Treat the prompt as a request for access
An unexpected approval notification can be caused by a mistaken sign-in, an old application, a credential attack or someone repeatedly attempting to persuade you to approve access. The notification alone does not identify which explanation is correct. It is enough reason to stop and inspect the account through a genuine channel.
Never approve a request because a caller says it will cancel the alert. Approval normally grants something; it is not an incident-cleanup button.
Act without following the suspicious message
- Deny or dismiss the unexpected request using the authenticator's supported controls. If the app offers a report option, use it appropriately. Do not share the displayed number or a one-time code with a caller.
- Open the service through its known app or bookmark on a trusted device. Review recent security activity, devices and available sign-in details. Record the time and what you were doing when the prompt appeared.
- If activity suggests misuse, change the password through the genuine service, review sessions and connected apps, and inspect recovery settings. A reused password should also be replaced on other affected accounts with unique values.
- For a work account, report the event through the established IT channel. Give the approximate time, service and whether you approved anything. Administrators can investigate activity that a user-facing screen may not show.
Verify containment rather than silence
The absence of further prompts is reassuring but does not prove that no session was created. Review successful sign-ins and relevant account changes. If you already approved a request, state that clearly when reporting; it changes what needs to be revoked and investigated.
Improve the sign-in method
Where your provider and existing devices support them, consider passkeys or other phishing-resistant methods. Number matching and richer prompt details can help users judge an action, but copying a displayed number for a caller can still authorise the wrong sign-in.
Identify legitimate background causes
If investigation shows an old mail client or scheduled task repeatedly signing in, fix or retire that integration. Do not disable MFA on the account simply to remove the symptom. Keep recovery methods usable and ensure the account owner recognises how ordinary sign-ins should look before the next unexpected request arrives.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.