes from edge cases: a new phone on a Monday morning, an overseas trip with no SMS delivery, a broken authenticator app before payroll closes. If recovery is confusing, workers remember the frustration more than the protection.
Clear self-service options, backup methods, pre-registered secondary authenticators, and fast identity proofing for exceptions can dramatically reduce support burden. Recovery should be secure, but it shouldn't feel like a scavenger hunt.
Training people without blaming them
Awareness programs often fail when they imply that careful users can solve a poorly designed system through willpower alone. Employees already juggling deadlines, customers, patients, and approvals need specific guidance tied to their real environment.
Useful training is direct:
- If you didn't start a login, deny the prompt and report it.
- If repeated prompts arrive, don't “clear” them by approving one.
- If someone messages you claiming to be IT and asks you to accept an MFA request, verify through an official channel.
- If your phone changes, enroll the new method before the old one is wiped when possible.
Short simulations can help, especially when they mirror actual tools and messages used internally. Managers also need coaching, because employees often follow their lead. If supervisors treat MFA as red tape, their teams will too.
Role-specific examples matter more than generic advice
A one-size-fits-all MFA policy tends to create friction unevenly. Different roles face different realities.
Executives travel frequently, switch devices, and are common targets for social engineering. They often need strong phishing-resistant authentication and concierge-level enrollment support, not broad exemptions.
Developers and IT administrators access powerful systems where a compromised account can have wide impact. Prompt fatigue here is especially risky because one mistaken approval may expose code repositories, cloud consoles, or identity infrastructure.
Frontline and hourly workers may share stations, have limited time between tasks, and lack company-issued smartphones. If MFA assumes personal devices and constant connectivity, adoption will suffer.
Contractors often work across multiple client environments, which can create prompt overload quickly. Limiting access paths, standardizing identity flows, and using time-bound access can help keep security manageable.
Making It Work
MFA fatigue is rarely just a user problem; it is usually a design problem that can be reduced with better methods, smarter policies, and clearer recovery paths. The goal is not to remove friction entirely, but to place it where it meaningfully lowers risk without interrupting legitimate work all day. Organizations that treat MFA as part of the user experience, not just a checkbox, are far more likely to improve both security outcomes and employee trust. If you want help evaluating your current approach or planning a better rollout, Axcel Technology can be a useful resource to explore at axceltechnology.com. Small, practical improvements made now can lead to a much stronger and less frustrating identity strategy over time.