Skip to main content
SysadmExel
Participant
July 31, 2026
Question

The sequence in which MFA requests are delivered is creating security-related confusion for users.

  • July 31, 2026
  • 3 replies
  • 18 views

Our team has implemented MFA across our organization. However, several employees have raised security concerns because they are receiving MFA requests seemingly at random and at unusual hours (for example, at midnight).

We have reassured our users that their passwords have not been compromised because Adobe requests MFA verification before the username is entered. Nevertheless, all affected users have questioned why the process works this way, since with most other applications, receiving an unsolicited MFA prompt is typically considered an indication that a password may have been compromised.

While we understand that Adobe documents this authentication flow in its support article (Adobe Two-Step Verification Documentation), we struggle to understand the security rationale behind this design choice.

We raised our concerns with customer support and were told that the issue would be discussed internally and that we would be kept informed. However, the case was later closed, and we simply received the same documentation link referenced above. We were even advised to disable MFA altogether if we found the behavior inconvenient.

Given the confusion and security concerns this design creates for users, we believe it would be worthwhile to reconsider the authentication flow and adopt the more conventional sequence of username, password, and then MFA verification. This approach would better align with user expectations and common security practices, while reducing the likelihood of confusion and MFA fatigue concerns.

    3 replies

    SysadmExel
    Participant
    August 3, 2026

    Even yesterday, the user received an unsolicited MFA prompt without having performed any action to sign in. This is becoming quite disruptive and frustrating.

    Community Manager
    July 31, 2026

    Hello ​@SysadmExel,

     

    Thank you for sharing this in detail, and we sincerely apologize for the experience you had.

     

    Your feedback on the authentication flow is well-founded, and we want to make sure it receives the attention it deserves this time.

    To help us follow up on this properly, could you please share the case number from your previous support interaction? This will allow us to review what was discussed and ensure that your concerns are escalated to the right internal team, rather than starting from scratch.

     

    We appreciate your patience and will make sure this is handled appropriately.


    ~Tariq

    SysadmExel
    Participant
    July 31, 2026

    The first time we raised this concern was under case ADB-46162601-M3B2, where a partial solution was introduced requiring users to enter the last four digits of the phone number associated with their account after entering their username. But didn’t hold because user have been MFA spammed again

    The most recent case was ADB-46419272-Q9K6, where we were told that our feedback had been acknowledged and suppose to be shared with the Product Team.

     

    Thank you