Terminology Index
Glossary
1801 terms
Showing 1249-1280 of 1801 terms
Push Notification MFA
A possession-factor MFA method that sends an approval prompt to a registered device for the user to tap. Convenient and stronger than passwords alone, but vulnerable to MFA fatigue and relay attacks.
Push-notification MFA prompts a registered device (typically a phone) to approve or deny a sign-in, so the user simply taps yes. It is convenient and far stronger than passwords alone, which is why it is widely deployed. But it has known weaknesses: MFA fatigue attacks bombard users until they approve, and push approval doesn't bind the credential to the legitimate site like FIDO/passkeys do. Number-matching prompts and conditional access reduce these risks, and high-value access often warrants phishing-resistant alternatives.
Introduced in: Identity and Access Management
Examples
- Approving a sign-in with a tap on a phone push prompt.
- Hardening push MFA with number-matching to defeat fatigue.
- Choosing phishing-resistant MFA over push for high-value access.
No related terms linked yet.
