September 2026

Multi-factor authentication (MFA) is one of our strongest defenses against cyber threats. However, attackers sometimes attempt "MFA fatigue" style attacks, sending multiple notifications to your phone hoping you will accidentally approve one.
To combat this, as of Monday, September 28, University of Miami Information Technology & Systems (ITS) is enabling a direct reporting feature within the Microsoft Authenticator app.
If your phone buzzes with an MFA request that you did not initiate (meaning you are not currently trying to log into a UM system), follow these two simple steps:
When the notification appears on your device, do not approve it. Instead, tap the "No, it's not me" option.
A secondary screen will appear asking if you would like to report the suspicious activity to your organization. Tap "Report."

Once you click "Report," the following happens automatically:
Remember: If you did not initiate an MFA prompt, reporting is always the right thing to do!
For 24/7 technical support, please contact the IT Service Desk.
Copyright: 2026 University of Miami. All Rights Reserved.
Emergency Information
Privacy Statement & Legal Notices
Individuals with disabilities who experience any technology-based barriers accessing University websites can submit details to our online form.