Processes in Microsoft 365 for setting up Office apps, redeeming product keys, and activating licenses.
To move Microsoft Authenticator to a new iOS device, set up the new phone, back up Authenticator on the old phone, then restore and re‑register accounts on the new phone.
- Prepare and back up on the old iPhone
- Make sure the old phone still works and can complete MFA. Do not wipe it or remove Authenticator until setup on the new phone is finished.
- Ensure you have:
- A personal Microsoft account to act as the recovery account.
- An iCloud account for storage.
- On the old iPhone, turn on:
- iCloud Drive
- iCloud Keychain
- iCloud Backup
- In your Saved to iCloud list, search for Authenticator and turn on the toggle for Authenticator.
- Update Microsoft Authenticator to version 6.8.33 or later.
- Open the Authenticator app at least once so it can update the backup.
- Set up the new iPhone
- Power on the new iPhone and complete Apple’s Setup Assistant.
- If desired, transfer data from the old phone or from iCloud during setup.
- After reaching the home screen, confirm that Microsoft Authenticator is installed. If not, install it from the App Store.
- Restore Authenticator on the new iPhone
- If you don’t see the backup when opening Authenticator, uninstall and reinstall the app on the new device.
- Open Authenticator and choose Begin recovery.
- Sign in with the same personal Microsoft account used for backup.
- Restore the backup:
- Microsoft personal accounts and third‑party OTP accounts (Amazon, Facebook, Gmail, etc.) will restore their one‑time password codes.
- Work or school accounts and passwordless sign‑in entries restore only the account names; they must be re‑registered.
- Re‑register work or school accounts and phone sign‑in
- On the new iPhone, sign in to a work app (for example, Microsoft Teams). Use the old phone to complete MFA if prompted.
- If your organization uses Intune:
- Install Intune Company Portal and enroll the device as required.
- After enrollment and compliance, open Authenticator and restore backup if not already done.
- In Authenticator, for each work or school account placeholder:
- Select the account.
- Choose Set up 2-step verification.
- Follow the prompts (usually scanning a QR code from the My Security info or organization setup page) to register the new device.
- If using phone sign-in for your work account, enable it again on the new device from within Authenticator after restoration.
- If the old phone is unavailable
- If there is another admin in the tenant, that admin can reset MFA for the user in the Microsoft Entra admin center so the new phone can be set up from scratch.
- If this is a business account and there is no other global admin, contact Microsoft support and ask for the Data Protection team to help recover the tenant admin account and reset MFA.
After confirming that all accounts work on the new phone, the old device and its Authenticator app can be safely removed.
References:
- Back up your accounts in Microsoft Authenticator
- Microsoft Authenticator FAQs
- Migrate to a new iPhone for work
- Use a screen reader to set up and troubleshoot multifactor authentication
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A