Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

A second check for an important account

Choose an additional sign-in factor and recognise requests you should decline.

Users of online and financial servicesAbout 5 minutes of reading + 3 questions
Start with the example Need help now?

What you will learn

  • Approve only sign-ins you started yourself.
  • Distinguish a one-time code from a phishing-resistant method.
  • Prepare a secure way to recover access.

Practice example

Your phone asks for approval while you are not using the account

Your phone asks for approval while you are not using the account
Your phone asks for approval while you are not using the account

Several sign-in approval requests arrive. You are not signing in. Someone then calls and says you must approve the request to stop the notifications.

Fictional training scenario.
Show the example explanation
You did not start a sign-in
Do not approve an unexpected request. It is a reason to check account security.
The call tries to change your decision
The call itself does not establish the caller’s identity or validate their explanation.

What a second factor adds

Two-factor authentication (2FA) combines two different kinds of evidence: something you know, such as a password, and something you have, such as a security key or phone. Biometrics, such as a fingerprint, can form part of verification in supported systems.

A second factor reduces the risk that a stolen password is enough to sign in. It cannot prevent every attack. A one-time code or an approval given without checking can still be exploited through phishing.

Which method to choose

Where supported, a FIDO security key provides resistance to phishing that an ordinary one-time code does not. An authenticator app generates a code on the device; SMS delivers one in a text message. Your choice depends on the service and, for work accounts, your organisation’s requirements.

Start with email, financial accounts and work services. Do not postpone enabling available protection while waiting for a method the service does not yet offer.

Enable protection and prepare for recovery

  1. Open the official app or website and find the security settings.
  2. Choose 2FA, multi-factor authentication or two-step verification, depending on the provider’s terminology.
  3. Follow the selected method’s instructions and check that signing in works.
  4. If the service provides backup codes, keep them somewhere secure. Check recovery and transfer options before replacing your phone.

Choose your service in the account settings guide for menu paths and the check before replacing a phone.

If an unexpected approval arrives

Decline a request you did not initiate. Do not read out or forward one-time codes. Open the account independently and review recent sign-ins; tell your IT team if it is a work account.

If you already approved the request or shared a code, follow account recovery guidance. If the request concerns banking or a payment, contact your bank immediately through an official channel and explain what you approved.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

A sign-in approval request arrives that you did not initiate. What should you do?

Why does this matter? A sign-in approval is more than a notification: it controls whether someone gains account access. An unexpected request needs checking, rather than approval simply to stop the alerts.

  1. Approve it to stop the notifications.

    Approval may enable someone else to sign in. If the request is not yours, approving it authorises someone else’s action rather than just silencing a notification.

  2. Send a code to a caller claiming to be support.

    The code could enable an attacker’s sign-in; do not share it. A one-time code may complete a sign-in someone else started, even if the caller knows your name.

  3. Decline it and independently open the account security settings.Correct answer

    Review recent sign-ins and follow the account compromise process if needed. Rejecting the request withholds approval; checking independently helps establish whether further protection is needed.

A service supports SMS codes and a FIDO security key. What advantage does the key offer?

Why does this matter? A fake page can request a one-time code just like a real one and relay it during someone else’s sign-in. Second factors therefore differ in their resistance to phishing.

  1. Resistance to phishing that entering a one-time code does not offer.Correct answer

    FIDO ties authentication to the correct service, rather than relying on a code you could enter on a fake page. Binding approval to the genuine service makes it harder for a fake site to use an approval intended for a different destination.

  2. A guarantee that the device cannot be infected.

    A sign-in method does not address every threat to a device. The key protects a particular part of signing in; malicious files and other problems still require device protection.

  3. No need to prepare for account recovery.

    You still need to plan for losing access. Losing your only key without a recovery plan can lock you out even when nobody has attacked the account.

You are setting up 2FA before replacing your phone. What else should you do?

Why does this matter? Your phone may be the only place you can obtain the second factor. If you erase or lose it before preparing recovery, the password alone may not restore access.

  1. Permanently disable 2FA to avoid complications.

    Prepare for recovery rather than leaving the account without extra protection. Permanently disabling the factor removes a barrier for someone who learns your password, although you only needed to replace a device.

  2. Check factor transfer instructions and securely store any supported recovery codes.Correct answer

    Follow the provider’s instructions and check access before erasing the old device. This lets you check access on the new device while you can still correct settings using the old one.

  3. Post recovery codes in a public group.

    Anyone with the codes may try to access the account. Recovery codes provide a backup way in, so public storage can give other people that way in too.

No registration. Your answers are not sent; the result is just for you.

Remember

Approve only sign-ins you started yourself.

Review password protection

References

Sources and further reading

The practical setup is based primarily on the Serbian National CERT guidance on two-factor authentication. Differences between methods and the benefit of phishing-resistant authentication are supplemented by the CISA multi-factor authentication guide (United States); always confirm the available options in the service provider’s official instructions.

Content last reviewed