A user can enter the password but never receives the expected MFA prompt and cannot access a protected service.
Un usuario introduce la contraseña, pero no recibe la solicitud MFA y no puede acceder al servicio protegido.
Cybersecurity FirstCiberseguridad primero
Never approve a prompt on the user's behalf, disclose bypass codes, or replace factors without strong identity verification and approved recovery procedures.
Nunca apruebes una solicitud por el usuario, reveles códigos de omisión ni reemplaces factores sin verificación fuerte y proceso aprobado.
Step 2 · Questions to askPaso 2 · Preguntas clave
Collect facts, not assumptions
Recopila hechos, no suposiciones
Which factor is expected: app, SMS, call, token, or security key?
Is the registered device available?
Did the user change phones or numbers?
Is device time correct?
Are repeated unexpected prompts occurring?
¿Qué factor se espera: app, SMS, llamada, token o llave?
¿Está disponible el dispositivo registrado?
¿Cambió teléfono o número?
¿La hora es correcta?
¿Hay solicitudes inesperadas repetidas?
Professional habitHábito profesional
Record the exact message, time, scope, recent changes, and business impact. Precise notes shorten diagnosis and escalation.
Registra mensaje exacto, hora, alcance, cambios recientes e impacto. Las notas precisas aceleran diagnóstico y escalamiento.
No notification but app code works: push or notification issue.
All methods fail: account, service, policy, or time issue.
New phone: approved re-registration may be required.
Unexpected prompts: possible MFA fatigue attack or compromised password.
Sin notificación pero código funciona: problema de push.
Todos los métodos fallan: cuenta, servicio, política u hora.
Teléfono nuevo: puede requerir registro aprobado.
Solicitudes inesperadas: posible fatiga MFA o contraseña comprometida.
Step 5 · Possible resolutionsPaso 5 · Posibles resoluciones
Resolve safely, validate, and document
Resuelve de forma segura, valida y documenta
Use an approved alternate registered factor.
Restore notifications, time synchronization, or app connectivity.
Perform approved factor reset and re-enrollment after verification.
Escalate suspicious prompts and initiate account-security response.
Usa un factor alterno ya registrado y aprobado.
Restaura notificaciones, hora o conectividad.
Restablece y registra de nuevo tras verificación aprobada.
Escala solicitudes sospechosas e inicia respuesta de seguridad.
Before closingAntes de cerrar
Confirm the result with the user or approved monitoring, document the cause and actions, and record any remaining risk or follow-up.
Confirma el resultado con el usuario o monitoreo aprobado, documenta causa y acciones, y registra cualquier riesgo o seguimiento.
Step 6 · Five easy questionsPaso 6 · Cinco preguntas fáciles
Quick learning check
Comprobación rápida
This is not a formal exam. Select an option, then use “Check answer” to see the correct answer and explanation.
Esto no es un examen formal. Selecciona una opción y usa “Revisar respuesta” para ver la respuesta correcta y la explicación.
1. What is required before resetting MFA?1. ¿Qué se requiere antes de restablecer MFA?
Correct answer: Strong identity verificationRespuesta correcta: Verificación fuerte de identidadMFA reset is a high-risk identity action.MFA reset is a high-risk identity action.
2. Should support approve a prompt for the user?2. ¿Debe soporte aprobar una solicitud por el usuario?
Correct answer: NoRespuesta correcta: NoThe user must control their own factor.The user must control their own factor.
3. What may repeated unexpected prompts indicate?3. ¿Qué pueden indicar solicitudes inesperadas repetidas?
Correct answer: An MFA fatigue attackRespuesta correcta: Un ataque de fatiga MFAUnexpected prompts can signal stolen credentials.Unexpected prompts can signal stolen credentials.
4. What can a new phone require?4. ¿Qué puede requerir un teléfono nuevo?
Correct answer: Approved re-enrollmentRespuesta correcta: Registro aprobado nuevamenteThe factor must be securely registered again.The factor must be securely registered again.
5. What is a safe temporary option?5. ¿Cuál es una opción temporal segura?
Correct answer: An approved alternate registered factorRespuesta correcta: Un factor alterno registrado y aprobadoUse only authorized recovery options.Use only authorized recovery options.
Step 7 · CertificatePaso 7 · Certificado
Create your certificate of participation
Crea tu certificado de participación
IT SUPPORT PRACTICAL CASE SERIES · CASE 10 OF 15
Certificate of Completion
This certifies that
has successfully completed
IT Support Practical Case 10
Multi-Factor Authentication Is Not Working
Completed a practical, cybersecurity-first support scenario focused on MFA, Identity Security, Authentication, Account Recovery, and Social Engineering.