The sequence in which MFA requests are delivered is creating security-related confusion for users.
Our team has implemented MFA across our organization. However, several employees have raised security concerns because they are receiving MFA requests seemingly at random and at unusual hours (for example, at midnight).
We have reassured our users that their passwords have not been compromised because Adobe requests MFA verification before the username is entered. Nevertheless, all affected users have questioned why the process works this way, since with most other applications, receiving an unsolicited MFA prompt is typically considered an indication that a password may have been compromised.
While we understand that Adobe documents this authentication flow in its support article (Adobe Two-Step Verification Documentation), we struggle to understand the security rationale behind this design choice.
We raised our concerns with customer support and were told that the issue would be discussed internally and that we would be kept informed. However, the case was later closed, and we simply received the same documentation link referenced above. We were even advised to disable MFA altogether if we found the behavior inconvenient.
Given the confusion and security concerns this design creates for users, we believe it would be worthwhile to reconsider the authentication flow and adopt the more conventional sequence of username, password, and then MFA verification. This approach would better align with user expectations and common security practices, while reducing the likelihood of confusion and MFA fatigue concerns.
