An unexpected MFA prompt can be a warning sign.
Attackers sometimes steal a password and then repeatedly try to sign in, hoping the user will eventually approve one of the MFA requests.
This is sometimes called MFA fatigue.
Employees should never approve an MFA request they did not start.
If an unexpected prompt appears, deny it if possible and report it to IT.
The account password may already be known to the attacker, so changing the password may also be necessary.
Modern authentication systems may show number matching or extra information to help users confirm the login.
MFA is powerful, but it still depends on users recognizing when a request is not legitimate.
The simple rule is: if you did not try to sign in, do not approve the prompt.
