📲
Push Notification MFA
Authentication
MFA method using push approvals; security depends on context, anti-fatigue controls, and phishing resistance.
Definition
Push MFA relies on user approvals. Strong designs add number matching, context, and rate limits. It is generally less phishing-resistant than passkeys/security keys.
In plain English
MFA method using push approvals; security depends on context, anti-fatigue controls, and phishing resistance.
Why this matters
Why it matters: Weak push MFA can be socially engineered.
Example
Example: Use number-matching prompts, rate limiting, and prefer passkeys for high-risk accounts.