
The request is not approved
When a notification is received without a legitimate sign-in, it is not approved. Displayed details, receipt time and the target application are recorded so that the investigation can be based on specific evidence. Repeated notifications are not accepted as a reason for approval.
Related events are reviewed
The event is reported through the organization’s support channel. Sign-in events and related sessions are reviewed. If credential exposure is confirmed, the password is reset and sessions are handled according to organizational policy.
The outcome is recorded
Findings and completed actions are recorded in the support request. If a repeated pattern is observed, notification practices and verification policy are reviewed. Recognition of unsolicited requests is also covered in user guidance.
What does an unexpected request mean?
An approval request without an initiated sign-in warrants investigation but does not alone prove compromise. Its time, destination service and recurrence are recorded and compared with known activity. Approval is not granted merely to stop repeated notifications. Where the notification lacks context, investigation proceeds through official support rather than an unfamiliar link.
Investigation and recurrence reduction
In a proposed workflow, repeated requests for an account are correlated with sign-in events from the same period. Confirmed misuse triggers credential and active-session actions under the incident procedure. After containment, reporting guidance and report ownership are reviewed. Closure is supported by evidence; dismissing the notification without investigating its cause does not close the case.
Reference and scope
This planning guide is applied in accordance with organizational policy and documented system capabilities.
NIST SP 800-63B-4 — Authentication and Authenticator Management