You want number matching so that people aren’t targets for MFA fatigue attacks. If they keep getting Approve/Allow prompts on their device via a compromised account, they end up just hitting Allow to get the notification to go away
💯 1
Aaron Parker
01/31/2024, 4:31 AM
On my phone, Authenticator is protected with Face ID so that I dont need a PIN
👍 1
j
Jan Tytgat
01/31/2024, 10:24 AM
Isn't Microsoft enforcing number matching for some time now?
j
Jon Bucud
01/31/2024, 2:35 PM
number matching = phish resistance ftw
r
Ryan Gallier
01/31/2024, 2:46 PM
I think he means... you hit accept, enter the number, THEN you have to auth to your phone. Mine does this, but it's fingerprint.