27 November 2022
Multi-factor authentication, MFA, increases your account security by requiring sign-in verification that is constantly changing but only known to you. Various MFA techniques are available including a code from an app, an SMS message or voice notification. For sophisticated attacks, some of these can be emulated where the attacker knows enough information.
Microsoft Authenticator is the most popular MFA method for businesses to secure their users' Microsoft 365 accounts. However, there is a growing issue of 'MFA fatigue attacks' which rely on the user's ability to approve a simple voice, SMS or push notification and doesn't require the user to have understanding of the session they are authenticating.
To combat this the Microsoft Authenticator app will use number matching. Beginning on 27 February 2023, Microsoft will start enabling this critical security feature for all users of the Microsoft Authenticator app.
Number matching prevents accidental approval by requiring the user to type in a two-digit code from the login screen to their Authenticator app. If the user did not initiate the sign-in, they will not know the two-digit code. This requires the attacker to request that the user supply a two-digit code, which should alert the user of the compromise.
To find out more IT security for your business, call Chris Joberns on 01473 835 280 to make online backups part of a data security plan.