MiBOT SupportMiBOT Support
7 min read

MFA Fatigue Attacks: Is Your 365 Setup Enough?

By Herman du PlessisTechnically reviewed by Herman du Plessis

If your Microsoft 365 users only get an SMS or push notification to approve sign-ins, you're no longer adequately protected. Attackers now bombard staff with approval prompts until someone taps 'yes' out of frustration — an MFA fatigue attack. The fix is Conditional Access policies, number matching, and location-based rules that make approvals context-aware instead of just a tap.

This isn't theoretical. It's happening to South African firms right now, often to the people who least expect it — the senior partner, the finance manager, the practice principal.

What is an MFA fatigue attack?

Multi-factor authentication (MFA) was supposed to be the silver bullet. Add a second step — a code, a push notification, a fingerprint — and even if attackers have your password, they can't get in.

Attackers adapted. Here's the playbook:

  1. They buy or phish your password from a leaked database.
  2. They attempt to log in as you — over and over, sometimes hundreds of times in an evening.
  3. Every attempt fires a push notification to your phone.
  4. Eventually, tired, distracted, or assuming it's a glitch, you tap Approve.

They're in. Your mailbox, your OneDrive, your Teams chats, your client files — all of it.

The attack works because it exploits human behaviour, not a technical flaw. And most SA businesses running standard Microsoft 365 have exactly this setup: password plus push. That's it.

Why is this hitting SA businesses harder?

A few reasons we see across our client base:

  • Loadshedding and after-hours work. Staff check email at odd hours from odd places. A push notification at 21:47 feels normal, not suspicious.
  • BYOD is the norm. Personal phones running MFA apps mean IT has zero visibility over the device approving the login.
  • Small teams, big trust. In a 30-person law firm or accounting practice, everyone assumes the alerts are just "IT doing something".
  • Legacy MFA rollouts. Many businesses switched on MFA in 2020 during the remote-work scramble and never revisited the settings.

The frustration is the worst part. You did the right thing. You turned on MFA. You told the team to use the app. And you still got breached — because the setup you had three years ago isn't the setup you need today.

What does 'good' Microsoft 365 security actually look like now?

A modern setup layers protection so that even if a password leaks, the attacker hits wall after wall. Here's the practical checklist we work through with clients:

1. Turn on number matching

Instead of just tapping Approve, users have to type a two-digit number shown on the login screen into their Authenticator app. If they didn't trigger the login, there's no number to type. This alone kills the vast majority of MFA fatigue attacks. It's a free feature in Microsoft Authenticator and takes minutes to enable.

2. Use Conditional Access policies

This is where Microsoft 365 management earns its keep. Conditional Access lets you set rules like:

  • Block sign-ins from countries you don't operate in.
  • Require an extra check if the login comes from an unmanaged device.
  • Force re-authentication for risky sign-ins (impossible travel, unfamiliar IP).
  • Restrict access to sensitive apps to trusted networks only.

For most SA professional-services firms, blocking logins from outside South Africa (or SADC if you have regional clients) is a five-minute change that shuts down 90% of foreign brute-force attempts.

3. Move to phishing-resistant MFA where it matters

For partners, directors, and finance staff — the high-value targets — consider hardware security keys (like YubiKey) or Windows Hello for Business. These can't be phished or fatigued because there's no push to tap.

4. Turn on sign-in risk detection

Microsoft Entra ID (formerly Azure AD) can flag sign-ins that look suspicious — unusual location, anonymous IP, credentials seen in a known breach. Pair this with a policy that blocks or forces password reset on high-risk sign-ins.

5. Audit who has what

Half the businesses we onboard have ex-staff still holding active licences, shared admin accounts with no MFA, or service accounts with global admin rights. Clean this up first — it's the cheapest security win you'll ever get.

How do you know if your current setup is enough?

Ask your IT provider (or yourself) these questions:

  • Is number matching enforced for everyone, or just "available"?
  • Do we have any Conditional Access policies, or are we relying on "security defaults"?
  • Which countries can log into our tenant right now? (The answer should be a short list.)
  • When last did we review who has admin privileges?
  • If a senior partner's password leaked tonight, what would stop the attacker?

If the answers are vague, that's the answer.

Key facts

  • MFA push approvals alone are no longer sufficient against modern attacks — number matching or phishing-resistant methods are the current baseline.
  • Conditional Access is included with most Microsoft 365 Business Premium licences — many SA businesses are paying for it and not using it.
  • Under POPIA, the Information Regulator expects notification of a data compromise "as soon as reasonably possible" after reasonable grounds exist to believe it occurred — you don't have to wait for the investigation to conclude. See inforegulator.org.za.
  • MiBOT Support is ISO/IEC 27001:2022 certified, so the controls we recommend are the same ones we're audited against.

What happens if you leave it?

The honest version: eventually, someone taps Approve. It might be next Tuesday, it might be next year. When it happens, you're not just dealing with a compromised mailbox — you're dealing with a POPIA notification, client questions, possible tender disqualification, and the very awkward internal conversation about who approved what.

The alternative is quieter. You harden the setup once, staff barely notice the change (number matching adds two seconds to a login), and the attacks that used to work simply don't. That's what proactive cyber security services actually deliver — not more alerts, fewer incidents.

Frequently asked questions

Is number matching enabled by default in Microsoft 365?

Microsoft has been rolling it out as a default for new tenants, but many existing SA business tenants still have it as optional. Log into the Microsoft Entra admin centre and check your Authentication methods policy — don't assume it's on.

Do we need Business Premium to use Conditional Access?

Conditional Access requires Entra ID P1, which is included in Microsoft 365 Business Premium and most enterprise plans. If you're on Business Standard or Basic, you'll need to upgrade the affected users — but often only your admins and high-risk staff need it, so the cost is manageable.

What's the difference between security defaults and Conditional Access?

Security defaults are Microsoft's one-size-fits-all baseline — MFA for everyone, block legacy authentication, protect admins. It's better than nothing. Conditional Access is the tailored version: you decide who, when, where, and how. For any business with more than about 15 staff, Conditional Access is worth the effort.

Can our current IT guy set this up?

Maybe — but the real question is whether they'll monitor it, tune it, and respond when something triggers. A one-off setup that no one watches is barely better than nothing. This is where the difference between break-fix vs managed IT shows up most clearly.

Getting the setup right

If your Microsoft 365 tenant is still running on 2021's security settings, it's overdue for a review. Not because something bad has necessarily happened, but because the threat landscape moved and the defaults didn't move with it.

At MiBOT Support, we do this kind of tenant review as part of onboarding every new client — it's usually where the first real "how did we not know that?" moments happen. If you'd like a fresh set of eyes on your setup, book a free consultation and we'll walk you through what your current configuration actually protects against, and what it doesn't.

Last reviewed: August 2026

Ready to Experience IT That Actually Works?

Let us take care of your technology so you can focus on growing your business.

  • 25+ years supporting SA businesses
  • Under 1-hour response
  • ISO/IEC 27001:2022 certified
Book a callCall