Why No Detail in MFA Request Windows?

Simon Parkinson 1 Reputation point
2022-11-15T15:51:49.863+00:00

Several times a day, I see screen like this pop-up:

260579-mfa.jpg

Often, it's because I just signed into a service and that's fine as I know where that request came from. However, sometimes I'll be in the middle of writing an email and will see that pop-up appear and I have no idea where it is coming from. Many people will acknowledge this without thinking and that can create all sorts of security issues.

There is no detail in the MFA pop-up. Is this request from Azure, Outlook, Teams or Sharepoint? Where is it coming from, my home town or a basement in Belarus? We need to see more detail on this prompt to make sure we are authorizing appropriately. No GUIDS, no machine references, just plain information, so the average user can make an informed decision to authorize or not.

Something like this:

260563-mfa2.jpg

I can look at that and see my Outlook 365 has expired. I now check my Outlook and see "Needs password" in the client footer and know it is valid.

Now if I see something like this:

260606-mfa3.jpg

I can ignore it and alert my security staff. The simplest of additions informs the user as to what the authorization involves. To me, this is a brain dead simple addition that would return LOTS of value, especially to the non-technical staff members.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Subhash Sharma 676 Reputation points Microsoft Employee Moderator
    2022-11-16T08:03:21.497+00:00

    Hello @Simon Parkinson
    Thank you for reaching out. Based on the details shared by you I see that you would like to get additional details about the MFA request.

    Please note that you can enable additional context from Microsoft Authenticator settings in portal to show application name and geographic location in push and passwordless notifications.
    After enabling this when a user receives a passwordless phone sign-in or MFA push notification in Microsoft Authenticator, they'll see the name of the application that requests the approval and the location based on the IP address where the sign-in originated from.
    Ex,
    260759-77.png

    For steps to enable additional context in Microsoft Authenticator please review the below article.
    How to use additional context in Microsoft Authenticator notifications - Authentication methods policy

    Additionally, if you would like to request for purpose to be added in the MFA requests then please submit a feature request here.

    I hope this answers your query.

    ---------
    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.