Not getting the push notification to approve sign-in
This runbook is for anyone who is stuck at a sign-in prompt waiting for an approval push that never arrives. You’ll learn how to quickly tell whether the problem is your phone, your network, your time settings, or your account setup, and how to fix each one safely.
TL;DR — If your sign-in approval push is not arriving, the most common causes are: notifications are disabled on your phone, the authenticator app is signed out or on the wrong account, or your phone cannot reach Apple/Google push services because of network or battery-saving settings. Start by opening the authenticator app manually, checking for a pending approval, then confirm notification permissions and disable battery/data restrictions for that app. Reading time: ~6 min
The scenario
It is a normal Tuesday afternoon. You enter your username and password, the sign-in page says it sent a push notification to your phone, and then nothing happens. You stare at the screen, unlock your phone, lock it again, and still no approval prompt appears. You may already be on office Wi‑Fi, on mobile data, or halfway through a client call trying to get into the dashboard you need right now.
Symptoms
- The sign-in page says one of these messages and then waits forever:
Approve the sign-in request on your device Push notification sent Check your phone to continue Waiting for approval... - Your phone shows no banner, no sound, and no lock-screen notification from the authenticator app.
- Opening the authenticator app shows either no pending request or an old request that has already expired.
- You can receive email or SMS on the phone, but not the sign-in approval push.
- The problem happens on Wi‑Fi but sometimes works on mobile data, or the reverse.
- The app may show messages like:
No pending notifications Device not registered Session expired Sign in again - Your phone is in Low Power Mode / Battery Saver, Focus / Do Not Disturb, or has Background App Refresh / background data disabled.
Likely causes
| Cause | How common | Quick check |
|---|---|---|
| Notifications are disabled for the authenticator app | Very common | Phone Settings → Notifications → [your authenticator app] |
| The authenticator app is signed out, on the wrong account, or device registration broke | Very common | Open the authenticator app and check whether your work/school account is present and signed in |
| Battery saver, background restrictions, or Focus/Do Not Disturb is suppressing the push | Common | Phone Settings → Battery / Battery Saver and Focus / Do Not Disturb |
| Network is blocking push delivery or the app cannot reach the internet | Common | Turn off Wi‑Fi, switch to mobile data, then retry sign-in |
| Phone date/time is wrong, causing approval requests or app sessions to fail | Occasional | Phone Settings → Date & Time → Set Automatically |
| The app is outdated or the OS push service is stuck | Occasional | App Store / Play Store → search the authenticator app → Update |
| Your sign-in method is set to push, but your account no longer has the correct device enrolled | Less common | In your identity provider's security settings (e.g. Security → MFA / Two-step verification) check enrolled devices |
Step-by-step diagnosis
-
Open the authenticator app manually
- Action: Unlock your phone and open the authenticator app directly instead of waiting for the banner.
- This is your problem if: you see a pending approval inside the app even though no push banner appeared.
- Jump to: Fixes → Notifications are disabled for the authenticator app or Fixes → Battery saver, background restrictions, or Focus/Do Not Disturb is suppressing the push.
-
Check whether the correct account is in the app
- Action: In the authenticator app, look for your work or school account. If the app asks you to sign in again, note that.
- This is your problem if: your account is missing, the app says
Sign in again,Session expired, orDevice not registered. - Jump to: Fixes → The authenticator app is signed out, on the wrong account, or device registration broke.
-
Confirm notification permission is allowed
- iPhone:
Settings → Notifications → [your authenticator app] → Allow Notifications - Android:
Settings → Apps → [your authenticator app] → Notifications → Allow - This is your problem if: notifications are off, lock-screen alerts are disabled, or the app is set to silent.
- Jump to: Fixes → Notifications are disabled for the authenticator app.
- iPhone:
-
Temporarily disable Focus / Do Not Disturb and battery restrictions
- iPhone:
Settings → FocusandSettings → Battery → Low Power Mode - Android:
Settings → Battery → Battery SaverandSettings → Apps → [your authenticator app] → Battery → Unrestricted(wording varies by phone maker) - This is your problem if: the push arrives immediately after turning these off.
- Jump to: Fixes → Battery saver, background restrictions, or Focus/Do Not Disturb is suppressing the push.
- iPhone:
-
Test another network
- Action: Turn off Wi‑Fi, use mobile data, and retry the sign-in. If you were on mobile data, try a trusted Wi‑Fi network.
- This is your problem if: the push works on one network but not the other.
- Jump to: Fixes → Network is blocking push delivery or the app cannot reach the internet.
-
Set date and time to automatic
- iPhone:
Settings → General → Date & Time → Set Automatically - Android:
Settings → System → Date & time → Set time automaticallyandSet time zone automatically - This is your problem if: the phone time was wrong and pushes start working after correction.
- Jump to: Fixes → Phone date/time is wrong, causing approval requests or app sessions to fail.
- iPhone:
-
Update the app and reboot the phone
- Action: Open the App Store or Play Store, update the authenticator app, then restart the phone.
- This is your problem if: the app was outdated or pushes begin working after restart.
- Jump to: Fixes → The app is outdated or the OS push service is stuck.
-
Check your enrolled sign-in methods in the account portal
- Action: In your provider's security portal (wording varies, often
Security→MFA,Two-step verification, orSign-in methods), confirm your current phone is enrolled for push approvals. - This is your problem if: the listed device is an old phone, missing, or push is disabled for your account.
- Jump to: Fixes → Your sign-in method is set to push, but your account no longer has the correct device enrolled.
- Action: In your provider's security portal (wording varies, often
Fixes
Notifications are disabled for the authenticator app
Turn notifications back on for the app.
- iPhone:
Settings → Notifications → [your authenticator app]- Turn on
Allow Notifications - Turn on
Lock Screen,Notification Center, andBanners - Turn off any per-app
Deliver Quietlystyle option if shown
- Android:
Settings → Apps → [your authenticator app] → Notifications- Turn notifications on
- If categories/channels are shown, enable all categories related to approval requests
Then retry sign-in.
Verify it worked: start a new sign-in and confirm a banner appears on the lock screen or notification shade within a few seconds.
The authenticator app is signed out, on the wrong account, or device registration broke
Open the app and sign back in with the same work/school account you use for the target service. If your provider has a security portal, remove the old device entry and enroll the current phone again.
Typical portal path in your provider's dashboard: Security → MFA / Two-step verification / Sign-in methods → Remove old device → Add method / Enroll device.
If your organization provides a QR code during setup, scan that code from the authenticator app's Add account flow.
⚠️ Removing the wrong MFA device can lock you out if you do not have a backup method like a recovery code, SMS, or a second enrolled device. Before deleting anything, confirm you have another working sign-in method.
Verify it worked: your current phone appears in the security portal, and a fresh sign-in sends a prompt to that device.
Battery saver, background restrictions, or Focus/Do Not Disturb is suppressing the push
Disable the settings that prevent the app from waking up in the background.
- iPhone:
Settings → Focus→ turn off active Focus modes or allow the authenticator appSettings → Battery→ turn offLow Power ModeSettings → General → Background App Refresh→ ensure it is on for the authenticator app
- Android:
Settings → Battery→ turn offBattery SaverSettings → Apps → [your authenticator app] → Battery→ set toUnrestrictedorNot optimizedSettings → Notifications→ disableDo Not Disturb, or allow the app as an exception- On some phones:
Settings → Apps → [app] → Mobile data & Wi‑Fi→ enableBackground data
Verify it worked: with the app closed and phone locked, a new sign-in produces a notification without opening the app manually.
Network is blocking push delivery or the app cannot reach the internet
If the push works on mobile data but not on Wi‑Fi, the Wi‑Fi network is likely filtering or interfering with push traffic.
Immediate workaround:
- Turn off Wi‑Fi and complete the sign-in on mobile data.
Longer-term fix:
- If this is a home network, reboot the router.
- If this is office or guest Wi‑Fi, ask the network admin to allow standard Apple/Google push notification traffic and not to block the authenticator app.
- If you use a VPN (virtual private network), disconnect it briefly and retry.
Verify it worked: the push consistently arrives on the corrected network without switching to mobile data.
Phone date/time is wrong, causing approval requests or app sessions to fail
Set the phone to automatic time and time zone.
- iPhone:
Settings → General → Date & Time → Set Automatically - Android:
Settings → System → Date & time → Set time automaticallyandSet time zone automatically
After changing it, fully close and reopen the authenticator app, then retry sign-in.
Verify it worked: the app no longer shows expired or invalid requests immediately, and a fresh approval request arrives normally.
The app is outdated or the OS push service is stuck
Update the app from the phone's app store, then restart the device.
- iPhone:
App Store → search for [your authenticator app] → Update - Android:
Play Store → search for [your authenticator app] → Update - Then restart the phone normally
If the app still fails, uninstall/reinstall only if you have confirmed you can re-enroll the account or have a backup MFA method.
⚠️ Reinstalling an authenticator app can remove locally stored accounts on some apps. Do not uninstall until you have recovery codes, a second factor, or confirmation from your admin that you can re-enroll safely.
Verify it worked: after the update/restart, the app stays signed in and receives a new push approval.
Your sign-in method is set to push, but your account no longer has the correct device enrolled
Sign in to your account's security settings from a device where you are already authenticated, or ask your admin/help desk to review your MFA enrollment.
Typical path in the provider dashboard: Profile / Account → Security → MFA, Two-step verification, or Sign-in methods.
Actions to take:
- Remove the old phone entry
- Add the current phone as a new sign-in method
- Enroll a backup method such as a second device, recovery codes, or SMS if your organization allows it
Verify it worked: the current phone is listed as the active approval device, and the next sign-in sends the push there.
Prevention
-
Enroll a backup sign-in method now
- In your security settings, add one extra method: a second authenticator device, recovery codes, or SMS if permitted.
- Store recovery codes in your password manager.
-
Allow the authenticator app to run normally in the background
- iPhone:
Settings → General → Background App Refresh - Android:
Settings → Apps → [app] → Battery → Unrestricted - This prevents the phone from delaying or dropping approval pushes.
- iPhone:
-
Keep automatic date/time enabled
- Leave these on permanently:
Set time automatically Set time zone automatically - Wrong time causes many silent MFA failures and expired approvals.
- Leave these on permanently:
-
Test push on both Wi‑Fi and mobile data after changing networks, VPN, or phone settings
- After joining a new office Wi‑Fi, enabling a VPN, or changing battery settings, do one test sign-in while you are not locked out.
-
Keep the app and phone OS updated
- Turn on automatic app updates in the App Store / Play Store.
- Install phone OS updates regularly so push services and notification handling stay reliable.
-
If you manage a team, document the exact MFA recovery path
- In your internal wiki, record:
Security portal URL MFA reset request process Who can remove/re-enroll a device Whether recovery codes are supported - This cuts recovery time when someone changes phones or loses push access.
- In your internal wiki, record:
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI