Number matching worked. That is the part most security programs never absorbed, because a control that succeeds quietly never gets a retrospective.
The attack it defeated — push bombing, MFA fatigue, whatever your vendor called it — was the cheapest intrusion technique of the last decade. An attacker holding a password from a credential dump fired approval prompts at a phone until the owner tapped Approve to make the buzzing stop. No malware. No exploit. Just attrition against a tired person at eleven at night. Then the approval prompt started demanding that the user read a two-digit number off the screen that initiated the sign-in, and reflexive approval stopped being possible.
So the money moved. That is the only dependable law in this field, and it is the actual subject here.
What number matching proves, and what it does not
The control does one thing well. It establishes that the person approving a sign-in is looking at the same screen that started it. A user can no longer consent to an authentication they know nothing about.
Notice the boundary of that guarantee. Number matching validates presence. It does not validate destination. If the sign-in page the user is reading happens to be a proxy operated by an attacker, the number on screen is the real number, relayed from the real identity provider a fraction of a second earlier. The victim types it correctly. Authentication succeeds legitimately. Meanwhile the attacker in the middle collects the session cookie and walks away with an authenticated session.
Phishing kits that proxy a genuine sign-in page rather than imitate one are no longer bespoke work — that is analysis, not a claim about volume. Against that technique, number matching is not a defense. Neither is a longer password, nor awareness training that teaches people to hunt for misspelled domains. The user did everything correctly and still lost the session.
The authentication paths that never ring your phone
Four routes deserve a line on an executive risk register.
- Session and token theft. A stolen cookie replays as an already-authenticated user. No prompt, no number, no fatigue to exploit. The countermeasures live in device compliance, token binding, and continuous access evaluation — not in the authenticator app.
- Consent phishing. A user is asked to grant an application permission to read mail or files. The grant is legitimate OAuth, issued by a legitimately authenticated person. Resetting the password changes nothing; the application keeps its access until somebody goes looking for it.
- Device code and cross-device flows. Sign-in flows built for televisions and conference room displays make effective lures, because the victim is asked to enter a code on a genuine Microsoft page. Everything looks correct because everything is correct.
- Machine and legacy identities. Service accounts, API keys, and app registrations that were never in scope for MFA to begin with. Few organizations can produce a current list of them, and fewer review that list on a schedule.
None of this is exotic. All of it shares one property: the human approval step, the thing number matching hardened so effectively, is not in the path at all.
Enrollment is now your highest-privilege operation
Here is the exposure that belongs in front of a board, and the one that tends to be reasoned about least clearly.
Every strong authentication system needs a recovery path. Phones get lost. Employees swap hardware. Someone flies to a conference and leaves the authenticator in a drawer in Sherman Oaks. That recovery path — re-enrolling an MFA method — is functionally the ability to mint a new credential for an account. It carries more power than a password reset, and in a great many organizations it is protected by less process.
Attackers understand the arithmetic. The call comes in late on a Friday from someone who sounds exactly like the controller, who is boarding a flight, who cannot reach email, who needs the authenticator reset right now. Synthetic voice has moved from research demonstration to ordinary tooling, and a usable sample can come from a recorded webinar or a voicemail greeting. That is an observation about capability, not a claim about any specific incident.
The defense here is procedural rather than technical. Enrollment and reset requests should be verified out-of-band against something a caller cannot talk their way past: a manager approval, a callback to a number already on file, a video check against a record. Whoever answers your help desk is holding the last line of your identity policy, and most companies have never written down what that person is supposed to do when the voice on the phone is urgent and familiar.
The decisions worth making this quarter
If number matching is enabled across your tenant, you have closed the loophole that mattered in 2022. The 2026 decision is a different one, and it is as much a budgeting question as a security question.
Move the accounts that matter to phishing-resistant credentials. Passkeys and FIDO2 security keys are bound cryptographically to the origin that issued them, so a proxy sign-in page cannot use them — the credential simply refuses to operate on the wrong domain. That is a property of the protocol, not a vendor promise. Begin with executives, finance, IT administrators, and anyone who can move money or change permissions.
Pair identity with device next. A stolen token loses most of its value when IT security policy requires a compliant, managed device before granting access to Microsoft 365. Conditional Access remains the largest unrealized gain available to mid-market organizations, and it usually runs on licensing already purchased.
Three more items deserve a calendar entry: an inventory of OAuth application consents, a written list of who may approve an MFA reset, and a verification script the service desk actually follows. None of it is glamorous. All of it is cheaper than the alternative.
The prompt was never the control
Executives tend to hear "we have MFA" as a finished project. Authentication behaves more like a portfolio that attackers continuously reprice. Number matching was a real win, and its reward was a shift in attacker attention toward tokens, consents, machine identities, and the person who answers the phone when a caller says they have lost their device.
Organizations that handle the next few years well will be the ones that stopped asking whether MFA is turned on and started asking which of their authentication paths still rests on a human judgment call made under pressure.
Pro Link Systems has supported Los Angeles businesses from Woodland Hills since 1999, with an in-house, US-based help desk that answers live — no phone tree, no hold queue — and an average ticket first-response time of 15 minutes. If you want an unsentimental review of your identity controls and where the remaining approval gaps sit, our managed IT services team is a reasonable place to begin.
Ready to talk to a real IT engineer?
Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.