A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Because the Authenticator backup is tied to iCloud and to how MFA is configured on the account, there are two separate issues to address: restoring the backup correctly and then fixing the sign-in/MFA loop.
- Verify that the Authenticator backup is correctly available on iOS
On the old phone (if still available):
- Turn on iCloud Drive.
- Turn on iCloud Keychain.
- Turn on iCloud Backup.
- In the Saved to iCloud list, search for Authenticator and make sure the toggle for Authenticator is turned on.
- Ensure Microsoft Authenticator is updated to version 6.8.33 or later.
- Open the Authenticator app at least once.
- Uninstall the Microsoft Authenticator app.
- Reinstall Microsoft Authenticator from the store.
- Open it and sign in with the same Apple ID/iCloud account that was used on the old phone.
- The backup should now appear and allow restore.
- Understand what is restored
After restore on iOS:
- Microsoft personal accounts that use only time-based one-time passwords (codes that refresh every 30 seconds) will have those codes available immediately.
- Microsoft personal accounts that also use passwordless sign-in, and all work or school accounts, restore only the account name; they still require signing in again to fully re-activate.
- Third-party accounts (Amazon, Facebook, Gmail, etc.) that use time-based codes will have their codes available once restored.
- Fix the MFA sign-in loop
If no push notification appears on the new phone when signing in:
- The push may be going to another device where Authenticator was last used. Check any older phone where Authenticator might still be installed and approve the sign-in there.
- If the old device is not available or Authenticator was deleted, use a different verification method offered on the sign-in screen (such as SMS) when available.
- If still locked out as an admin
If this is a work/school (Microsoft 365) account and access is completely blocked because all MFA methods point to the lost Authenticator:
- A global admin for the tenant must reset or require re-registering MFA for the affected account using the admin tools.
- If the locked-out user is the only global admin, the Microsoft Data Protection team must be involved via Microsoft Support to verify identity and reset MFA. This is done by calling the regional Microsoft customer service phone number and asking to open a ticket with the Data Protection team for an admin who has lost access to MFA.
Once the backup is visible and restored on the new phone, and MFA is reset or re-registered if needed, sign-in should succeed and codes or approvals should appear in the Authenticator app.
References:
- Microsoft Authenticator FAQs
- Back up your accounts in Microsoft Authenticator
- Use a screen reader to set up and troubleshoot multifactor authentication
- I have a Micrsoft business account and I am the admin and the only user registered under this account. I can't log in because i have replaced my phone and the authenticator doesn't work. - Microsoft Q&A
- How Do I Regain Access to My Account After Losing Access to Microsoft Authenticator? (Urgent Request). - Microsoft Q&A
- I need to reset my mfa methods - Microsoft Q&A
- Cannot unlock the Autheticator - Microsoft Q&A
- Requesting a Tenant Admin MFA Reset - Microsoft Q&A