
MFA fatigue: why your team disables it and how to prevent that
Forcing MFA without UX design creates dangerous workarounds. Strategies we have seen work in real PR offices.
CISA insists on MFA for all remote access — rightly so. But in rushed SMB rollouts we see the same ending: users approve prompts without reading, store codes in iPhone Notes, or IT creates permanent exceptions for "management." Schneier puts it well: security people circumvent is not security.
MFA fatigue is not laziness; it is poorly designed friction
MFA fatigue is not laziness; it is poorly designed friction. If every laptop login demands a push and the phone is in another room, users find shortcuts. The fix is not removing MFA — it is SSO with reasonable sessions, FIDO2 where it matters (admin, finance, cloud consoles), and risk-based policies.
For Microsoft 365 or Google Workspace in 15–80 user companie
For Microsoft 365 or Google Workspace in 15–80 user companies in Puerto Rico, we recommend: passwordless or hardware keys for admins, Authenticator with number matching, and geo restrictions on critical apps. Document recovery that is not "WhatsApp reset to the owner."
Train with local scenarios: "If someone calls pretending to be Microsoft support asking for the six-digit code, hang up." Short quarterly simulations beat 40-page policies. The goal is MFA as muscle memory, not daily punishment.
Measure adoption: MFA coverage, bypass attempts, lockout tickets. If lockouts exceed 5% monthly, your UX needs tuning, not more rules. Well-implemented MFA dramatically reduces credential incidents; poorly implemented MFA creates shadow IT.

Operations and execution — connecting strategy with what the team ships every week.


