Overview
This article provides a low-risk, evidence-driven troubleshooting path for unexpected mfa prompt: approve or deny?. Work from identity and service checks toward more disruptive actions, and stop before a change could cause data loss, broaden access, weaken security, or interrupt other users.
Why this happens
Security warnings and suspected account compromise require evidence preservation, safe containment, credential protection, and coordinated administrator-side review rather than ordinary trial-and-error troubleshooting.
Before You Begin
- Preserve screenshots, alert text, times, sender addresses, and other useful evidence.
- Use a known-clean device for sensitive account changes when practical.
- Do not approve unexpected MFA prompts or communicate secrets to an unverified requester.
- If ransomware or active compromise is suspected, prioritize containment and escalation over ordinary troubleshooting.
Navigation reference: Official work account portal > Security.
Click-by-Click Troubleshooting
Step 1: Deny the unexpected prompt
Action: In Microsoft Authenticator, Google prompts, or the approved MFA application, select Deny or the equivalent option for a sign-in you did not initiate.
Why this matters: Approving an unsolicited prompt can give an attacker access.
What to look for: Confirm the prompt truly was not triggered by your own sign-in.
Expected result: The unexpected request should not be approved.
Step 2: Do not respond to repeated prompts
Action: Stop approving or interacting with repeated prompts and record their times.
Why this matters: Repeated prompts can indicate MFA fatigue attacks.
What to look for: Look for bursts of prompts or unfamiliar sign-in location information.
Expected result: The pattern should be documented without granting access.
Step 3: Change the password from the official portal
Action: Use the official work account portal from a trusted session to change the password if compromise is suspected.
Why this matters: An attacker may already know the password even if MFA blocked entry.
What to look for: Confirm the new password is unique and not reused.
Expected result: The old credential should no longer authenticate.
Step 4: Review recent sign-ins
Action: Open the official account security page and review recent sign-in activity.
Why this matters: Recent activity can show whether any unexpected request succeeded.
What to look for: Look for unfamiliar devices, countries, IPs, or successful sign-ins.
Expected result: Suspicious sessions should be identified.
Step 5: Review authentication methods
Action: Review registered MFA methods and remove only methods that IT confirms are unauthorized.
Why this matters: Attackers may attempt to establish persistence through a new authentication method.
What to look for: Look for unknown phone numbers, apps, or security keys.
Expected result: Only approved authentication methods should remain.
Step 6: Report the event
Action: Notify IT/security with the prompt times, account, device, and any unfamiliar sign-in details.
Why this matters: Administrators may need to revoke sessions or investigate the identity platform.
What to look for: Provide facts and screenshots where available.
Expected result: IT should have enough detail to validate account security.
What to Look For
- Whether the issue affects one user/device or multiple users.
- Whether a clean browser or alternate approved client changes the result.
- Whether the error points to identity, permission, licensing, service, device, or network state.
- Whether the same controlled test succeeds after the targeted correction.
When to Stop
When to Contact IT
Contact J3 Systems Group if the issue remains unresolved, affects multiple users, requires administrator-level changes, involves security or data-loss risk, or the next step would be disruptive. Include article code KB-07.005, the affected account/device/resource, exact error, time observed, and the results of the controlled tests above.
Need help with this issue?
J3 Systems Group supports small businesses and nonprofits with Microsoft 365, Google Workspace, cybersecurity, devices, documentation, and day-to-day IT operations.
Contact J3 Systems GroupAuthoritative references
Vendor interfaces, licensing, and security guidance can change. Verify current platform behavior against the primary documentation below before making high-impact production changes.