Skip to content
Blurtek
Back to blog
Cybersecurity

MFA fatigue in SMEs: stopping push bombing without making login painful

How to configure MFA, number matching and conditional access to prevent tired approvals after password theft.

Blurtek
3 min read18 palabras
01

When MFA becomes a notification approved out of fatigue

In push bombing, the attacker already has the password and triggers MFA prompts until the user approves one.

  • Enable number matching
  • Remove weak methods where possible
  • Alert on repeated MFA prompts
  • Prioritize passkeys or FIDO2 for critical accounts

Blurtek tunes identity and conditional access so MFA protects without blocking users.

Solicitar diagnóstico
WE START BY LISTENING

Your next step,
thought through together.

Tell us what needs to improve. We help you decide where to start and what is worth building.

Tell us about your project
MFA fatigue in SMEs: stopping push bombing without making login painful | Blurtek