← Back to glossary

MFA method using push approvals; security depends on context, anti-fatigue controls, and phishing resistance.

Definition

Push MFA relies on user approvals. Strong designs add number matching, context, and rate limits. It is generally less phishing-resistant than passkeys/security keys.

In plain English MFA method using push approvals; security depends on context, anti-fatigue controls, and phishing resistance.

Why this matters

Why it matters: Weak push MFA can be socially engineered.

Example

Example: Use number-matching prompts, rate limiting, and prefer passkeys for high-risk accounts.