1. Relying on Phishable MFA Methods
Not all MFA is created equal. Many organizations still rely on methods that are vulnerable to social engineering, such as one-time codes sent via SMS text or basic push notifications that simply ask a user to tap “Approve.” Cybercriminals exploit these
weaknesses with ease. SIM swapping attacks allow a thief to take control of an employee’s phone number, intercepting SMS codes. Even more common are “MFA fatigue” or “push bombing” attacks, where an attacker who has already stolen a password spams a user with login notifications. Annoyed, distracted, or confused, the employee eventually hits “Approve” just to make the alerts stop, and the attacker is in. Cybersecurity agencies now strongly recommend moving toward phishing-resistant options like FIDO2 hardware keys or other authenticators that rely on cryptography to verify a login is legitimate.
2. Leaving Gaps in Your Coverage
One of the most frequent mistakes is incomplete deployment. Companies often roll out MFA for their primary cloud services, like Microsoft 365 or Google Workspace, but leave other critical systems unprotected. Attackers don't look for the strongest link; they search for the weakest one. Legacy applications, command-line tools, VPN access, and service accounts are common blind spots that often lack native MFA support. An attacker who compromises a single, unprotected entry point can often move laterally across the network to access more sensitive data. Ensuring that MFA is enforced consistently across all applications, for all users—including privileged administrators and executives—is non-negotiable. Solutions now exist that act as a proxy or gateway to extend modern authentication to older systems without requiring a complete overhaul.
3. Poor Configuration and Weak Policies
The devil is in the details of your MFA configuration. A poorly configured system can be almost as bad as having no MFA at all. For example, some systems can be set to “fail open,” meaning if the MFA service is unavailable, it defaults to allowing access, creating a huge security hole. Another common issue is setting overly long session timeouts, which means an authenticated session could be hijacked and used by an attacker for hours or days. Furthermore, not enabling features like number matching—where a user must type a specific number displayed on their screen into the app—removes a key defense against push bombing. Organizations should implement risk-based or adaptive authentication, which can require a stronger verification method if a login attempt seems suspicious, such as coming from an unusual location or at an odd time.
4. Ignoring the User Experience
If a security control is too disruptive, employees will find ways to bypass it. Implementing MFA without considering the day-to-day workflow can backfire. A cumbersome process that requires multiple, frequent authentications for low-risk tasks will frustrate users and can lead to bad habits, like approving prompts without thinking. The goal is to make security as seamless as possible. This means choosing MFA methods that are both strong and user-friendly, like biometrics built into a device (e.g., Windows Hello) or hardware keys that require a simple tap. A balanced approach aligns the level of friction with the level of risk. A user accessing a non-sensitive document might not need to re-authenticate, but one trying to access critical financial data should face a stricter check.
5. Failing to Train Your Team
Technology alone cannot solve a human problem. Attackers increasingly target people, not just systems. Employees must be trained to recognize the signs of an MFA-based attack. They need to understand that an unsolicited MFA prompt is a major red flag—it means their password has likely been compromised and they should report it immediately. Training should explain what MFA fatigue attacks are and instill the habit of denying any login request they did not initiate. Furthermore, they need a clear and simple process for reporting suspicious activity to the IT or security team. Without this awareness, even the most technically robust MFA system can be undone by a well-meaning employee who is simply trying to clear their notifications.













