• Home
    • What is
    • Computer security
      • Windows security
      • Mac security
      • Linux security
    • Mobile security
      • Android security
      • iOS Security
    • Data security
    • SCCM
    • Reviews
      • Case studies
    • Advertise
    • Contact
      • Privacy Policy
  • Subscribe now

    Loading
  • Home
  • What is
  • Computer security
    • Windows security
    • Mac security
    • Linux security
  • Mobile security
    • Android security
    • iOS Security
  • Data security
  • SCCM
  • Reviews
    • Case studies
  • Advertise
  • Contact
    • Privacy Policy
Home » Breaking Computer security Cyber Security data security Device security Latest Cybersecurity News Windows security

Microsoft Enforces Number Matching in Authenticator to Combat MFA Fatigue Attacks

John Greenwood Posted On May 8, 2023
0



Microsoft MFA Fatigue Attacks

Microsoft has introduced a new security upgrade to Microsoft Authenticator push notifications called “number matching” to combat multi-factor authentication (MFA) fatigue attacks.

MFA fatigue attacks involve cybercriminals bombarding targets with push notifications requesting approval for log-in attempts using stolen credentials. The targets may give in to the repeated malicious MFA push requests, allowing the attackers to log into their accounts.

The success of this social engineering attack method has been proven by Lapsus$ and Yanluowang threat actors who have breached high-profile organizations, including Microsoft, Cisco, and Uber, among others.

Number matching is a key security upgrade to traditional second-factor notifications in Microsoft Authenticator. This upgrade removes the admin controls and enforces number matching experience tenant-wide for all users of Microsoft Authenticator push notifications from May 8, 2023.

Relevant services will deploy these changes starting May 8, 2023, and users will start to see the number match in approval requests. However, some services may deploy the feature later than others.

Manually Enabling Number Matching

To manually enable number matching before Microsoft removes admin controls, go to Security > Authentication methods > Microsoft Authenticator in the Azure portal.

On the Enable and Target tab, click Yes and All users to enable the policy for everyone or add selected users and groups.

Set the Authentication mode for these users/groups to Any or Push.

MFA Fatigue Attacks
Microsoft MFA Number Matching (Source: Bleeping Computer)

On the Configure tab, for Require number matching for push notifications, change Status to Enabled, choose who to include or exclude from number matching, and click Save.

Users can also enable number matching for all users or a single group using Graph APIs.

Additional Defense Against MFA Fatigue Attacks

Those who want to add an additional defense line against MFA fatigue attacks can limit the number of MFA authentication requests per user using Microsoft, DUO, Okta, or other platforms.

They can also lock the accounts or alert the security team/domain admin when these thresholds are exceeded.

Impact of Number Matching on MFA Fatigue Attacks

Number matching will help to reduce the number of false positives in MFA push notifications and ensure that only genuine notifications are sent to users.

This will, in turn, reduce the number of MFA fatigue attacks that targets have to face.

As Microsoft has started enforcing number matching for MFA alerts, it is expected that other MFA providers will also adopt similar measures to combat push bombing or MFA push spam.

Limitations of Number Matching

While number matching is an effective defense against MFA fatigue attacks, it is not foolproof. Cybercriminals can still use social engineering techniques to trick users into approving fake requests. Therefore, it is crucial to educate users about the risks of MFA fatigue attacks and how to spot fake requests.

Additionally, organizations should implement other security measures such as monitoring user behavior, using threat intelligence tools, and deploying security solutions that can detect and prevent attacks before they happen.

Multi-factor authentication is an essential security measure to protect against cyberattacks. However, MFA fatigue attacks can compromise this security measure, putting sensitive data at risk.

With the introduction of number matching, Microsoft has taken a significant step towards combating MFA fatigue attacks. Organizations should follow suit and adopt similar measures to safeguard their systems and data against cyber threats.

Share the article with your friends


Cybersecuritydata securityPrivacy


Author

John Greenwood

He has been working with Cybersec and Infosec market for 12+ years now. Passionate about AI, Cybersecurity, Info security, Blockchain and Machine Learning. When he is not occupied with cybersecurity, he likes to go on bike rides!

You may also like
Recast Software: Advanced Endpoint Management and Security Tools for IT Teams
November 16, 2024
Patch My PC: Streamlined Software Management for ConfigMgr and Intune
November 9, 2024
Best Microsoft Intune Alternatives: Top 5 MDMs to Consider
November 4, 2024
Leave A Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Subscribe to our newsletter

    Loading
  • Windows security

    • Recast Software: Advanced Endpoint Management and Security...
      November 16, 2024
    • Patch My PC: Streamlined Software Management for ConfigMgr...
      November 9, 2024
    • Best Microsoft Intune Alternatives: Top 5 MDMs to Consider
      November 4, 2024
    • Top 11 Log Management Tools for Efficient System Management
      September 20, 2024
    • Top 5 Threat Intelligence Tools For 2024
      September 19, 2024


  • About us

    Our vision is to deliver the trending and happening cyber events to the enthusiasts.

    We believe in delivering educational and quality content for hassle-free understanding of the subject.

  • Subscribe to our newsletter

    Loading
  • Follow us

  • Advertise with us

    You can reach us via Facebook, Linkedin, or Twitter for advertising purposes.


© The Cybersecurity Times 2022. All rights reserved.
Press enter/return to begin your search