A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
To move Microsoft Authenticator accounts to a new phone, the process depends on whether the old phone is still available and working.
If the old phone is still available (recommended path)
- Set up backup on the old phone (iOS example)
- Open Microsoft Authenticator on the old phone.
- Go to Settings.
- Turn on iCloud backup. This backs up your account credentials to iCloud and creates a Recovery Account.
- (Optional) To sync autofill passwords, go to Autofill > Sync account.
- Prepare the old iPhone for migration (if using iPhone for work)
- On the old iPhone, turn on Automatic Downloads for apps:
- Settings > App Store > Automatic Downloads > turn on Apps.
- Turn on iCloud Backup and run a backup:
- Settings > tap your Apple ID > iCloud > iCloud Backup > turn on and tap Back Up Now.
- Confirm in iCloud that the apps you want (including Authenticator) are included in the backup.
- On the old iPhone, turn on Automatic Downloads for apps:
- Set up the new iPhone
- Power on the new iPhone and go through Setup Assistant.
- When prompted, choose how to transfer data:
- Transfer from iCloud – signs in to iCloud and restores apps/data in the background.
- Transfer from old phone – wait for transfer to complete on both devices.
- After the device restarts and shows the home screen, wait for apps to finish installing.
- Confirm Microsoft Authenticator is installed. If not, install it from the App Store.
- Restore Authenticator on the new phone
- Open Microsoft Authenticator on the new phone and follow the prompts to restore from the iCloud backup.
- For Microsoft personal accounts:
- If using only one-time password codes, codes will work after restore.
- If using passwordless sign-in, only the account name is restored; sign in again when prompted.
- For work or school accounts, only the account name is restored; sign in again to re-activate.
- For 3rd party accounts (Amazon, Facebook, Gmail, etc.), one-time password codes are restored and usable.
- Enroll the new device for work (if it’s a work phone)
- On the new device, open a work app (for example, Microsoft Teams) and sign in with the work account.
- Complete MFA/passwordless prompts using Authenticator on the old phone if required.
- When Conditional Access blocks access and prompts to enroll, follow the enrollment steps to register the new device.
If the backup does not appear on the new phone (iOS)
On the old device:
- Enable iCloud Drive.
- Enable iCloud Keychain.
- Enable iCloud Backup and ensure Authenticator is toggled on in the “Saved to iCloud” list.
- Make sure Authenticator is version 6.8.33 or later.
- Open Authenticator at least once before switching phones.
On the new device:
- Uninstall and reinstall the Authenticator app.
- Open it again; the backup should now appear for restore.
If the old phone is not available and there is no backup
If there is no access to the old phone and no working backup, access to each account protected by Authenticator must be recovered using that account’s recovery methods (for example, alternate email, phone, or admin support). For Microsoft 365 tenants where the only global admin is locked out due to MFA on a lost/replaced phone, a support ticket with Microsoft’s Data Protection team is required to regain access.
References:
- Migrate to a new iPhone for work
- Back up your accounts in Microsoft Authenticator
- I have a new mobile phone and I want to add it to MFA
- Use a screen reader to set up and troubleshoot multifactor authentication
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work.
- Severity A Situation - Locked out of global admin account (MFA) - business down
- Cannot unlock the Autheticator