A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the new phone does not have the old Authenticator configuration, the account must be restored or the MFA settings reset using another method already configured on the account.
Use the path that matches the situation:
- Restore Authenticator from backup (if a backup exists)
- On iOS: install Microsoft Authenticator, then use Restore from backup and sign in with the same personal Microsoft account that was used for backup. After restore, for each account that shows Sign in to restore your account or Action required, tap it and complete sign-in with password plus email/phone verification to re-activate it.
- On Android: open Authenticator and select Restore from backup or Begin recovery before signing in. Use the same backup account. Then tap Sign in or Action required on each account tile and complete the extra verification.
- Use an alternative verification method (if configured)
- When prompted for the Authenticator code, choose another method such as SMS or email if it is offered. Complete sign-in using that method.
- Once signed in, go to the account’s security/MFA settings and add the new phone’s Authenticator app as a new sign-in method, then remove the old device so future prompts go to the new phone.
- If Authenticator backup cannot be restored
- If the backup account (iCloud/Microsoft backup account) cannot be accessed, Authenticator credentials cannot be recovered. In that case, accounts must be added to Authenticator again from each service’s security/MFA settings after signing in with another method.
- If completely locked out of a work/school (business) account
- If this is a work or school account and there is no alternative sign-in method and no other admin can reset MFA, the tenant’s global admin (or, if the locked-out user is the only admin) must contact Microsoft support/Data Protection via phone to request an MFA reset, as described in the Q&A guidance. Support will verify identity and reset the authentication methods so Authenticator can be set up again on the new phone.
If none of the above works because there is no backup and no alternative sign-in method, and it is a personal Microsoft account, use the Microsoft account sign-in helper to recover access to the backup/sign-in account, then reconfigure Authenticator and other MFA methods.
References:
- Restore account credentials from Microsoft Authenticator
- Troubleshoot signing in with a passkey
- Troubleshoot problems with Microsoft Authenticator
- Microsoft Authenticator FAQs
- Cannot authenticate with E-mail when logging into Microsoft Authenticator(iOS). - Microsoft Q&A
- Microsoft authenticator sending me into a spiral - Microsoft Q&A
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A
- Using Outlook mobile to sign in
- Authenticator Did Not Complete Login