A user reports unexpected MFA prompts and then a missing phone. What is your response?

Instruction: Handle account protection and recovery as separate but coordinated tasks. Describe safe identity verification, security escalation, and how you would confirm restored access without requesting authentication secrets.

Context:

A Microsoft 365 employee calls from a desk phone. They saw three Authenticator approval prompts they did not initiate earlier today and now cannot find the enrolled phone. A meeting starts in 20 minutes. They ask you to remove MFA immediately. You have the help desk recovery runbook, but authentication-method changes and session revocation require the identity/security team's authority.

Updated

Official answer available

Read the opening below, then unlock the full answer and practical guidance.

I'd acknowledge the meeting pressure and establish a trusted way to continue the support conversation. I would treat the unexpected prompts and missing phone as facts that require prompt attention, while avoiding assumptions about who initiated them. I'd document the times and the user's last known access, then follow the organization's identity-verification process before discussing changes to the account...

Related Questions