Skip to content
IdentitéTrust starts here
English
EnglishEspañolPortuguês
Contact

How Does Push Notification MFA Work?

Eusebio CoterilloEusebio Coterillo ·
Editorial illustration for How Does Push Notification MFA Work?.

You enter your username and password.

Almost immediately, your phone vibrates.

A notification appears:

That's push notification Multi-Factor Authentication (MFA), and it has become one of the most familiar forms of workplace authentication.

Its popularity isn't difficult to understand. Push MFA eliminates the need to wait for a text message, copy a six-digit code, or carry a separate token. A user can often approve a login in seconds.

But that simplicity raises an important question:

What exactly happens when you tap “Approve”?

And an even more important cybersecurity question:

What happens when the person generating the authentication request isn't you?

Push notification MFA can provide meaningful security improvements over passwords alone. But conventional approval-based authentication also has weaknesses—particularly when users are conditioned to approve requests without carefully considering where they originated.

Understanding those strengths and limitations can help organizations make better decisions about MFA and determine when it's time to move toward stronger forms of authentication.

What Is Push Notification MFA?

Push notification MFA is an application-based authentication method that uses a registered device—usually a smartphone—as an additional authentication factor.

A typical login works something like this:

CISA describes mobile push-notification MFA in essentially this way: the user authenticates, the identity platform signals the mobile application, and the user accepts the resulting prompt.

The phone therefore becomes part of the authentication process.

Instead of relying exclusively on:

Something you know — your password

the system adds:

Enter password → Wait for text → Read code → Return to application → Type code → Continue

Push Authentication

Enter password → Receive notification → Approve → Continue

Removing those extra steps can make authentication considerably easier, particularly for employees who authenticate multiple times during a workday.

Push authentication also avoids some of the telecommunications-related vulnerabilities associated with SMS, such as SIM swapping and attacks involving the cellular network. CISA ranks app-based methods above SMS or voice MFA, although it distinguishes stronger app-based approaches from simple push approval.

But convenience introduces another problem.

The easier it becomes to press “Approve,” the easier it can become to approve something you shouldn't.

The Critical Weakness: Who Started the Login?

Imagine you're sitting at your desk when your phone suddenly displays:

Approve Sign-In?

You aren't currently signing in anywhere.

What happened?

One possibility is that an attacker has obtained your username and password.

The criminal attempts to log in.

Your organization's authentication system recognizes the password and sends the MFA request to your legitimate phone.

The security system is effectively asking:

“Is this really you?”

The problem is that the user may not know exactly what generated the request.

If you press Deny, the attacker remains outside.

If you press Approve, you may have just completed the attacker's authentication for them.

MFA Fatigue: When Attackers Weaponize the Approve Button

Editorial concept illustrating How Does Push Notification MFA Work?

Cybercriminals discovered that they don't necessarily need to defeat the authentication technology.

Sometimes they can simply wear down the person using it.

An attacker with a stolen password may repeatedly attempt to log in.

Your phone receives:

Approve?

You deny it.

Another arrives.

Approve?

Then another.

And another.

Eventually, the attacker hopes you will approve one:

This is known as MFA fatigue, push fatigue, or push bombing.

CISA specifically warns about this technique and recommends phishing-resistant MFA as the stronger solution. Where organizations cannot immediately deploy phishing-resistant MFA, CISA recommends number matching as an interim defense against MFA-fatigue attacks.

That's an important distinction.

MFA can be present and an attacker can still exploit the authentication experience.

Number Matching Makes Push MFA Better

Modern push authentication can improve on the simple:

Approve / Deny

model.

With number matching, the website or application displays a number.

For example:

42

The phone receives the authentication request, but instead of simply tapping Approve, the user must enter or match 42 in the authenticator application.

Microsoft now uses number matching for Authenticator push notifications and describes it as an important security improvement over traditional second-factor notifications.

Why does that help?

Because an attacker randomly bombarding your phone with approval requests can no longer rely as easily on you simply tapping:

Approve.

You need information associated with the authentication session you actually initiated.

That's better.

But there's another important point organizations should understand.

Better push MFA isn't necessarily the same thing as phishing-resistant authentication.

Push MFA Can Still Be Vulnerable to Phishing

Staircase visual connecting Push MFA Can Still Be Vulnerable to Phishing, Authentication Has Two Sides, What Is Full Duplex Authentication®?, Why Mutual Authentication Matters

Suppose an attacker creates an extremely convincing copy of your company's login page.

You click a link in an email.

The page looks legitimate.

You enter your username and password.

The attacker immediately submits those credentials to the real corporate website.

The legitimate authentication system sends a push notification to your phone.

You think:

The problem is that you started the process on an imposter website.

NIST's current digital identity guidance states that out-of-band authentication is not phishing-resistant, while CISA similarly notes that push-notification authenticator applications generally do not protect against phishing.

This exposes one of the fundamental limitations of many conventional authentication systems:

They spend enormous effort determining whether the user is legitimate while still relying heavily on the user to determine whether the destination is legitimate.

Authentication Has Two Sides

Consider what conventional MFA is primarily designed to establish:

“Are you really the authorized user?”

That's obviously important.

But what about:

“Is this really the website or application you intended to access?”

Cybercriminals understand this imbalance extremely well.

They create:

They can copy:

A user may have difficulty distinguishing the fake from the real thing.

That's where the authentication conversation needs to move beyond simply adding another approval prompt.

What Is Full Duplex Authentication®?

Full Duplex Authentication® (FDA) is Identité's patented authentication technology and is designed around a fundamentally different principle:

Both sides of the digital relationship should establish trust.

The user authenticates to the legitimate application or website, while the application or website must also authenticate itself as legitimate.

That distinction becomes increasingly important in an environment filled with phishing sites, lookalike domains, and digital impersonation.

Why Mutual Authentication Matters

Archipelago visual connecting Why Mutual Authentication Matters, Push MFA vs. Full Duplex Authentication®, What About Biometrics?, Identité Uses a Decentralized Architecture

Imagine an attacker creates a nearly perfect copy of your bank's website.

Even the domain may differ from the real one by only a character.

A conventional authentication process may still ask you to prove who you are.

Full Duplex Authentication® addresses the other half of the relationship.

The destination must establish its identity as well.

An imposter website can copy the appearance of a legitimate website.

But it cannot successfully perform the legitimate site's side of Full Duplex Authentication®.

That's a major philosophical difference.

Instead of putting the entire burden on the user to identify fraud, the authentication architecture itself participates in establishing whether the destination can be trusted.

Push MFA vs. Full Duplex Authentication®

The distinction can be summarized simply:

Authentication Approach

Primary Question

Password

Do you know the secret?

SMS MFA

Do you know the password and possess the phone number?

Conventional Push MFA

Do you know the password and possess the registered device?

Push + Number Matching

Can you correlate the registered device with this authentication attempt?

Full Duplex Authentication®

Can the user and the legitimate destination establish trust with one another?

A phone may require:

before the authentication request can be approved.

This can strengthen the process because simply possessing the phone may not be enough.

NIST's guidance recognizes multi-factor out-of-band authenticators that require an activation factor such as a password or biometric before authentication can be completed.

But biometric authentication raises another question:

Where does the biometric data go?

That's especially important because a password can be changed.

Your fingerprint cannot.

Identité Uses a Decentralized Architecture

Article-specific explanatory visual for Identité Uses a Decentralized Architecture

Identité utilizes a decentralized authentication architecture designed so that biometric data remains on the user's trusted device.

When fingerprint or facial recognition is used, the biometric information does not need to be sent to Identité, the employer, or a centralized biometric database for matching.

Your biometric data stays on your device.

The organization needs the authentication result.

It doesn't need possession of the user's fingerprint or facial biometric information.

This helps reduce the security and privacy risks associated with concentrating sensitive biometric information in a centralized repository.

Should Organizations Stop Using Push MFA?

Not necessarily.

Security isn't always a choice between:

Push MFA can provide significantly more protection than passwords alone, particularly when it is properly implemented.

Organizations currently using push authentication should consider practices such as:

NIST specifically says out-of-band verifiers sending push notifications should impose reasonable limits on the rate or total number of pushes since the last successful authentication.

And CISA's hierarchy is worth remembering: phishing-resistant MFA is preferred, while number-matched push authentication is a useful option for organizations that cannot immediately make that transition.

Never Approve a Push Request You Didn't Initiate

For employees, one rule matters above almost everything else:

If you aren't trying to log in, don't approve the authentication request.

An unexpected push notification should be treated as suspicious.

If repeated requests appear, follow your organization's security procedures rather than simply approving one to make them disappear.

An MFA prompt isn't merely a nuisance.

It could be evidence that someone already possesses your password.

Don't Train Employees to Click “Approve”

Editorial scene illustrating Don't Train Employees to Click “Approve”

Organizations should also think carefully about authentication fatigue.

If employees receive authentication requests constantly throughout the day, they can become conditioned to respond automatically.

Authentication changes from:

“Let me verify that this is legitimate.”

to:

“Tap the button so I can get back to work.”

That's not the behavior security teams want.

The objective shouldn't be to generate the maximum number of MFA prompts.

It should be:

Maximum authentication confidence with minimum unnecessary friction.

PasswordFree® — Moving Beyond Conventional Push Authentication

For organizations seeking a cloud-delivered passwordless authentication solution, Identité offers PasswordFree®, our SaaS solution.

PasswordFree® is designed around:

Rather than simply adding another approval step to a password, the objective is to reduce dependence on passwords while strengthening the underlying authentication relationship.

NoPass™ — Enterprise Authentication With Greater Control

Petals visual connecting NoPass™ — Enterprise Authentication With Greater Control, What Happens If the Phone Is Lost?, The Evolution of Push Authentication, The Identité Perspective

Enterprises requiring greater control can choose NoPass™, Identité's PaaS solution powered by patented Full Duplex Authentication®.

NoPass™ can be deployed on premises or in the cloud and is designed for enterprise environments requiring integration with technologies such as:

This flexibility can be particularly important for banks, healthcare organizations, government agencies, and other regulated enterprises with strict requirements surrounding infrastructure and sensitive information.

For financial institutions that prefer to keep authentication infrastructure and sensitive data within their own controlled environment, NoPass™ can be deployed on premises.

What Happens If the Phone Is Lost?

Any smartphone-based authentication strategy needs to answer this question before deployment.

Phones get:

If the authentication architecture has no recovery plan, stronger security can quickly become an availability problem.

Identité addresses this through Emergency PIN Authentication and Secure Backup & Restore.

When permitted by organizational policy, an Emergency PIN can provide controlled temporary authentication when the primary device is unavailable.

If the phone must be replaced, users can securely restore their authentication profile from an approved cloud or corporate-network backup.

The restore process can be completed in less than two minutes.

That helps reduce downtime, re-enrollment, and help desk intervention.

The Evolution of Push Authentication

Push notification MFA was an important improvement over passwords alone.

It made MFA easier.

It removed the need to manually transfer SMS codes.

It helped accelerate widespread MFA adoption.

Then attackers adapted.

Push bombing demonstrated that a simple approval button could be manipulated.

Number matching improved the model.

But phishing continues to expose the larger issue.

Authenticating the user is only half of a trusted digital relationship.

That's why authentication is continuing to evolve:

Password → MFA → Push MFA → Stronger contextual MFA → Phishing-resistant/passwordless authentication → Mutual authentication

Each stage attempts to solve weaknesses exposed by the stage before it.

The Identité Perspective

When someone asks:

“How does push notification MFA work?”

the simple answer is:

Your authentication system sends a request to a registered device, and you approve that request to help establish that you are the legitimate user.

But the more important question is:

“Is proving that I'm the legitimate user enough?”

In today's threat environment, we believe authentication needs to establish more.

The biometric can help establish:

“I am the authorized user.”

The trusted device participates in establishing:

“My biometric data stays on my device.”

Through PasswordFree® and NoPass™, Identité combines passwordless authentication, mutual authentication, decentralized biometrics, compatible hardware security keys, Emergency PIN Authentication, and Secure Backup & Restore into an architecture designed around security, privacy, productivity, and business continuity.

Push MFA made authentication easier.

The next challenge is making authentication smarter.

Because the strongest digital relationship shouldn't require only one party to prove who they are.

Trust should work both ways.